Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb389926d19fe6595cd66946951e91fcd85210 | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb387926d19fe6595cd66946951e91fcd85210 | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38f842a1cec7a86d87bdb6546ad12dac02909e811d61329366be8eb43a8ec4cdb8eec906920dff156d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949cc7432f1dc0e | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38f862a1cec7a86d87bdb6546ad12dac02909e811d61329366be8eb43a8ec4cdb8eec906920dff156d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949cc7432f1dc0e | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38f852a1cec7a86d87bdb6546ad12dac02909e811d61329366be8eb43a8ec4cdb8eec906920dff156d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949cc7432f1dc0e | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb386926d19fe6595cd66946951e91fcd85210 | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38a926d19fe6595cd66946851e91fcd85241 | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38f872a1cec7a86d87bdb6546ad12dac02909e811d61329366be8eb43a8ec4cdb8eec906920dff156d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949cc7432f1dc0e | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb388926d19fe6595cd66946951e91fcd85210 | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38a926d19fe6595cd66946851e91fcd85241ab258d81329326be8ef43a8f51f8a95b5cd212a91f953c588fb52d6db9f51a9a0a29d5954cad713479a672918d4348dd1d6925549c1 | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38b926d19fe6595cd66946851e91fcd85241 | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38f842a1cec7a86d87bdb6546ad12dac0290 | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38f872a1cec7a86d87bdb6546ad12dac0290 | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38f862a1cec7a86d87bdb6546ad12dac0290 | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb386926d19fe6595cd66946951e91fcd85210ee31bd505672e26e5fd09b4a145c9c4e9976278d7f0449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c4dcd763cf8d5 | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb387926d19fe6595cd66946951e91fcd85210ee31bd505672e26e5fd09b4a145c9c4e9976278d7f0449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c4dcd763cf8d5 | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb389926d19fe6595cd66946951e91fcd85210ee31bd505672e26e5fd09b4a145c9c4e9976278d7f0449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c4dcd763cf8d5 | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38f852a1cec7a86d87bdb6546ad12dac0290 | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb388926d19fe6595cd66946951e91fcd85210ee31bd505672e26e5fd09b4a145c9c4e9976278d7f0449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c4dcd763cf8d5 | Avira URL Cloud: Label: malware |
Source: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38b926d19fe6595cd66946851e91fcd85241ab258d81329326be8ef43a8f51f8a95b5cd212a91f953c588fb52d6db9f51a9a0a29d5954cad713479a672918d4348dd1d6925549c1 | Avira URL Cloud: Label: malware |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.113.115.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 95.215.206.151 |
Source: unknown | TCP traffic detected without corresponding DNS query: 95.215.206.151 |
Source: is-5LK4E.tmp.1.dr, is-1K3IJ.tmp.1.dr | String found in binary or memory: http://icu-project.org |
Source: svchost.exe, 00000003.00000002.1364793231.0000021FE6013000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.bingmapsportal.com |
Source: eF5TnJ6Frr.tmp, eF5TnJ6Frr.tmp, 00000001.00000002.2464766278.0000000000401000.00000020.00000001.01000000.00000004.sdmp, eF5TnJ6Frr.tmp.0.dr, is-NAA2F.tmp.1.dr | String found in binary or memory: http://www.innosetup.com/ |
Source: eF5TnJ6Frr.exe | String found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdline |
Source: eF5TnJ6Frr.exe | String found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU |
Source: eF5TnJ6Frr.exe, 00000000.00000003.1223562867.0000000002350000.00000004.00001000.00020000.00000000.sdmp, eF5TnJ6Frr.exe, 00000000.00000003.1223695253.0000000002088000.00000004.00001000.00020000.00000000.sdmp, eF5TnJ6Frr.tmp, eF5TnJ6Frr.tmp, 00000001.00000002.2464766278.0000000000401000.00000020.00000001.01000000.00000004.sdmp, eF5TnJ6Frr.tmp.0.dr, is-NAA2F.tmp.1.dr | String found in binary or memory: http://www.remobjects.com/ps |
Source: eF5TnJ6Frr.exe, 00000000.00000003.1223562867.0000000002350000.00000004.00001000.00020000.00000000.sdmp, eF5TnJ6Frr.exe, 00000000.00000003.1223695253.0000000002088000.00000004.00001000.00020000.00000000.sdmp, eF5TnJ6Frr.tmp, 00000001.00000002.2464766278.0000000000401000.00000020.00000001.01000000.00000004.sdmp, eF5TnJ6Frr.tmp.0.dr, is-NAA2F.tmp.1.dr | String found in binary or memory: http://www.remobjects.com/psU |
Source: defragtoolspro.exe, 00000002.00000002.2465600216.0000000000A2C000.00000004.00000020.00020000.00000000.sdmp, defragtoolspro.exe, 00000002.00000003.2098151119.0000000003348000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://176.113.115.96/ |
Source: defragtoolspro.exe, 00000002.00000003.2098151119.0000000003348000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://176.113.115.96/- |
Source: defragtoolspro.exe, 00000002.00000002.2465600216.0000000000A2C000.00000004.00000020.00020000.00000000.sdmp, defragtoolspro.exe, 00000002.00000003.2098168723.0000000000A40000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38c926d19fe6595cd66946851e91fcd85241 |
Source: defragtoolspro.exe, 00000002.00000002.2465600216.0000000000A45000.00000004.00000020.00020000.00000000.sdmp, defragtoolspro.exe, 00000002.00000002.2467457722.0000000003340000.00000004.00000020.00020000.00000000.sdmp, defragtoolspro.exe, 00000002.00000003.2098168723.0000000000A45000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38d926d19fe6595cd66946851e91fcd85241 |
Source: defragtoolspro.exe, 00000002.00000002.2465600216.0000000000A2C000.00000004.00000020.00020000.00000000.sdmp, defragtoolspro.exe, 00000002.00000003.2098168723.0000000000A40000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38f926d19fe6595cd66946851e91fcd85241 |
Source: defragtoolspro.exe, 00000002.00000002.2467457722.000000000334D000.00000004.00000020.00020000.00000000.sdmp, defragtoolspro.exe, 00000002.00000002.2467457722.0000000003344000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://95.215.206.151/ |
Source: defragtoolspro.exe, 00000002.00000002.2467457722.0000000003388000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb386926d19fe6595cd66946951e91fcd85210 |
Source: defragtoolspro.exe, 00000002.00000002.2467457722.0000000003388000.00000004.00000020.00020000.00000000.sdmp, defragtoolspro.exe, 00000002.00000002.2467457722.0000000003344000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb387926d19fe6595cd66946951e91fcd85210 |
Source: defragtoolspro.exe, 00000002.00000002.2465600216.0000000000A2C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb388926d19fe6595cd66946951e91fcd85210 |
Source: defragtoolspro.exe, 00000002.00000002.2467457722.0000000003388000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb389926d19fe6595cd66946951e91fcd85210 |
Source: defragtoolspro.exe, 00000002.00000002.2465600216.0000000000A2C000.00000004.00000020.00020000.00000000.sdmp, defragtoolspro.exe, 00000002.00000002.2465600216.0000000000A45000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38a926d19fe6595cd66946851e91fcd85241 |
Source: defragtoolspro.exe, 00000002.00000002.2467457722.0000000003388000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38b926d19fe6595cd66946851e91fcd85241 |
Source: defragtoolspro.exe, 00000002.00000002.2467457722.0000000003340000.00000004.00000020.00020000.00000000.sdmp, defragtoolspro.exe, 00000002.00000002.2467457722.0000000003388000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38f842a1cec7a86d87bdb6546ad12dac0290 |
Source: defragtoolspro.exe, 00000002.00000002.2467457722.0000000003388000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38f852a1cec7a86d87bdb6546ad12dac0290 |
Source: defragtoolspro.exe, 00000002.00000002.2467457722.000000000334D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38f862a1cec7a86d87bdb6546ad12dac0290 |
Source: defragtoolspro.exe, 00000002.00000002.2467457722.000000000334D000.00000004.00000020.00020000.00000000.sdmp, defragtoolspro.exe, 00000002.00000002.2465600216.0000000000A0E000.00000004.00000020.00020000.00000000.sdmp, defragtoolspro.exe, 00000002.00000002.2467457722.0000000003344000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://95.215.206.151/ai/?key=8f3f2b3ab14e166f251de6a5231678fbb38f872a1cec7a86d87bdb6546ad12dac0290 |
Source: defragtoolspro.exe, 00000002.00000002.2465600216.0000000000A2C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://95.215.206.151/en-GB |
Source: defragtoolspro.exe, 00000002.00000002.2465600216.0000000000A2C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://95.215.206.151/en-US |
Source: defragtoolspro.exe, 00000002.00000002.2467457722.000000000334D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://95.215.206.151/icies |
Source: defragtoolspro.exe, 00000002.00000002.2467457722.000000000334D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://95.215.206.151/rosoft |
Source: svchost.exe, 00000003.00000003.1364372767.0000021FE6058000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://appexmapsappupdate.blob.core.windows.net |
Source: svchost.exe, 00000003.00000003.1364372767.0000021FE6058000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364864148.0000021FE6059000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.ditu.live.com/REST/V1/MapControlConfiguration/native/ |
Source: svchost.exe, 00000003.00000003.1364294790.0000021FE6062000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000003.1364429472.0000021FE6041000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000003.1364207406.0000021FE606E000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000003.1364350172.0000021FE605E000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000003.1364407060.0000021FE605A000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000003.1364372767.0000021FE6058000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364837454.0000021FE6042000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364929038.0000021FE6063000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364956812.0000021FE6070000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.ditu.live.com/REST/v1/Imagery/Copyright/ |
Source: svchost.exe, 00000003.00000003.1364207406.0000021FE606E000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364956812.0000021FE6070000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.ditu.live.com/REST/v1/JsonFilter/VenueMaps/data/ |
Source: svchost.exe, 00000003.00000003.1364372767.0000021FE6058000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.ditu.live.com/REST/v1/Locations |
Source: svchost.exe, 00000003.00000002.1364943247.0000021FE6068000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000003.1364281984.0000021FE6067000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.ditu.live.com/REST/v1/Routes/ |
Source: svchost.exe, 00000003.00000003.1364094531.0000021FE6075000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364971379.0000021FE6077000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.ditu.live.com/REST/v1/Transit/Stops/ |
Source: svchost.exe, 00000003.00000003.1364372767.0000021FE6058000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.ditu.live.com/mapcontrol/logging.ashx |
Source: svchost.exe, 00000003.00000003.1364294790.0000021FE6062000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000003.1364407060.0000021FE605A000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000003.1364372767.0000021FE6058000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364929038.0000021FE6063000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364810207.0000021FE602B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Imagery/Copyright/ |
Source: svchost.exe, 00000003.00000003.1364372767.0000021FE6058000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Locations |
Source: svchost.exe, 00000003.00000002.1364943247.0000021FE6068000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000003.1364281984.0000021FE6067000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364810207.0000021FE602B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/ |
Source: svchost.exe, 00000003.00000003.1364372767.0000021FE6058000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Driving |
Source: svchost.exe, 00000003.00000003.1364372767.0000021FE6058000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Transit |
Source: svchost.exe, 00000003.00000003.1364372767.0000021FE6058000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Walking |
Source: svchost.exe, 00000003.00000003.1364294790.0000021FE6062000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364929038.0000021FE6063000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364810207.0000021FE602B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Traffic/Incidents/ |
Source: svchost.exe, 00000003.00000003.1364429472.0000021FE6041000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364837454.0000021FE6042000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Transit/Schedules/ |
Source: svchost.exe, 00000003.00000003.1364372767.0000021FE6058000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.virtualearth.net/mapcontrol/logging.ashx |
Source: svchost.exe, 00000003.00000003.1364294790.0000021FE6062000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364929038.0000021FE6063000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dev.virtualearth.net/webservices/v1/LoggingService/LoggingService.svc/Log? |
Source: svchost.exe, 00000003.00000002.1364837454.0000021FE6042000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364929038.0000021FE6063000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gd?pv=1&r= |
Source: svchost.exe, 00000003.00000002.1364837454.0000021FE6042000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gdi?pv=1&r= |
Source: svchost.exe, 00000003.00000003.1364294790.0000021FE6062000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364929038.0000021FE6063000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gdv?pv=1&r= |
Source: svchost.exe, 00000003.00000003.1364429472.0000021FE6041000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364837454.0000021FE6042000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gri?pv=1&r= |
Source: svchost.exe, 00000003.00000002.1364956812.0000021FE6070000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dynamic.t |
Source: svchost.exe, 00000003.00000003.1364372767.0000021FE6058000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://dynamic.t0.tiles.ditu.live.com/comp/gen.ashx |
Source: svchost.exe, 00000003.00000002.1364943247.0000021FE6068000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000003.1364281984.0000021FE6067000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364810207.0000021FE602B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ecn.dev.virtualearth.net/REST/v1/Imagery/Copyright/ |
Source: svchost.exe, 00000003.00000003.1364429472.0000021FE6041000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/comp/gen.ashx |
Source: svchost.exe, 00000003.00000002.1364837454.0000021FE6042000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gd?pv=1&r= |
Source: svchost.exe, 00000003.00000002.1364837454.0000021FE6042000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364864148.0000021FE6059000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdi?pv=1&r= |
Source: svchost.exe, 00000003.00000002.1364810207.0000021FE602B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gri?pv=1&r= |
Source: svchost.exe, 00000003.00000003.1364372767.0000021FE6058000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://t0.ssl.ak.tiles.virtualearth.net/tiles/gen |
Source: svchost.exe, 00000003.00000003.1364372767.0000021FE6058000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000003.00000002.1364864148.0000021FE6059000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tiles.virtualearth.net/tiles/cmd/StreetSideBubbleMetaData?north= |
Source: eF5TnJ6Frr.exe, 00000000.00000003.1223280972.0000000002081000.00000004.00001000.00020000.00000000.sdmp, eF5TnJ6Frr.exe, 00000000.00000003.1223217091.0000000002350000.00000004.00001000.00020000.00000000.sdmp, eF5TnJ6Frr.exe, 00000000.00000002.2465460091.0000000002081000.00000004.00001000.00020000.00000000.sdmp, eF5TnJ6Frr.tmp, 00000001.00000003.1224931810.0000000003130000.00000004.00001000.00020000.00000000.sdmp, eF5TnJ6Frr.tmp, 00000001.00000003.1224993868.0000000002258000.00000004.00001000.00020000.00000000.sdmp, eF5TnJ6Frr.tmp, 00000001.00000002.2465767756.000000000064E000.00000004.00000020.00020000.00000000.sdmp, eF5TnJ6Frr.tmp, 00000001.00000002.2466455866.0000000002258000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.easycutstudio.com/support.html |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49721 |
Source: unknown | Network traffic detected: HTTP traffic on port 49731 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49741 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49740 |
Source: unknown | Network traffic detected: HTTP traffic on port 49727 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49725 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49741 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49729 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49739 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49738 |
Source: unknown | Network traffic detected: HTTP traffic on port 49736 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49737 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49736 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49735 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49734 |
Source: unknown | Network traffic detected: HTTP traffic on port 49738 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49732 |
Source: unknown | Network traffic detected: HTTP traffic on port 49734 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49731 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49730 |
Source: unknown | Network traffic detected: HTTP traffic on port 49732 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49730 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49726 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49740 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49724 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49728 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49721 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49723 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49729 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49728 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49727 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49726 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49725 |
Source: unknown | Network traffic detected: HTTP traffic on port 49735 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49724 |
Source: unknown | Network traffic detected: HTTP traffic on port 49737 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49723 |
Source: unknown | Network traffic detected: HTTP traffic on port 49739 -> 443 |
Source: C:\Users\user\Desktop\eF5TnJ6Frr.exe | Code function: 0_2_0040840C | 0_2_0040840C |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00470C74 | 1_2_00470C74 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0043533C | 1_2_0043533C |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004813C4 | 1_2_004813C4 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00467848 | 1_2_00467848 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004303D0 | 1_2_004303D0 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0044453C | 1_2_0044453C |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004885E0 | 1_2_004885E0 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00434638 | 1_2_00434638 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00444AE4 | 1_2_00444AE4 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0048ED0C | 1_2_0048ED0C |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00430F5C | 1_2_00430F5C |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0045F16C | 1_2_0045F16C |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004451DC | 1_2_004451DC |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0045B21C | 1_2_0045B21C |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004455E8 | 1_2_004455E8 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00487680 | 1_2_00487680 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0046989C | 1_2_0046989C |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00451A30 | 1_2_00451A30 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0043DDC4 | 1_2_0043DDC4 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_00401000 | 2_2_00401000 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_004067B7 | 2_2_004067B7 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_609660FA | 2_2_609660FA |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6092114F | 2_2_6092114F |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6091F2C9 | 2_2_6091F2C9 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6096923E | 2_2_6096923E |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6093323D | 2_2_6093323D |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6095C314 | 2_2_6095C314 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60950312 | 2_2_60950312 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6094D33B | 2_2_6094D33B |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6093B368 | 2_2_6093B368 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6096748C | 2_2_6096748C |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6093F42E | 2_2_6093F42E |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60954470 | 2_2_60954470 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_609615FA | 2_2_609615FA |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6096A5EE | 2_2_6096A5EE |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6096D6A4 | 2_2_6096D6A4 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_609606A8 | 2_2_609606A8 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60932654 | 2_2_60932654 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60955665 | 2_2_60955665 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6094B7DB | 2_2_6094B7DB |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6092F74D | 2_2_6092F74D |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60964807 | 2_2_60964807 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6094E9BC | 2_2_6094E9BC |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60937929 | 2_2_60937929 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6093FAD6 | 2_2_6093FAD6 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6096DAE8 | 2_2_6096DAE8 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6094DA3A | 2_2_6094DA3A |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60936B27 | 2_2_60936B27 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60954CF6 | 2_2_60954CF6 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60950C6B | 2_2_60950C6B |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60966DF1 | 2_2_60966DF1 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60963D35 | 2_2_60963D35 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60909E9C | 2_2_60909E9C |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60951E86 | 2_2_60951E86 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60912E0B | 2_2_60912E0B |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60954FF8 | 2_2_60954FF8 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_02CEBAED | 2_2_02CEBAED |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_02CF2A70 | 2_2_02CF2A70 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_02CED31F | 2_2_02CED31F |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_02CE70B0 | 2_2_02CE70B0 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_02CDE071 | 2_2_02CDE071 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_02CF266D | 2_2_02CF266D |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_02CEBF05 | 2_2_02CEBF05 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_02CE873A | 2_2_02CE873A |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_02CEB5F9 | 2_2_02CEB5F9 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_02CF0DA4 | 2_2_02CF0DA4 |
Source: defragtoolspro.exe, defragtoolspro.exe, 00000002.00000002.2467969881.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, defragtoolspro.exe, 00000002.00000003.1244611693.000000000096F000.00000004.00000020.00020000.00000000.sdmp, sqlite3.dll.2.dr, is-MBT7C.tmp.1.dr | Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence'; |
Source: defragtoolspro.exe, 00000002.00000002.2467969881.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, defragtoolspro.exe, 00000002.00000003.1244611693.000000000096F000.00000004.00000020.00020000.00000000.sdmp, sqlite3.dll.2.dr, is-MBT7C.tmp.1.dr | Binary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q); |
Source: defragtoolspro.exe, defragtoolspro.exe, 00000002.00000002.2467969881.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, defragtoolspro.exe, 00000002.00000003.1244611693.000000000096F000.00000004.00000020.00020000.00000000.sdmp, sqlite3.dll.2.dr, is-MBT7C.tmp.1.dr | Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND coalesce(rootpage,1)>0 |
Source: defragtoolspro.exe, 00000002.00000002.2467969881.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, defragtoolspro.exe, 00000002.00000003.1244611693.000000000096F000.00000004.00000020.00020000.00000000.sdmp, sqlite3.dll.2.dr, is-MBT7C.tmp.1.dr | Binary or memory string: CREATE TABLE "%w"."%w_node"(nodeno INTEGER PRIMARY KEY, data BLOB);CREATE TABLE "%w"."%w_rowid"(rowid INTEGER PRIMARY KEY, nodeno INTEGER);CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY, parentnode INTEGER);INSERT INTO '%q'.'%q_node' VALUES(1, zeroblob(%d)) |
Source: defragtoolspro.exe, 00000002.00000002.2467969881.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, defragtoolspro.exe, 00000002.00000003.1244611693.000000000096F000.00000004.00000020.00020000.00000000.sdmp, sqlite3.dll.2.dr, is-MBT7C.tmp.1.dr | Binary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB); |
Source: defragtoolspro.exe, 00000002.00000002.2467969881.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, defragtoolspro.exe, 00000002.00000003.1244611693.000000000096F000.00000004.00000020.00020000.00000000.sdmp, sqlite3.dll.2.dr, is-MBT7C.tmp.1.dr | Binary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB); |
Source: defragtoolspro.exe, 00000002.00000002.2467969881.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, defragtoolspro.exe, 00000002.00000003.1244611693.000000000096F000.00000004.00000020.00020000.00000000.sdmp, sqlite3.dll.2.dr, is-MBT7C.tmp.1.dr | Binary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx)); |
Source: defragtoolspro.exe, 00000002.00000002.2467969881.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, defragtoolspro.exe, 00000002.00000003.1244611693.000000000096F000.00000004.00000020.00020000.00000000.sdmp, sqlite3.dll.2.dr, is-MBT7C.tmp.1.dr | Binary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s; |
Source: defragtoolspro.exe, 00000002.00000002.2467969881.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, defragtoolspro.exe, 00000002.00000003.1244611693.000000000096F000.00000004.00000020.00020000.00000000.sdmp, sqlite3.dll.2.dr, is-MBT7C.tmp.1.dr | Binary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s; |
Source: defragtoolspro.exe, 00000002.00000002.2467969881.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, defragtoolspro.exe, 00000002.00000003.1244611693.000000000096F000.00000004.00000020.00020000.00000000.sdmp, sqlite3.dll.2.dr, is-MBT7C.tmp.1.dr | Binary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB); |
Source: defragtoolspro.exe, 00000002.00000002.2467969881.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, defragtoolspro.exe, 00000002.00000003.1244611693.000000000096F000.00000004.00000020.00020000.00000000.sdmp, sqlite3.dll.2.dr, is-MBT7C.tmp.1.dr | Binary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger'); |
Source: defragtoolspro.exe, defragtoolspro.exe, 00000002.00000002.2467969881.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, defragtoolspro.exe, 00000002.00000003.1244611693.000000000096F000.00000004.00000020.00020000.00000000.sdmp, sqlite3.dll.2.dr, is-MBT7C.tmp.1.dr | Binary or memory string: SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence' |
Source: C:\Users\user\Desktop\eF5TnJ6Frr.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\eF5TnJ6Frr.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: msimg32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: msacm32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: riched20.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: msls31.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: explorerframe.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: sqlite3.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: moshost.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mapsbtsvc.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mosstorage.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ztrace_maps.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ztrace_maps.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mapconfiguration.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ztrace_maps.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: aphostservice.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: networkhelper.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: userdataplatformhelperutil.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: syncutil.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mccspal.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dmcfgutils.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dmcmnutils.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dmxmlhelputils.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: inproclogger.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: flightsettings.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: windows.networking.connectivity.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: npmproxy.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: msv1_0.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ntlmshared.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: cryptdll.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: synccontroller.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: pimstore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: aphostclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: accountaccessor.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dsclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: systemeventsbrokerclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: userdatalanguageutil.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mccsengineshared.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: pimstore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: cemapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: userdatatypehelperutil.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: phoneutil.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: execmodelproxy.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: rmclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: storsvc.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: fltlib.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: bcd.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wer.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: appxdeploymentclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: storageusage.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: mpclient.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: wscapi.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\eF5TnJ6Frr.exe | Code function: 0_2_004065C8 push 00406605h; ret | 0_2_004065FD |
Source: C:\Users\user\Desktop\eF5TnJ6Frr.exe | Code function: 0_2_004040B5 push eax; ret | 0_2_004040F1 |
Source: C:\Users\user\Desktop\eF5TnJ6Frr.exe | Code function: 0_2_00408104 push ecx; mov dword ptr [esp], eax | 0_2_00408109 |
Source: C:\Users\user\Desktop\eF5TnJ6Frr.exe | Code function: 0_2_00404185 push 00404391h; ret | 0_2_00404389 |
Source: C:\Users\user\Desktop\eF5TnJ6Frr.exe | Code function: 0_2_00404206 push 00404391h; ret | 0_2_00404389 |
Source: C:\Users\user\Desktop\eF5TnJ6Frr.exe | Code function: 0_2_0040C218 push eax; ret | 0_2_0040C219 |
Source: C:\Users\user\Desktop\eF5TnJ6Frr.exe | Code function: 0_2_004042E8 push 00404391h; ret | 0_2_00404389 |
Source: C:\Users\user\Desktop\eF5TnJ6Frr.exe | Code function: 0_2_00404283 push 00404391h; ret | 0_2_00404389 |
Source: C:\Users\user\Desktop\eF5TnJ6Frr.exe | Code function: 0_2_00408F38 push 00408F6Bh; ret | 0_2_00408F63 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004849F4 push 00484B02h; ret | 1_2_00484AFA |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0040995C push 00409999h; ret | 1_2_00409991 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00458060 push 00458098h; ret | 1_2_00458090 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004860E4 push ecx; mov dword ptr [esp], ecx | 1_2_004860E9 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004062C4 push ecx; mov dword ptr [esp], eax | 1_2_004062C5 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004783C8 push ecx; mov dword ptr [esp], edx | 1_2_004783C9 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004104F0 push ecx; mov dword ptr [esp], edx | 1_2_004104F5 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00412938 push 0041299Bh; ret | 1_2_00412993 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0049AD44 pushad ; retf | 1_2_0049AD53 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0040CE48 push ecx; mov dword ptr [esp], edx | 1_2_0040CE4A |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00459378 push 004593BCh; ret | 1_2_004593B4 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0040F3A8 push ecx; mov dword ptr [esp], edx | 1_2_0040F3AA |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0040546D push eax; ret | 1_2_004054A9 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004434B4 push ecx; mov dword ptr [esp], ecx | 1_2_004434B8 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0040553D push 00405749h; ret | 1_2_00405741 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004055BE push 00405749h; ret | 1_2_00405741 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0040563B push 00405749h; ret | 1_2_00405741 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004056A0 push 00405749h; ret | 1_2_00405741 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0045186C push 0045189Fh; ret | 1_2_00451897 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00451A30 push ecx; mov dword ptr [esp], eax | 1_2_00451A35 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00495BE4 push ecx; mov dword ptr [esp], ecx | 1_2_00495BE9 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00419C38 push ecx; mov dword ptr [esp], ecx | 1_2_00419C3D |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-O4E0F.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-5LK4E.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-J59BF.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-1K3IJ.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\libGLESv2.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\icuuc51.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-MBT7C.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Temp\is-H295N.tmp\_isetup\_setup64.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-IP43T.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\Qt5PrintSupport.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-Q018O.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | File created: C:\ProgramData\DefragToolsPro\sqlite3.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\icuin51.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | File created: C:\ProgramData\DefragToolsPro\DefragToolsPro.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Temp\is-H295N.tmp\_isetup\_iscrypt.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\eF5TnJ6Frr.exe | File created: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\Qt5Concurrent.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\sqlite3.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Temp\is-H295N.tmp\_isetup\_shfoldr.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\uninstall\is-NAA2F.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\msvcp100.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\libEGL.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\uninstall\unins000.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-8QM7V.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\msvcr100.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | File created: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-5NBFO.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00423C1C IsIconic,PostMessageA,PostMessageA,PostMessageA,SendMessageA,IsWindowEnabled,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, | 1_2_00423C1C |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00423C1C IsIconic,PostMessageA,PostMessageA,PostMessageA,SendMessageA,IsWindowEnabled,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, | 1_2_00423C1C |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004241EC IsIconic,SetActiveWindow,SetFocus, | 1_2_004241EC |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004241A4 IsIconic,SetActiveWindow, | 1_2_004241A4 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00418394 IsIconic,GetWindowPlacement,GetWindowRect,GetWindowLongA,GetWindowLongA,ScreenToClient,ScreenToClient, | 1_2_00418394 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004843A8 IsIconic,GetWindowLongA,ShowWindow,ShowWindow, | 1_2_004843A8 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0042286C SendMessageA,ShowWindow,ShowWindow,CallWindowProcA,SendMessageA,ShowWindow,SetWindowPos,GetActiveWindow,IsIconic,SetWindowPos,SetActiveWindow,ShowWindow, | 1_2_0042286C |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_0042F2F0 IsIconic,GetWindowLongA,GetWindowLongA,GetActiveWindow,MessageBoxA,SetActiveWindow,GetActiveWindow,MessageBoxA,SetActiveWindow, | 1_2_0042F2F0 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_004175A8 IsIconic,GetCapture, | 1_2_004175A8 |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00417CDE IsIconic,SetWindowPos, | 1_2_00417CDE |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Code function: 1_2_00417CE0 IsIconic,SetWindowPos,GetWindowPlacement,SetWindowPlacement, | 1_2_00417CE0 |
Source: C:\Users\user\Desktop\eF5TnJ6Frr.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Windows Defender\MpCmdRun.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-O4E0F.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-H295N.tmp\_isetup\_iscrypt.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-5LK4E.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-J59BF.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\Qt5Concurrent.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-1K3IJ.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\libGLESv2.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-H295N.tmp\_isetup\_shfoldr.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\icuuc51.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\uninstall\is-NAA2F.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\msvcp100.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-IP43T.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-H295N.tmp\_isetup\_setup64.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-MBT7C.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\libEGL.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\Qt5PrintSupport.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-Q018O.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\uninstall\unins000.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-8QM7V.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\msvcr100.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\is-5NBFO.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-OE1VH.tmp\eF5TnJ6Frr.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\icuin51.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_609660FA sqlite3_finalize,sqlite3_free,sqlite3_value_numeric_type,sqlite3_value_numeric_type,sqlite3_value_text,sqlite3_value_int,memcmp,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_strnicmp,sqlite3_mprintf,sqlite3_mprintf,sqlite3_malloc,sqlite3_free,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_bind_value, | 2_2_609660FA |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6090C1D6 sqlite3_clear_bindings,sqlite3_mutex_enter,sqlite3_mutex_leave, | 2_2_6090C1D6 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60963143 sqlite3_stricmp,sqlite3_bind_int64,sqlite3_mutex_leave, | 2_2_60963143 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6096A2BD sqlite3_bind_int64,sqlite3_step,sqlite3_column_int,sqlite3_reset, | 2_2_6096A2BD |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6096923E sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_malloc,sqlite3_malloc,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_realloc,sqlite3_realloc,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free,sqlite3_free, | 2_2_6096923E |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6096A38C sqlite3_bind_int,sqlite3_column_int,sqlite3_step,sqlite3_reset, | 2_2_6096A38C |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6096748C sqlite3_malloc,sqlite3_bind_int,sqlite3_step,sqlite3_column_blob,sqlite3_column_bytes,sqlite3_reset,sqlite3_bind_int,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_malloc,sqlite3_bind_int64,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int,sqlite3_step,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_reset,memcmp,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int,sqlite3_reset,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_bind_int64,sqlite3_realloc,sqlite3_column_int,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int,sqlite3_bind_int,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_bind_int,sqlite3_bind_blob,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free, | 2_2_6096748C |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_609254B1 sqlite3_bind_zeroblob,sqlite3_mutex_leave, | 2_2_609254B1 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6094B407 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_reset, | 2_2_6094B407 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6090F435 sqlite3_bind_parameter_index, | 2_2_6090F435 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_609255D4 sqlite3_mutex_leave,sqlite3_bind_text16, | 2_2_609255D4 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_609255FF sqlite3_bind_text, | 2_2_609255FF |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6096A5EE sqlite3_value_text,sqlite3_value_bytes,sqlite3_strnicmp,sqlite3_strnicmp,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_malloc,sqlite3_column_int,sqlite3_column_int64,sqlite3_column_text,sqlite3_column_bytes,sqlite3_finalize,sqlite3_step,sqlite3_free,sqlite3_finalize,sqlite3_strnicmp,sqlite3_bind_int,sqlite3_column_int,sqlite3_step,sqlite3_reset,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_column_int64,sqlite3_column_int,sqlite3_column_text,sqlite3_column_bytes,sqlite3_step,sqlite3_finalize,sqlite3_strnicmp,sqlite3_strnicmp,sqlite3_bind_int,sqlite3_bind_int,sqlite3_step,sqlite3_reset,sqlite3_value_int,sqlite3_malloc,sqlite3_bind_null,sqlite3_step,sqlite3_reset,sqlite3_value_int,sqlite3_value_text,sqlite3_value_bytes,sqlite3_free, | 2_2_6096A5EE |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6094B54C sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset,memmove, | 2_2_6094B54C |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60925686 sqlite3_bind_int64,sqlite3_mutex_leave, | 2_2_60925686 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6094A6C5 sqlite3_bind_int64,sqlite3_step,sqlite3_column_blob,sqlite3_column_bytes,sqlite3_malloc,sqlite3_reset,sqlite3_free, | 2_2_6094A6C5 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_609256E5 sqlite3_bind_int,sqlite3_bind_int64, | 2_2_609256E5 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6094B6ED sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step, | 2_2_6094B6ED |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6092562A sqlite3_bind_blob, | 2_2_6092562A |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60925655 sqlite3_bind_null,sqlite3_mutex_leave, | 2_2_60925655 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6094C64A sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_free, | 2_2_6094C64A |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_609687A7 sqlite3_bind_int64,sqlite3_bind_int,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int,sqlite3_step,sqlite3_column_blob,sqlite3_column_bytes,sqlite3_column_int64,sqlite3_reset,sqlite3_free,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_bind_int64,sqlite3_bind_int,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free, | 2_2_609687A7 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6095F7F7 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset, | 2_2_6095F7F7 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6092570B sqlite3_bind_double,sqlite3_mutex_leave, | 2_2_6092570B |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6095F772 sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_step,sqlite3_reset, | 2_2_6095F772 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60925778 sqlite3_bind_value,sqlite3_bind_int64,sqlite3_bind_double,sqlite3_bind_blob, | 2_2_60925778 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6090577D sqlite3_bind_parameter_name, | 2_2_6090577D |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6094B764 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step, | 2_2_6094B764 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6090576B sqlite3_bind_parameter_count, | 2_2_6090576B |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6094A894 sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset, | 2_2_6094A894 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6095F883 sqlite3_bind_int64,sqlite3_bind_int,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_step,sqlite3_reset, | 2_2_6095F883 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6094C8C2 sqlite3_value_int,sqlite3_value_int,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_null,sqlite3_bind_null,sqlite3_step,sqlite3_reset, | 2_2_6094C8C2 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6096281E sqlite3_mprintf,sqlite3_vtab_config,sqlite3_malloc,sqlite3_mprintf,sqlite3_mprintf,sqlite3_errmsg,sqlite3_mprintf,sqlite3_free,sqlite3_mprintf,sqlite3_exec,sqlite3_free,sqlite3_prepare_v2,sqlite3_bind_text,sqlite3_step,sqlite3_column_int64,sqlite3_finalize,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_errmsg,sqlite3_mprintf,sqlite3_mprintf,sqlite3_mprintf,sqlite3_free,sqlite3_mprintf,sqlite3_free,sqlite3_declare_vtab,sqlite3_errmsg,sqlite3_mprintf,sqlite3_free, | 2_2_6096281E |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6096583A memcmp,sqlite3_realloc,qsort,sqlite3_malloc,sqlite3_free,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_step,sqlite3_reset, | 2_2_6096583A |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6095F9AD sqlite3_bind_int,sqlite3_step,sqlite3_column_type,sqlite3_reset, | 2_2_6095F9AD |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6094A92B sqlite3_bind_int64,sqlite3_bind_null,sqlite3_bind_blob,sqlite3_step,sqlite3_reset, | 2_2_6094A92B |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6090EAE5 sqlite3_transfer_bindings, | 2_2_6090EAE5 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6095FB98 sqlite3_value_int,sqlite3_bind_int,sqlite3_bind_value,sqlite3_step,sqlite3_reset, | 2_2_6095FB98 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6095ECA6 sqlite3_mprintf,sqlite3_mprintf,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_bind_value, | 2_2_6095ECA6 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6095FCCE sqlite3_malloc,sqlite3_free,sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_step,sqlite3_reset, | 2_2_6095FCCE |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6095FDAE sqlite3_malloc,sqlite3_bind_int,sqlite3_step,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_reset,sqlite3_free,sqlite3_free,sqlite3_bind_int,sqlite3_bind_blob,sqlite3_step,sqlite3_reset,sqlite3_free, | 2_2_6095FDAE |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60966DF1 sqlite3_value_text,sqlite3_mprintf,sqlite3_free,strcmp,sqlite3_free,sqlite3_malloc,sqlite3_bind_int64,sqlite3_step,sqlite3_column_type,sqlite3_reset,sqlite3_column_blob,sqlite3_reset,sqlite3_malloc,sqlite3_free,sqlite3_reset,sqlite3_result_error_code,sqlite3_result_blob, | 2_2_60966DF1 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_60969D75 sqlite3_bind_int,sqlite3_step,sqlite3_column_int,sqlite3_reset, | 2_2_60969D75 |
Source: C:\Users\user\AppData\Local\Defrag Tools Pro 11.3.1.910\defragtoolspro.exe | Code function: 2_2_6095FFB2 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_result_error_code, | 2_2_6095FFB2 |