Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd} |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd} |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd} |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer32 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer32 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd} |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Elevation |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Elevation |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Source: svchost.exe, 0000000A.00000003.2027268744.00000176A741D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://127.0 |
Source: svchost.exe, 0000000A.00000003.2027432399.00000176A7ACA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://127.0.0.1:8000/3dd821bd/c462449b |
Source: svchost.exe, 0000000A.00000003.2027432399.00000176A7ACA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://127.0.0.1:8000/3dd821bd/c7af6c55 |
Source: svchost.exe, 0000000A.00000003.2027268744.00000176A741D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://127.01: |
Source: powershell.exe, 00000000.00000002.1765083847.0000000006269000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000000.00000002.1792038808.0000000006D3B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000000.00000002.1765083847.0000000004881000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000000.00000002.1792038808.0000000006D3B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: svchost.exe, 0000000A.00000003.2005062234.00000176A74E0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://91.240.118.2:9769/78fc5131525a9e8d335b1/0cmq2c1e.n3ms9 |
Source: svchost.exe, 00000006.00000002.1824887890.000000000310C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://91.240.118.2:9769/78fc5131525a9e8d335b1/0cmq2c1e.n3ms9kernelbasentdllkernel32GetProcessMitig |
Source: svchost.exe, 00000006.00000002.1823657943.0000000002C3C000.00000004.00000010.00020000.00000000.sdmp | String found in binary or memory: https://91.240.118.2:9769/78fc5131525a9e8d335b1/0cmq2c1e.n3ms9x |
Source: powershell.exe, 00000000.00000002.1765083847.0000000004881000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore6lB |
Source: svchost.exe, 0000000A.00000003.2027432399.00000176A7ACA000.00000004.00000020.00020000.00000000.sdmp, AvastBrowserUpdate.exe | String found in binary or memory: https://clients2.google.com/cr/report |
Source: AvastBrowserUpdate.exe | String found in binary or memory: https://clients2.google.com/service/check2?crx3=true |
Source: AvastBrowserUpdate.exe | String found in binary or memory: https://clients5.google.com/tbproxy/usagestats |
Source: svchost.exe, 00000006.00000003.1784459553.000000000319F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://cloudflare-dns.com/dns-query |
Source: svchost.exe, 00000006.00000003.1784459553.000000000319F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://cloudflare-dns.com/dns-queryPOSTContent-TypeContent-LengthHostapplication/dns-message%dMachi |
Source: powershell.exe, 00000000.00000002.1765083847.0000000006269000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000000.00000002.1765083847.0000000006269000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000000.00000002.1765083847.0000000006269000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: svchost.exe, 0000000A.00000003.2004473827.00000176A742E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://discord.com |
Source: svchost.exe, 0000000A.00000003.2004473827.00000176A742E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://discordapp.com |
Source: powershell.exe, 00000000.00000002.1792038808.0000000006D3B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: AvastBrowserUpdate.exe | String found in binary or memory: https://m.google.com/devicemanagement/data/api |
Source: powershell.exe, 00000000.00000002.1765083847.0000000006269000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: AvastBrowserUpdate.exe | String found in binary or memory: https://update.googleapis.com/service/update2 |
Source: AvastBrowserUpdate.exe | String found in binary or memory: https://www.google.com/support/installer/? |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00000176A6B51CF4 NtAcceptConnectPort,CloseHandle, | 10_2_00000176A6B51CF4 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00000176A6B515C0 NtAcceptConnectPort, | 10_2_00000176A6B515C0 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C5F244 NtAcceptConnectPort, | 10_2_00007DF422C5F244 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C5F224 NtAcceptConnectPort, | 10_2_00007DF422C5F224 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C60188 NtAcceptConnectPort,free, | 10_2_00007DF422C60188 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C5F050 NtAcceptConnectPort, | 10_2_00007DF422C5F050 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C5EFCC NtAcceptConnectPort, | 10_2_00007DF422C5EFCC |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C5FFDC malloc,RtlDosPathNameToNtPathName_U,NtAcceptConnectPort,NtAcceptConnectPort,free, | 10_2_00007DF422C5FFDC |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C5EFAC NtAcceptConnectPort, | 10_2_00007DF422C5EFAC |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C5F0B8 NtAcceptConnectPort, | 10_2_00007DF422C5F0B8 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C5F76C calloc,DuplicateHandle,NtAcceptConnectPort,free,NtAcceptConnectPort,NtAcceptConnectPort, | 10_2_00007DF422C5F76C |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C5F3FC CreateFileMappingW,MapViewOfFile,DuplicateHandle,NtAcceptConnectPort, | 10_2_00007DF422C5F3FC |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C5EEF0 NtAcceptConnectPort, | 10_2_00007DF422C5EEF0 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247475EF64 NtAcceptConnectPort, | 13_2_000002247475EF64 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247475F19C NtAcceptConnectPort, | 13_2_000002247475F19C |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C61CE8 calloc,CreateProcessW,NtResumeThread,CloseHandle,free, | 23_3_00007DF448C61CE8 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C61CE8 calloc,CreateProcessW,NtResumeThread,CloseHandle,free, | 23_3_00007DF448C61CE8 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C61958 calloc,NtAllocateVirtualMemory,NtWriteVirtualMemory,NtQueryInformationProcess,NtReadVirtualMemory,NtReadVirtualMemory,NtReadVirtualMemory,NtReadVirtualMemory,NtProtectVirtualMemory,NtProtectVirtualMemory,NtWriteVirtualMemory,NtProtectVirtualMemory, | 23_3_00007DF448C61958 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C61958 calloc,NtAllocateVirtualMemory,NtWriteVirtualMemory,NtQueryInformationProcess,NtReadVirtualMemory,NtReadVirtualMemory,NtReadVirtualMemory,NtReadVirtualMemory,NtProtectVirtualMemory,NtProtectVirtualMemory,NtWriteVirtualMemory,NtProtectVirtualMemory, | 23_3_00007DF448C61958 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C61958 calloc,NtAllocateVirtualMemory,NtWriteVirtualMemory,NtQueryInformationProcess,NtReadVirtualMemory,NtReadVirtualMemory,NtReadVirtualMemory,NtReadVirtualMemory,NtProtectVirtualMemory,NtProtectVirtualMemory,NtWriteVirtualMemory,NtProtectVirtualMemory, | 23_3_00007DF448C61958 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C61958 calloc,NtAllocateVirtualMemory,NtWriteVirtualMemory,NtQueryInformationProcess,NtReadVirtualMemory,NtReadVirtualMemory,NtReadVirtualMemory,NtReadVirtualMemory,NtProtectVirtualMemory,NtProtectVirtualMemory,NtWriteVirtualMemory,NtProtectVirtualMemory, | 23_3_00007DF448C61958 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C61CE8 calloc,CreateProcessW,NtResumeThread,CloseHandle,free, | 23_3_00007DF448C61CE8 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C61CE8 calloc,CreateProcessW,NtResumeThread,CloseHandle,free, | 23_3_00007DF448C61CE8 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_2_00B07FAB NtAllocateVirtualMemory,NtProtectVirtualMemory,VirtualFree, | 25_2_00B07FAB |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_069F5038 | 0_2_069F5038 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_069F67D0 | 0_2_069F67D0 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_069F63F1 | 0_2_069F63F1 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_069F6330 | 0_2_069F6330 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_069F52AF | 0_2_069F52AF |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_069F53C1 | 0_2_069F53C1 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_069F5310 | 0_2_069F5310 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_069F5300 | 0_2_069F5300 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_069F534A | 0_2_069F534A |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_069F5C38 | 0_2_069F5C38 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_069F584B | 0_2_069F584B |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_09AE49D5 | 0_2_09AE49D5 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_09AE0BA8 | 0_2_09AE0BA8 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_09AE0609 | 0_2_09AE0609 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_09AE0618 | 0_2_09AE0618 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_3_00000176A6B92C73 | 10_3_00000176A6B92C73 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_3_00000176A6B91BDD | 10_3_00000176A6B91BDD |
Source: C:\Windows\System32\svchost.exe | Code function: 10_3_00000176A6B927D3 | 10_3_00000176A6B927D3 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_3_00000176A6B95EC8 | 10_3_00000176A6B95EC8 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_3_00000176A6B955C8 | 10_3_00000176A6B955C8 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_3_00000176A6B95948 | 10_3_00000176A6B95948 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_3_00000176A6B9252E | 10_3_00000176A6B9252E |
Source: C:\Windows\System32\svchost.exe | Code function: 10_3_00000176A6B94A84 | 10_3_00000176A6B94A84 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00000176A6B50C70 | 10_2_00000176A6B50C70 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C51364 | 10_2_00007DF422C51364 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C44040 | 10_2_00007DF422C44040 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C3286C | 10_2_00007DF422C3286C |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C65254 | 10_2_00007DF422C65254 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C9D210 | 10_2_00007DF422C9D210 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D0E1EC | 10_2_00007DF422D0E1EC |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D1F354 | 10_2_00007DF422D1F354 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C90344 | 10_2_00007DF422C90344 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C8D050 | 10_2_00007DF422C8D050 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C31058 | 10_2_00007DF422C31058 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D2C010 | 10_2_00007DF422D2C010 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D1DFB4 | 10_2_00007DF422D1DFB4 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D1EFBC | 10_2_00007DF422D1EFBC |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C86FB0 | 10_2_00007DF422C86FB0 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C35FA0 | 10_2_00007DF422C35FA0 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C9D100 | 10_2_00007DF422C9D100 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C8F0C4 | 10_2_00007DF422C8F0C4 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C840B4 | 10_2_00007DF422C840B4 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C9D668 | 10_2_00007DF422C9D668 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422CAD610 | 10_2_00007DF422CAD610 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C856C0 | 10_2_00007DF422C856C0 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C4F408 | 10_2_00007DF422C4F408 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D2C52C | 10_2_00007DF422D2C52C |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C42500 | 10_2_00007DF422C42500 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D1E4EC | 10_2_00007DF422D1E4EC |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D1C4B0 | 10_2_00007DF422D1C4B0 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C85A0C | 10_2_00007DF422C85A0C |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D1A9E4 | 10_2_00007DF422D1A9E4 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C5198C | 10_2_00007DF422C5198C |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C3F9A0 | 10_2_00007DF422C3F9A0 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C51B54 | 10_2_00007DF422C51B54 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422CB0AE4 | 10_2_00007DF422CB0AE4 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D12A7C | 10_2_00007DF422D12A7C |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422CDA790 | 10_2_00007DF422CDA790 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422CA1784 | 10_2_00007DF422CA1784 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C78910 | 10_2_00007DF422C78910 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D1E908 | 10_2_00007DF422D1E908 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C5D8B8 | 10_2_00007DF422C5D8B8 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D1EE3C | 10_2_00007DF422D1EE3C |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D57E4C | 10_2_00007DF422D57E4C |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D17D94 | 10_2_00007DF422D17D94 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422CD1D7C | 10_2_00007DF422CD1D7C |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C6CD74 | 10_2_00007DF422C6CD74 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C9CF24 | 10_2_00007DF422C9CF24 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C47E74 | 10_2_00007DF422C47E74 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C90EA0 | 10_2_00007DF422C90EA0 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D24C70 | 10_2_00007DF422D24C70 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422CA5BEC | 10_2_00007DF422CA5BEC |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D38D64 | 10_2_00007DF422D38D64 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422D3BD30 | 10_2_00007DF422D3BD30 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422C83D28 | 10_2_00007DF422C83D28 |
Source: C:\Windows\System32\svchost.exe | Code function: 10_2_00007DF422CFDC78 | 10_2_00007DF422CFDC78 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247479D210 | 13_2_000002247479D210 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247480E1EC | 13_2_000002247480E1EC |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247481F354 | 13_2_000002247481F354 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_0000022474751364 | 13_2_0000022474751364 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_0000022474790344 | 13_2_0000022474790344 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247474F408 | 13_2_000002247474F408 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247482C52C | 13_2_000002247482C52C |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_0000022474742500 | 13_2_0000022474742500 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247481E4EC | 13_2_000002247481E4EC |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247481EE3C | 13_2_000002247481EE3C |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_0000022474790EA0 | 13_2_0000022474790EA0 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_0000022474747E74 | 13_2_0000022474747E74 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_0000022474735FA0 | 13_2_0000022474735FA0 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247479CF24 | 13_2_000002247479CF24 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_0000022474786FB0 | 13_2_0000022474786FB0 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247481DFB4 | 13_2_000002247481DFB4 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247481EFBC | 13_2_000002247481EFBC |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_0000022474731058 | 13_2_0000022474731058 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247478D050 | 13_2_000002247478D050 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247485F008 | 13_2_000002247485F008 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247482C010 | 13_2_000002247482C010 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247479D100 | 13_2_000002247479D100 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247478F0C4 | 13_2_000002247478F0C4 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_00000224747840B4 | 13_2_00000224747840B4 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_0000022474785A0C | 13_2_0000022474785A0C |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_0000022474812A7C | 13_2_0000022474812A7C |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247481A9E4 | 13_2_000002247481A9E4 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_0000022474751B54 | 13_2_0000022474751B54 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_00000224747A5BEC | 13_2_00000224747A5BEC |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_00000224747FDC78 | 13_2_00000224747FDC78 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_0000022474838D64 | 13_2_0000022474838D64 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_0000022474817D94 | 13_2_0000022474817D94 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247476CD74 | 13_2_000002247476CD74 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_0000022474783D28 | 13_2_0000022474783D28 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_00000224747AD610 | 13_2_00000224747AD610 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247479D668 | 13_2_000002247479D668 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_00000224747856C0 | 13_2_00000224747856C0 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_00000224747DA790 | 13_2_00000224747DA790 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_00000224747A1784 | 13_2_00000224747A1784 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247473286C | 13_2_000002247473286C |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_0000022474778910 | 13_2_0000022474778910 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247475D8B8 | 13_2_000002247475D8B8 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247473F9A0 | 13_2_000002247473F9A0 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247475198C | 13_2_000002247475198C |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Code function: 13_2_000002247481E908 | 13_2_000002247481E908 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00000245CB641F40 | 23_3_00000245CB641F40 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00000245CB641716 | 23_3_00000245CB641716 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00000245CB642724 | 23_3_00000245CB642724 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00000245CB64366C | 23_3_00000245CB64366C |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00000245CB640283 | 23_3_00000245CB640283 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C62204 | 23_3_00007DF448C62204 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C62204 | 23_3_00007DF448C62204 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C64EFC | 23_3_00007DF448C64EFC |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C6392C | 23_3_00007DF448C6392C |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C62520 | 23_3_00007DF448C62520 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C53838 | 23_3_00007DF448C53838 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C51AD0 | 23_3_00007DF448C51AD0 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C5147C | 23_3_00007DF448C5147C |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C5CC44 | 23_3_00007DF448C5CC44 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C5C640 | 23_3_00007DF448C5C640 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C5323C | 23_3_00007DF448C5323C |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C5F254 | 23_3_00007DF448C5F254 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C62204 | 23_3_00007DF448C62204 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C62204 | 23_3_00007DF448C62204 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C607E8 | 23_3_00007DF448C607E8 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C559DC | 23_3_00007DF448C559DC |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C59FAC | 23_3_00007DF448C59FAC |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C5B5A0 | 23_3_00007DF448C5B5A0 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C6392C | 23_3_00007DF448C6392C |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C55540 | 23_3_00007DF448C55540 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C6392C | 23_3_00007DF448C6392C |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C63942 | 23_3_00007DF448C63942 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C55F68 | 23_3_00007DF448C55F68 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C5AD54 | 23_3_00007DF448C5AD54 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C5BD10 | 23_3_00007DF448C5BD10 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C5A328 | 23_3_00007DF448C5A328 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C6392C | 23_3_00007DF448C6392C |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C6392C | 23_3_00007DF448C6392C |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C5A918 | 23_3_00007DF448C5A918 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C5FB14 | 23_3_00007DF448C5FB14 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C62520 | 23_3_00007DF448C62520 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C5B0B4 | 23_3_00007DF448C5B0B4 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C536F0 | 23_3_00007DF448C536F0 |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Code function: 23_3_00007DF448C5769C | 23_3_00007DF448C5769C |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_03282328 | 25_3_03282328 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_03260330 | 25_3_03260330 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032E2330 | 25_3_032E2330 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032B4340 | 25_3_032B4340 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032BE3A0 | 25_3_032BE3A0 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0324C3E0 | 25_3_0324C3E0 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032FE226 | 25_3_032FE226 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_03240259 | 25_3_03240259 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_03252290 | 25_3_03252290 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032FC293 | 25_3_032FC293 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032FE2DB | 25_3_032FE2DB |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0324A100 | 25_3_0324A100 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032DC11F | 25_3_032DC11F |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_2_00B07549 | 25_2_00B07549 |
Source: unknown | Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noLogo -ExecutionPolicy unrestricted -file "C:\Users\user\Desktop\f38186770bffa4a12a7170942b9c0d71ac736142924da24a.ps1" | |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Windows\System32\notepad.exe "C:\Windows\System32\notepad.exe" "C:\Users\user\Desktop\f38186770bffa4a12a7170942b9c0d71ac736142924da24a.ps1" | |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" | |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process created: C:\Windows\SysWOW64\svchost.exe "C:\Windows\System32\svchost.exe" | |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 9152 -s 532 | |
Source: C:\Windows\SysWOW64\svchost.exe | Process created: C:\Windows\System32\svchost.exe "C:\Windows\System32\svchost.exe" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" | |
Source: unknown | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe" | |
Source: unknown | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe" | |
Source: unknown | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe" | |
Source: unknown | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe --user-data-dir="C:\Users\user\AppData\Local\Temp\chr2ED9.tmp" --explicitly-allowed-ports=8000 --disable-gpu --new-window "http://127.0.0.1:8000/3dd821bd/c462449b" | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2372,i,17367199698315043982,10504146810115243822,262144 --variations-seed-version --mojo-platform-channel-handle=2424 /prefetch:3 | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --user-data-dir="C:\Users\user\AppData\Local\Temp\chr36E9.tmp" --explicitly-allowed-ports=8000 --disable-gpu --new-window "http://127.0.0.1:8000/3dd821bd/c7af6c55" | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2444 --field-trial-handle=2028,i,6020323842153141009,18313218026254877854,262144 /prefetch:3 | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Windows Media Player\wmpnscfg.exe "C:\Program Files\Windows Media Player\wmpnscfg.exe" | |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Process created: C:\Windows\System32\dllhost.exe "C:\Windows\system32\dllhost.exe" | |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Process created: C:\Windows\SysWOW64\svchost.exe "C:\Windows\System32\svchost.exe" | |
Source: C:\Windows\SysWOW64\svchost.exe | Process created: C:\Windows\System32\svchost.exe "C:\Windows\System32\svchost.exe" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" | |
Source: unknown | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe" | |
Source: unknown | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe" | |
Source: unknown | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe" | |
Source: unknown | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe --user-data-dir="C:\Users\user\AppData\Local\Temp\chrF4BA.tmp" --explicitly-allowed-ports=8000 --disable-gpu --new-window "http://127.0.0.1:8000/fd0371dc/c462449b" | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2228,i,724619310003278838,16624656589504802511,262144 --variations-seed-version --mojo-platform-channel-handle=2272 /prefetch:3 | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --user-data-dir="C:\Users\user\AppData\Local\Temp\chrF94E.tmp" --explicitly-allowed-ports=8000 --disable-gpu --new-window "http://127.0.0.1:8000/fd0371dc/c7af6c55" | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2144 --field-trial-handle=2092,i,4896275505363065535,15071639892316473483,262144 /prefetch:3 | |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process created: C:\Windows\SysWOW64\svchost.exe "C:\Windows\System32\svchost.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Process created: C:\Windows\System32\svchost.exe "C:\Windows\System32\svchost.exe" | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe --user-data-dir="C:\Users\user\AppData\Local\Temp\chr2ED9.tmp" --explicitly-allowed-ports=8000 --disable-gpu --new-window "http://127.0.0.1:8000/3dd821bd/c462449b" | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --user-data-dir="C:\Users\user\AppData\Local\Temp\chr36E9.tmp" --explicitly-allowed-ports=8000 --disable-gpu --new-window "http://127.0.0.1:8000/3dd821bd/c7af6c55" | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Windows Media Player\wmpnscfg.exe "C:\Program Files\Windows Media Player\wmpnscfg.exe" | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2372,i,17367199698315043982,10504146810115243822,262144 --variations-seed-version --mojo-platform-channel-handle=2424 /prefetch:3 | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2444 --field-trial-handle=2028,i,6020323842153141009,18313218026254877854,262144 /prefetch:3 | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Process created: C:\Windows\System32\dllhost.exe "C:\Windows\system32\dllhost.exe" | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Process created: C:\Windows\SysWOW64\svchost.exe "C:\Windows\System32\svchost.exe" | |
Source: C:\Windows\SysWOW64\svchost.exe | Process created: C:\Windows\System32\svchost.exe "C:\Windows\System32\svchost.exe" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe --user-data-dir="C:\Users\user\AppData\Local\Temp\chrF4BA.tmp" --explicitly-allowed-ports=8000 --disable-gpu --new-window "http://127.0.0.1:8000/fd0371dc/c462449b" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --user-data-dir="C:\Users\user\AppData\Local\Temp\chrF94E.tmp" --explicitly-allowed-ports=8000 --disable-gpu --new-window "http://127.0.0.1:8000/fd0371dc/c7af6c55" | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2228,i,724619310003278838,16624656589504802511,262144 --variations-seed-version --mojo-platform-channel-handle=2272 /prefetch:3 | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2144 --field-trial-handle=2092,i,4896275505363065535,15071639892316473483,262144 /prefetch:3 | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: mrmcorer.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: efswrt.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\System32\notepad.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Section loaded: uxtheme.dll | |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Section loaded: secur32.dll | |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Section loaded: dpapi.dll | |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Section loaded: taskschd.dll | |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Section loaded: xmllite.dll | |
Source: C:\Windows\System32\dllhost.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\dllhost.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\dllhost.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\System32\dllhost.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: msi.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: netapi32.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: wtsapi32.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: msimg32.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: wininet.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: wkscli.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: cscapi.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: dbghelp.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: dbgcore.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: dbghelp.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: dbgcore.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: dpapi.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: rasadhlp.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Section loaded: windowscodecs.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: powrprof.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: umpdc.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: devobj.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: drprov.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: winsta.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: ntlanman.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: davclnt.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: davhlpr.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: netapi32.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: rasadhlp.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: cscapi.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dbghelp.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: sxs.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dpapi.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dbghelp.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dbghelp.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dbghelp.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Program Files\Windows Media Player\wmpnscfg.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\dllhost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\dllhost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\svchost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: svchost.exe, 0000000A.00000003.1953083654.00000176A6DC9000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: SCSI#Disk&Ven_VMware&Prod_Virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}SymbolicLinkymbolicLinkcLinkSymbolicLink |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Canara Transaction PasswordVMware20,11696428655x |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: discord.comVMware20,11696428655f |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: interactivebrokers.co.inVMware20,11696428655d |
Source: svchost.exe, 0000000A.00000002.2355327636.00000176A6C13000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW@8 |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - COM.HKVMware20,11696428655 |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: global block list test formVMware20,11696428655 |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Canara Transaction PasswordVMware20,11696428655} |
Source: svchost.exe, 00000006.00000002.1824640212.0000000003000000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000006.00000002.1824860537.0000000003069000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 0000000A.00000002.2355327636.00000176A6C13000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW |
Source: svchost.exe, 00000006.00000002.1824705546.0000000003012000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW( |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - EU East & CentralVMware20,11696428655 |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655^ |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: account.microsoft.com/profileVMware20,11696428655u |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: secure.bankofamerica.comVMware20,11696428655|UE |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: www.interactivebrokers.comVMware20,11696428655} |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - GDCDYNVMware20,11696428655p |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - EU WestVMware20,11696428655n |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: outlook.office365.comVMware20,11696428655t |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: microsoft.visualstudio.comVMware20,11696428655x |
Source: powershell.exe, 00000000.00000002.1763807176.00000000027D2000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655 |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: outlook.office.comVMware20,11696428655s |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: www.interactivebrokers.co.inVMware20,11696428655~ |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ms.portal.azure.comVMware20,11696428655 |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: AMC password management pageVMware20,11696428655 |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: tasks.office.comVMware20,11696428655o |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - NDCDYNVMware20,11696428655z |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: turbotax.intuit.comVMware20,11696428655t |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: interactivebrokers.comVMware20,11696428655 |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696428655 |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: dev.azure.comVMware20,11696428655j |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: netportal.hdfcbank.comVMware20,11696428655 |
Source: svchost.exe, 00000006.00000002.1825146308.00000000032A0000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: /5VQEmU+ |
Source: svchost.exe, 00000006.00000003.1765553355.00000000053D0000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: DisableGuestVmNetworkConnectivity |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - HKVMware20,11696428655] |
Source: svchost.exe, 00000006.00000003.1765553355.00000000053D0000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: EnableGuestVmNetworkConnectivity |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: bankofamerica.comVMware20,11696428655x |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: trackpan.utiitsl.comVMware20,11696428655h |
Source: svchost.exe, 0000000A.00000003.1999547230.00000176A7B6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Test URL for global passwords blocklistVMware20,11696428655 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Code function: 5_2_041B0277 mov eax, dword ptr fs:[00000030h] | 5_2_041B0277 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 6_3_02C40283 mov eax, dword ptr fs:[00000030h] | 6_3_02C40283 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0325E328 mov eax, dword ptr fs:[00000030h] | 25_3_0325E328 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032E6300 mov eax, dword ptr fs:[00000030h] | 25_3_032E6300 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_03232312 mov eax, dword ptr fs:[00000030h] | 25_3_03232312 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0326C31F mov eax, dword ptr fs:[00000030h] | 25_3_0326C31F |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0325A369 mov eax, dword ptr fs:[00000030h] | 25_3_0325A369 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0325A369 mov eax, dword ptr fs:[00000030h] | 25_3_0325A369 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032D2360 mov eax, dword ptr fs:[00000030h] | 25_3_032D2360 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032D2360 mov eax, dword ptr fs:[00000030h] | 25_3_032D2360 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_03304368 mov eax, dword ptr fs:[00000030h] | 25_3_03304368 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032B4340 mov eax, dword ptr fs:[00000030h] | 25_3_032B4340 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032B4340 mov eax, dword ptr fs:[00000030h] | 25_3_032B4340 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032B4340 mov eax, dword ptr fs:[00000030h] | 25_3_032B4340 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032B4340 mov eax, dword ptr fs:[00000030h] | 25_3_032B4340 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032D4342 mov eax, dword ptr fs:[00000030h] | 25_3_032D4342 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0322C350 mov eax, dword ptr fs:[00000030h] | 25_3_0322C350 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0322C350 mov eax, dword ptr fs:[00000030h] | 25_3_0322C350 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0322C350 mov eax, dword ptr fs:[00000030h] | 25_3_0322C350 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0322C350 mov eax, dword ptr fs:[00000030h] | 25_3_0322C350 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0322C350 mov eax, dword ptr fs:[00000030h] | 25_3_0322C350 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0322C350 mov eax, dword ptr fs:[00000030h] | 25_3_0322C350 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0326C350 mov eax, dword ptr fs:[00000030h] | 25_3_0326C350 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032D0350 mov eax, dword ptr fs:[00000030h] | 25_3_032D0350 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0326C380 mov eax, dword ptr fs:[00000030h] | 25_3_0326C380 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_03262398 mov eax, dword ptr fs:[00000030h] | 25_3_03262398 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_03262398 mov eax, dword ptr fs:[00000030h] | 25_3_03262398 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0324C3E0 mov eax, dword ptr fs:[00000030h] | 25_3_0324C3E0 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0324C3E0 mov eax, dword ptr fs:[00000030h] | 25_3_0324C3E0 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032703F6 mov eax, dword ptr fs:[00000030h] | 25_3_032703F6 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032703F6 mov eax, dword ptr fs:[00000030h] | 25_3_032703F6 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032703F6 mov eax, dword ptr fs:[00000030h] | 25_3_032703F6 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032703F6 mov eax, dword ptr fs:[00000030h] | 25_3_032703F6 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_033043E7 mov eax, dword ptr fs:[00000030h] | 25_3_033043E7 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032E63F7 mov eax, dword ptr fs:[00000030h] | 25_3_032E63F7 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032323C8 mov eax, dword ptr fs:[00000030h] | 25_3_032323C8 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032323C8 mov eax, dword ptr fs:[00000030h] | 25_3_032323C8 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032323C8 mov eax, dword ptr fs:[00000030h] | 25_3_032323C8 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0322E3D8 mov eax, dword ptr fs:[00000030h] | 25_3_0322E3D8 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0322E3D8 mov eax, dword ptr fs:[00000030h] | 25_3_0322E3D8 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0322E3D8 mov eax, dword ptr fs:[00000030h] | 25_3_0322E3D8 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032C6220 mov eax, dword ptr fs:[00000030h] | 25_3_032C6220 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032C6220 mov eax, dword ptr fs:[00000030h] | 25_3_032C6220 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032C6220 mov ecx, dword ptr fs:[00000030h] | 25_3_032C6220 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0325A200 mov eax, dword ptr fs:[00000030h] | 25_3_0325A200 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0325A200 mov eax, dword ptr fs:[00000030h] | 25_3_0325A200 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0325A200 mov eax, dword ptr fs:[00000030h] | 25_3_0325A200 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0325A200 mov ecx, dword ptr fs:[00000030h] | 25_3_0325A200 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0325A200 mov eax, dword ptr fs:[00000030h] | 25_3_0325A200 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0325A200 mov eax, dword ptr fs:[00000030h] | 25_3_0325A200 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0325A200 mov eax, dword ptr fs:[00000030h] | 25_3_0325A200 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0325A200 mov eax, dword ptr fs:[00000030h] | 25_3_0325A200 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0325A200 mov eax, dword ptr fs:[00000030h] | 25_3_0325A200 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0325A200 mov eax, dword ptr fs:[00000030h] | 25_3_0325A200 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0322821D mov eax, dword ptr fs:[00000030h] | 25_3_0322821D |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_03236271 mov eax, dword ptr fs:[00000030h] | 25_3_03236271 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032B027F mov eax, dword ptr fs:[00000030h] | 25_3_032B027F |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032B027F mov eax, dword ptr fs:[00000030h] | 25_3_032B027F |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032B027F mov eax, dword ptr fs:[00000030h] | 25_3_032B027F |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0322E25A mov eax, dword ptr fs:[00000030h] | 25_3_0322E25A |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0330224F mov eax, dword ptr fs:[00000030h] | 25_3_0330224F |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0330224F mov eax, dword ptr fs:[00000030h] | 25_3_0330224F |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032BC2A0 mov eax, dword ptr fs:[00000030h] | 25_3_032BC2A0 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032BC2A0 mov eax, dword ptr fs:[00000030h] | 25_3_032BC2A0 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032BC2A0 mov eax, dword ptr fs:[00000030h] | 25_3_032BC2A0 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032CA2B0 mov eax, dword ptr fs:[00000030h] | 25_3_032CA2B0 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032CA2B0 mov eax, dword ptr fs:[00000030h] | 25_3_032CA2B0 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0322A290 mov eax, dword ptr fs:[00000030h] | 25_3_0322A290 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0322A290 mov eax, dword ptr fs:[00000030h] | 25_3_0322A290 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0322A290 mov eax, dword ptr fs:[00000030h] | 25_3_0322A290 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0326229C mov eax, dword ptr fs:[00000030h] | 25_3_0326229C |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0326229C mov ecx, dword ptr fs:[00000030h] | 25_3_0326229C |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032362E0 mov eax, dword ptr fs:[00000030h] | 25_3_032362E0 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032362E0 mov eax, dword ptr fs:[00000030h] | 25_3_032362E0 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032362E0 mov eax, dword ptr fs:[00000030h] | 25_3_032362E0 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032362E0 mov eax, dword ptr fs:[00000030h] | 25_3_032362E0 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032682F5 mov eax, dword ptr fs:[00000030h] | 25_3_032682F5 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032E62D0 mov ecx, dword ptr fs:[00000030h] | 25_3_032E62D0 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_03304130 mov eax, dword ptr fs:[00000030h] | 25_3_03304130 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032B8120 mov eax, dword ptr fs:[00000030h] | 25_3_032B8120 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0324A100 mov eax, dword ptr fs:[00000030h] | 25_3_0324A100 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0324A100 mov eax, dword ptr fs:[00000030h] | 25_3_0324A100 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0324A100 mov eax, dword ptr fs:[00000030h] | 25_3_0324A100 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_03226110 mov eax, dword ptr fs:[00000030h] | 25_3_03226110 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_03226110 mov eax, dword ptr fs:[00000030h] | 25_3_03226110 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_03226110 mov eax, dword ptr fs:[00000030h] | 25_3_03226110 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_0326411D mov eax, dword ptr fs:[00000030h] | 25_3_0326411D |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032E8110 mov eax, dword ptr fs:[00000030h] | 25_3_032E8110 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032E8110 mov eax, dword ptr fs:[00000030h] | 25_3_032E8110 |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_3_032C816B mov eax, dword ptr fs:[00000030h] | 25_3_032C816B |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_2_00B07BBC mov eax, dword ptr fs:[00000030h] | 25_2_00B07BBC |
Source: C:\Users\user\AppData\Roaming\Avt\AvastBrowserUpdate.exe | Code function: 25_2_035401F1 mov eax, dword ptr fs:[00000030h] | 25_2_035401F1 |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_metadata_store |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\mdpkiolbdkhdjpekfbkbmhigcaggjagi\Icons Maskable |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_prediction_model_downloads\031db23f-f53a-4d6b-b429-cd0302ef56d3 |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Cache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_prediction_model_downloads\6490c938-fe3f-48ae-bc5e-e1986298f7c1 |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync App Settings |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\fhihpiojkbmbpdjeoajapmgkhlnakfjf\Icons |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Safe Browsing Network |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\Files |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\fmgjjmmmlfnkbppncabfkddbjimcfncm\Icons |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\mdpkiolbdkhdjpekfbkbmhigcaggjagi |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\agimnkijcaahngcdmfeangaknmldooml\Icons Monochrome |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_prediction_model_downloads\a5f61848-f128-4a80-965b-a3000feed295 |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\js\index-dir |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\fmgjjmmmlfnkbppncabfkddbjimcfncm |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\coupon_db |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\kefjledonklijopmnomlcbpllchaibag\Icons |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\mdpkiolbdkhdjpekfbkbmhigcaggjagi\Icons Monochrome |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\agimnkijcaahngcdmfeangaknmldooml |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\fmgjjmmmlfnkbppncabfkddbjimcfncm\Icons Monochrome |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\index-dir |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\DawnCache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\agimnkijcaahngcdmfeangaknmldooml\Icons Maskable |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\wasm\index-dir |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\fmgjjmmmlfnkbppncabfkddbjimcfncm\Icons Maskable |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\kefjledonklijopmnomlcbpllchaibag |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnCache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Scripts |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\WebStorage |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\wasm |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sessions |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\fhihpiojkbmbpdjeoajapmgkhlnakfjf |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\affceca8-5877-40b6-92a1-68308b316b66 |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Shared Dictionary\cache\index-dir |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Shared Dictionary\cache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\mdpkiolbdkhdjpekfbkbmhigcaggjagi\Icons |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalStorageConfigDB |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\fhihpiojkbmbpdjeoajapmgkhlnakfjf\Icons Maskable |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\js |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\aghbiahbpaijignceidepookljebhfak\Icons Monochrome |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_prediction_model_downloads\58ef9818-5ea1-49a0-b5b0-9338401a7943 |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\kefjledonklijopmnomlcbpllchaibag\Icons Monochrome |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Shared Dictionary |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\mpnpojknpmmopombnjdcgaaiekajbnjb\Icons Maskable |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDB |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_prediction_model_downloads |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\fhihpiojkbmbpdjeoajapmgkhlnakfjf\Icons Monochrome |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnWebGPUCache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_prediction_model_downloads\15702f96-fbc1-4934-99bf-a9a7406c1be7 |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnGraphiteCache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\mpnpojknpmmopombnjdcgaaiekajbnjb\Icons Monochrome |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\aghbiahbpaijignceidepookljebhfak\Icons |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\agimnkijcaahngcdmfeangaknmldooml\Icons |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\discounts_db |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\aghbiahbpaijignceidepookljebhfak |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Network |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\mpnpojknpmmopombnjdcgaaiekajbnjb\Icons |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GPUCache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\kefjledonklijopmnomlcbpllchaibag\Icons Maskable |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dir |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Cache\Cache_Data |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\aghbiahbpaijignceidepookljebhfak\Icons Maskable |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\mpnpojknpmmopombnjdcgaaiekajbnjb |