Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSACCESS.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\servertool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\Locator.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7z.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | System file written: C:\Windows\System32\AppVClient.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7zG.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\SysWOW64\perfhost.exe | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\msiexec.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\keytool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\notification_click_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_proxy.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\pwahelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\kinit.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\policytool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.ShowHelp.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\Uninstall.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\FXSSVC.exe | |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\rmiregistry.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\SensorDataService.exe | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\msdtc.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java-rmi.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedgewebview2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\pack200.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jabswitch.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | System file written: C:\Windows\System32\alg.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\rmid.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7zFM.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\klist.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\tnameserv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\excelcnv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jjs.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\Installer\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\orbd.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_pwa_launcher.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ktab.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to behavior |
Source: niellist.exe, 00000011.00000002.1411628662.0000000000B15000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.21 |
Source: niellist.exe, 00000011.00000002.1411628662.0000000000B15000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/ |
Source: niellist.exe, 00000003.00000002.1298601630.0000000000D07000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/2X |
Source: alg.exe, 00000002.00000003.1340496189.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/2m |
Source: alg.exe, 00000002.00000003.1307088264.00000000004C1000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1300228185.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/bspqodujb |
Source: alg.exe, 00000002.00000003.1307088264.00000000004C1000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1300228185.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/bspqodujbngs |
Source: niellist.exe, 00000003.00000002.1298601630.0000000000D07000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/eri |
Source: niellist.exe, 00000011.00000002.1411628662.0000000000B04000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/qnwbdottpdjvb |
Source: niellist.exe, 00000011.00000002.1411628662.0000000000B24000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/qnwbdottpdjvb588 |
Source: niellist.exe, 00000011.00000002.1411628662.0000000000B04000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/qnwbdottpdjvbs |
Source: alg.exe, 00000002.00000003.1339720537.00000000004F6000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1340849614.00000000004FF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/twetxppkkq |
Source: alg.exe, 00000002.00000003.1339720537.00000000004F6000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1558654635.00000000004F6000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1770492535.00000000004F6000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1346185101.00000000004F6000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/twetxppkkqVt |
Source: niellist.exe, 00000003.00000002.1294142638.0000000000CCD000.00000004.00000020.00020000.00000000.sdmp, niellist.exe, 00000003.00000002.1298601630.0000000000CFB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/woywqgxcq |
Source: alg.exe, 00000002.00000003.1300228185.00000000004BB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196:80/bspqodujb~vZ |
Source: niellist.exe, 00000011.00000002.1411628662.0000000000B22000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196:80/qnwbdottpdjvbY |
Source: alg.exe, 00000002.00000003.1558654635.0000000000513000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1340849614.0000000000513000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196:80/twetxppkkq |
Source: niellist.exe, 00000003.00000002.1298601630.0000000000CFB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196:80/woywqgxcq |
Source: alg.exe, 00000002.00000003.1313095660.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.229.117.57/ |
Source: alg.exe, 00000002.00000003.1313095660.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.229.117.57/12 |
Source: alg.exe, 00000002.00000003.1313095660.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.229.117.57/12E |
Source: alg.exe, 00000002.00000003.1312913508.00000000004E0000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1314920250.00000000004DD000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1313095660.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.229.117.57/buysxojjpcbe |
Source: alg.exe, 00000002.00000003.1313095660.00000000004BB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.229.117.57:80/buysxojjpcbeP |
Source: Ziraat_Bankasi_Swift-Messaji_Notifications.exe, 00000000.00000002.1274105597.0000000000D8F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1307088264.00000000004C1000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1300228185.00000000004C1000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1280251410.00000000004C1000.00000004.00000020.00020000.00000000.sdmp, niellist.exe, 00000003.00000002.1293879138.0000000000BF8000.00000004.00000020.00020000.00000000.sdmp, niellist.exe, 00000011.00000002.1410876293.0000000000A08000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/ |
Source: Ziraat_Bankasi_Swift-Messaji_Notifications.exe, 00000000.00000002.1274105597.0000000000D8F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/Ad |
Source: Ziraat_Bankasi_Swift-Messaji_Notifications.exe, 00000000.00000002.1274105597.0000000000D8F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/DM |
Source: alg.exe, 00000002.00000003.1300228185.00000000004C1000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1280251410.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/E |
Source: alg.exe, 00000002.00000003.1280251410.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/a |
Source: Ziraat_Bankasi_Swift-Messaji_Notifications.exe, 00000000.00000002.1273923400.0000000000D75000.00000040.00000020.00020000.00000000.sdmp, Ziraat_Bankasi_Swift-Messaji_Notifications.exe, 00000000.00000002.1274105597.0000000000D98000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/ahfjecsqgekcwio |
Source: Ziraat_Bankasi_Swift-Messaji_Notifications.exe, 00000000.00000002.1273923400.0000000000D75000.00000040.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/ahfjecsqgekcwioro |
Source: alg.exe, 00000002.00000003.1307290100.00000000004F6000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1312913508.00000000004F6000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1314920250.00000000004F6000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/arkfkq |
Source: niellist.exe, 00000003.00000002.1298601630.0000000000CF2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/bwejhhjeahxfje |
Source: alg.exe, 00000002.00000003.1280251410.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/oqcvpoewhl |
Source: alg.exe, 00000002.00000003.1279607006.00000000004E0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/oqcvpoewhl-v |
Source: alg.exe, 00000002.00000003.1307088264.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/rkfkq |
Source: Ziraat_Bankasi_Swift-Messaji_Notifications.exe, 00000000.00000002.1274105597.0000000000D98000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239:80/ahfjecsqgekcwio |
Source: alg.exe, 00000002.00000003.1307088264.00000000004BB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239:80/arkfkq |
Source: alg.exe, 00000002.00000003.1280251410.00000000004BB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239:80/oqcvpoewhl |
Source: alg.exe, 00000002.00000003.1559227442.00000000004C1000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1986704664.00000000004C1000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1322367769.00000000004C1000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1771772723.00000000004C1000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1340496189.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23/uhxgrttve |
Source: alg.exe, 00000002.00000003.1322367769.00000000004BB000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1771772723.00000000004BB000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1986704664.00000000004BB000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1559227442.00000000004BB000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1340496189.00000000004BB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23:80/uhxgrttve |
Source: alg.exe, 00000002.00000003.1771772723.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/ |
Source: alg.exe, 00000002.00000003.1986704664.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/J |
Source: alg.exe, 00000002.00000003.1986704664.00000000004C1000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1771772723.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/a |
Source: alg.exe, 00000002.00000003.1559227442.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/gs |
Source: alg.exe, 00000002.00000003.1770492535.00000000004F6000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1987338757.0000000000511000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1772721366.0000000000511000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/iljywase |
Source: alg.exe, 00000002.00000003.1987338757.0000000000511000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1772721366.0000000000511000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/iljywasehv |
Source: alg.exe, 00000002.00000003.1772721366.0000000000511000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/kkjhdthfjo |
Source: alg.exe, 00000002.00000003.1558654635.0000000000513000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1987338757.0000000000511000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1772721366.0000000000511000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/kkjhdthfjouemm1$ |
Source: alg.exe, 00000002.00000003.1987338757.00000000004FF000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1987338757.0000000000511000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/qlbvcaqfgtptt |
Source: alg.exe, 00000002.00000003.1987338757.0000000000511000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/qlbvcaqfgtpttqtS |
Source: alg.exe, 00000002.00000003.1987338757.0000000000511000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1772721366.0000000000511000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197:80/iljywase |
Source: alg.exe, 00000002.00000003.1558654635.0000000000513000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197:80/kkjhdthfjoP |
Source: alg.exe, 00000002.00000003.1987338757.0000000000511000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197:80/qlbvcaqfgtpttcrobat |
Source: powershell.exe, 0000000E.00000002.1464480139.000001FEBE977000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.microskW |
Source: powershell.exe, 0000000E.00000002.1464480139.000001FEBE90C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.microso |
Source: powershell.exe, 0000000E.00000002.1437482472.000001FEB6143000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000015.00000002.1614630556.000001DD944F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000015.00000002.1539783861.000001DD846A9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: niellist.exe, 00000003.00000002.1293879138.0000000000BF8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://pywolwnvd.biz/ |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/actor/next |
Source: powershell.exe, 0000000E.00000002.1397307978.000001FEA62FA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000015.00000002.1539783861.000001DD846A9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/fault |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/AckRequested |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequence |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequenceResponse |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/LastMessage |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/SequenceAcknowledgement |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/TerminateSequence |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rmX |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dns |
Source: XClient.exe, 0000000B.00000002.2539294552.0000000002EB1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000E.00000002.1397307978.000001FEA60D1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000015.00000002.1539783861.000001DD84481000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/right/possessproperty |
Source: powershell.exe, 0000000E.00000002.1397307978.000001FEA62FA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000015.00000002.1539783861.000001DD846A9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/ |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/0 |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id10LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id10Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id11LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id11Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id12LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id12Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id13LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id13Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id14LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id14Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id15LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id15Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id16LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id16Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id17LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id17Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id18LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id18Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id19LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id19Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id1LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id1Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id20LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id20Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id21LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id21Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id22LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id22Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id23LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id23Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id24LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id24Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id2LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id2Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id3LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id3Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id3Response0 |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id4LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id4Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id5LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id5Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id6LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id6Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id7LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id7Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id8LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id8Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id8Response0 |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id9LR |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id9Response |
Source: build.exe, 0000000A.00000002.2549800111.0000000003211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/x |
Source: alg.exe, 00000002.00000003.1322367769.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/ |
Source: alg.exe, 00000002.00000003.1322367769.00000000004C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/N |
Source: alg.exe, 00000002.00000003.1322162088.00000000004E0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/uhxgrttve?usid=25&utid=9755593280 |
Source: alg.exe, 00000002.00000003.1322162088.00000000004E0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/uhxgrttve?usid=25&utid=9755593280LocationETagAuthentication-InfoAgeAccept-Ra |
Source: alg.exe, 00000002.00000003.1328245615.00000000004DD000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1322162088.00000000004E0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/uhxgrttve?usid=25&utid=9755593280hv |
Source: alg.exe, 00000002.00000003.1322367769.00000000004BB000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1771772723.00000000004BB000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1986704664.00000000004BB000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1559227442.00000000004BB000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1340496189.00000000004BB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz:80/uhxgrttve?usid=25&utid=9755593280PU |
Source: powershell.exe, 00000015.00000002.1539783861.000001DD846A9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: alg.exe, 00000002.00000003.1439852307.0000000001550000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://www.winimage.com/zLibDll |
Source: powershell.exe, 0000000E.00000002.1397307978.000001FEA60D1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000015.00000002.1539783861.000001DD84481000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore68 |
Source: RegSvcs.exe, 00000009.00000002.1311146517.0000000003E63000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000009.00000002.1311146517.0000000003F3C000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000009.00000002.1311146517.0000000003EF1000.00000004.00000800.00020000.00000000.sdmp, build.exe, 0000000A.00000000.1301567190.0000000000EF2000.00000002.00000001.01000000.00000008.sdmp | String found in binary or memory: https://api.ip.sb/ip |
Source: alg.exe, 00000002.00000003.2038298699.0000000001450000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://aus5.mozilla.org/update/6/%PRODUCT%/%VERSION%/%BUILD_ID%/%BUILD_TARGET%/%LOCALE%/%CHANNEL%/% |
Source: alg.exe, 00000002.00000003.1550726071.0000000001550000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://clients2.google.com/service/update2/crxFailed |
Source: alg.exe, 00000002.00000003.1551610424.0000000001550000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1551415000.0000000001550000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://clients2.google.com/service/update2/crxHKEY_LOCAL_MACHINE |
Source: powershell.exe, 00000015.00000002.1614630556.000001DD944F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000015.00000002.1614630556.000001DD944F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000015.00000002.1614630556.000001DD944F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: alg.exe, 00000002.00000003.2038429513.0000000001450000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://crash-reports.mozilla.com/submit?id= |
Source: powershell.exe, 00000015.00000002.1539783861.000001DD846A9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: alg.exe, 00000002.00000003.2038532715.0000000001450000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://hg.mozilla.org/releases/mozilla-release/rev/68e4c357d26c5a1f075a1ec0c696d4fe684ed881 |
Source: alg.exe, 00000002.00000003.2038532715.0000000001450000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://hg.mozilla.org/releases/mozilla-release/rev/68e4c357d26c5a1f075a1ec0c696d4fe684ed881118.0.1 |
Source: alg.exe, 00000002.00000003.2038004148.0000000001450000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://incoming.telemetry.mozilla.org/submit/firefox-launcher-process/launcher-process-failure/1/ |
Source: powershell.exe, 0000000E.00000002.1437482472.000001FEB6143000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000015.00000002.1614630556.000001DD944F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: alg.exe, 00000002.00000003.1347358368.00000000014D0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.7-zip.org/ |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_0040E6A0 | 0_2_0040E6A0 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_0042D975 | 0_2_0042D975 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_004221C5 | 0_2_004221C5 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_004362D2 | 0_2_004362D2 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_004803DA | 0_2_004803DA |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_0043242E | 0_2_0043242E |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_004225FA | 0_2_004225FA |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_0045E616 | 0_2_0045E616 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_004166E1 | 0_2_004166E1 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_0043878F | 0_2_0043878F |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00436844 | 0_2_00436844 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00480857 | 0_2_00480857 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00418808 | 0_2_00418808 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00468889 | 0_2_00468889 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_0042CB21 | 0_2_0042CB21 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00436DB6 | 0_2_00436DB6 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00416F9E | 0_2_00416F9E |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00413030 | 0_2_00413030 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_0042F1D9 | 0_2_0042F1D9 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00423187 | 0_2_00423187 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00401287 | 0_2_00401287 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00421484 | 0_2_00421484 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00415520 | 0_2_00415520 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00427696 | 0_2_00427696 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00415760 | 0_2_00415760 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00421978 | 0_2_00421978 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_0055BCC8 | 0_2_0055BCC8 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_0040FCE0 | 0_2_0040FCE0 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00487DDB | 0_2_00487DDB |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00421D90 | 0_2_00421D90 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_0042BDA6 | 0_2_0042BDA6 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_0040DF00 | 0_2_0040DF00 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00413FE0 | 0_2_00413FE0 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00B100D9 | 0_2_00B100D9 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00AD6EAF | 0_2_00AD6EAF |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00AD51EE | 0_2_00AD51EE |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00B0D580 | 0_2_00B0D580 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00B03780 | 0_2_00B03780 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00B0C7F0 | 0_2_00B0C7F0 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00B139A3 | 0_2_00B139A3 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00B05980 | 0_2_00B05980 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00AD7B71 | 0_2_00AD7B71 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00AD7F80 | 0_2_00AD7F80 |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Code function: 0_2_00D71360 | 0_2_00D71360 |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 3_2_00AE39A3 | 3_2_00AE39A3 |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 3_2_00AD5980 | 3_2_00AD5980 |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 3_2_00AA6EAF | 3_2_00AA6EAF |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 3_2_00AA51EE | 3_2_00AA51EE |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 3_2_00ADD580 | 3_2_00ADD580 |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 3_2_00AA7F80 | 3_2_00AA7F80 |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 3_2_00AD3780 | 3_2_00AD3780 |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 3_2_00ADC7F0 | 3_2_00ADC7F0 |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 3_2_00CEA410 | 3_2_00CEA410 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_00408C60 | 9_2_00408C60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_0040DC11 | 9_2_0040DC11 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_00407C3F | 9_2_00407C3F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_00418CCC | 9_2_00418CCC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_00406CA0 | 9_2_00406CA0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_004028B0 | 9_2_004028B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_0041A4BE | 9_2_0041A4BE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_00418244 | 9_2_00418244 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_00401650 | 9_2_00401650 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_00402F20 | 9_2_00402F20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_004193C4 | 9_2_004193C4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_00418788 | 9_2_00418788 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_00402F89 | 9_2_00402F89 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_00402B90 | 9_2_00402B90 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_004073A0 | 9_2_004073A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_02860FE0 | 9_2_02860FE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_02861030 | 9_2_02861030 |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Code function: 10_2_017DDC74 | 10_2_017DDC74 |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Code function: 10_2_057EEE58 | 10_2_057EEE58 |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Code function: 10_2_057E8850 | 10_2_057E8850 |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Code function: 10_2_057E0040 | 10_2_057E0040 |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Code function: 10_2_057E0007 | 10_2_057E0007 |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Code function: 10_2_057E8840 | 10_2_057E8840 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 12_2_0099CA20 | 12_2_0099CA20 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 12_2_0099AA63 | 12_2_0099AA63 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 12_2_00998789 | 12_2_00998789 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 12_2_009BA810 | 12_2_009BA810 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 12_2_009979F0 | 12_2_009979F0 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 12_2_009B92A0 | 12_2_009B92A0 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 12_2_009B93B0 | 12_2_009B93B0 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 12_2_00997C00 | 12_2_00997C00 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 12_2_009C2D40 | 12_2_009C2D40 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 12_2_009BEEB0 | 12_2_009BEEB0 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 13_2_00CD7C00 | 13_2_00CD7C00 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 13_2_00CFA810 | 13_2_00CFA810 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 13_2_00CD79F0 | 13_2_00CD79F0 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 13_2_00D02D40 | 13_2_00D02D40 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 13_2_00CF92A0 | 13_2_00CF92A0 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 13_2_00CFEEB0 | 13_2_00CFEEB0 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 13_2_00CF93B0 | 13_2_00CF93B0 |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 17_2_00AFC668 | 17_2_00AFC668 |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 17_2_0340515C | 17_2_0340515C |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 17_2_033C6EAF | 17_2_033C6EAF |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 17_2_033F5980 | 17_2_033F5980 |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 17_2_033C51EE | 17_2_033C51EE |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 17_2_034039A3 | 17_2_034039A3 |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 17_2_033C7F80 | 17_2_033C7F80 |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 17_2_033F3780 | 17_2_033F3780 |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 17_2_033FC7F0 | 17_2_033FC7F0 |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Code function: 17_2_033FD580 | 17_2_033FD580 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 19_2_02CC1385 | 19_2_02CC1385 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 19_2_02CC1315 | 19_2_02CC1315 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 19_2_02CC1335 | 19_2_02CC1335 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 19_2_02CC1021 | 19_2_02CC1021 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 19_2_02CC1030 | 19_2_02CC1030 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 19_2_05A305E8 | 19_2_05A305E8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 19_2_05A305F8 | 19_2_05A305F8 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Code function: 21_2_00007FFC3C8130E9 | 21_2_00007FFC3C8130E9 |
Source: Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: armsvc.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: alg.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: niellist.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVClient.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: officesvcmgr.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: chrome_pwa_launcher.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AutoIt3Help.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AutoIt3_x64.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SciTE.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AdobeARMHelper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jaureg.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jucheck.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jusched.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevated_tracing_service.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: java.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: chrmstp.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaw.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: setup.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaws.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: notification_helper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: os_update_handler.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: chrome_proxy.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: crashreporter.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: default-browser-agent.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: firefox.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: updater.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: maintenanceservice.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevation_service.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: maintenanceservice.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jabswitch.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: java-rmi.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: java.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javacpl.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaw.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaws.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jjs.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jp2launcher.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: keytool.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: kinit.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevation_service.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7z.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7zFM.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7zG.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: klist.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ktab.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: orbd.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: pack200.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: policytool.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: rmid.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: rmiregistry.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: servertool.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ssvagent.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: tnameserv.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Acrobat.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcrobatInfo.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: acrobat_sl.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroBroker.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: unpack200.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ie_to_edge_stub.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: cookie_exporter.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: identity_helper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: setup.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedgewebview2.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedge_proxy.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedge_pwa_launcher.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: notification_click_helper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: pwahelper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroCEF.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SingleClientServicesUpdater.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroCEF.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SingleClientServicesUpdater.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: armsvc.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: alg.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: niellist.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVClient.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: officesvcmgr.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: chrome_pwa_launcher.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AutoIt3Help.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AutoIt3_x64.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SciTE.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AdobeARMHelper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jaureg.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jucheck.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jusched.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevated_tracing_service.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: java.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: chrmstp.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaw.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: setup.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaws.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: notification_helper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: os_update_handler.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: chrome_proxy.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: crashreporter.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: default-browser-agent.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: firefox.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: updater.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: maintenanceservice.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevation_service.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: maintenanceservice.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jabswitch.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: java-rmi.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: java.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javacpl.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaw.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaws.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jjs.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jp2launcher.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: keytool.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: kinit.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevation_service.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7z.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7zFM.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7zG.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: klist.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ktab.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: orbd.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: pack200.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: policytool.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: rmid.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: rmiregistry.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: servertool.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ssvagent.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: tnameserv.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Acrobat.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcrobatInfo.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: acrobat_sl.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroBroker.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: unpack200.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ie_to_edge_stub.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: cookie_exporter.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: identity_helper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: setup.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedgewebview2.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedge_proxy.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedge_pwa_launcher.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: notification_click_helper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: pwahelper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroCEF.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SingleClientServicesUpdater.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroCEF.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SingleClientServicesUpdater.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: drprov.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ntlanman.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: davclnt.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: davhlpr.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: browcli.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: msvcp140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: apphelp.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: edputil.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: urlmon.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: iertutil.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: srvcli.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: appresolver.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: bcp47langs.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: slc.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: sppc.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dbghelp.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: mpr.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: ntmarta.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: mpr.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: ntmarta.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: vbscript.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: mlang.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: edputil.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: appresolver.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: wsock32.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: mpr.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: wininet.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: winnsi.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: webio.dll | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: apphelp.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: tapi32.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: credui.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: fxstiff.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: fxsresm.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: ualapi.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: msdtctm.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: msdtcprx.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: msdtclog.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mtxclu.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: winmm.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: clusapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: xolehlp.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: resutils.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: ktmw32.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: resutils.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: comres.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: msdtcvsp1res.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mtxoci.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: oci.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: cscapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: firewallapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: fwbase.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: fwpolicyiomgr.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: hid.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: dxgi.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: devobj.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: ntmarta.dll | |
Source: armsvc.exe.0.dr | Static PE information: section name: .didat |
Source: alg.exe.0.dr | Static PE information: section name: .didat |
Source: officesvcmgr.exe.2.dr | Static PE information: section name: .didat |
Source: chrome_pwa_launcher.exe.2.dr | Static PE information: section name: .gxfg |
Source: chrome_pwa_launcher.exe.2.dr | Static PE information: section name: .retplne |
Source: chrome_pwa_launcher.exe.2.dr | Static PE information: section name: LZMADEC |
Source: chrome_pwa_launcher.exe.2.dr | Static PE information: section name: _RDATA |
Source: elevated_tracing_service.exe.2.dr | Static PE information: section name: .gxfg |
Source: elevated_tracing_service.exe.2.dr | Static PE information: section name: .retplne |
Source: elevated_tracing_service.exe.2.dr | Static PE information: section name: CPADinfo |
Source: elevated_tracing_service.exe.2.dr | Static PE information: section name: _RDATA |
Source: elevated_tracing_service.exe.2.dr | Static PE information: section name: malloc_h |
Source: chrmstp.exe.2.dr | Static PE information: section name: .gxfg |
Source: chrmstp.exe.2.dr | Static PE information: section name: .retplne |
Source: chrmstp.exe.2.dr | Static PE information: section name: .rodata |
Source: chrmstp.exe.2.dr | Static PE information: section name: CPADinfo |
Source: chrmstp.exe.2.dr | Static PE information: section name: LZMADEC |
Source: chrmstp.exe.2.dr | Static PE information: section name: _RDATA |
Source: chrmstp.exe.2.dr | Static PE information: section name: malloc_h |
Source: setup.exe.2.dr | Static PE information: section name: .gxfg |
Source: setup.exe.2.dr | Static PE information: section name: .retplne |
Source: setup.exe.2.dr | Static PE information: section name: .rodata |
Source: setup.exe.2.dr | Static PE information: section name: CPADinfo |
Source: setup.exe.2.dr | Static PE information: section name: LZMADEC |
Source: setup.exe.2.dr | Static PE information: section name: _RDATA |
Source: setup.exe.2.dr | Static PE information: section name: malloc_h |
Source: notification_helper.exe.2.dr | Static PE information: section name: .gxfg |
Source: notification_helper.exe.2.dr | Static PE information: section name: .retplne |
Source: notification_helper.exe.2.dr | Static PE information: section name: CPADinfo |
Source: notification_helper.exe.2.dr | Static PE information: section name: _RDATA |
Source: os_update_handler.exe.2.dr | Static PE information: section name: .gxfg |
Source: os_update_handler.exe.2.dr | Static PE information: section name: .retplne |
Source: os_update_handler.exe.2.dr | Static PE information: section name: CPADinfo |
Source: os_update_handler.exe.2.dr | Static PE information: section name: LZMADEC |
Source: os_update_handler.exe.2.dr | Static PE information: section name: _RDATA |
Source: chrome_proxy.exe.2.dr | Static PE information: section name: .gxfg |
Source: chrome_proxy.exe.2.dr | Static PE information: section name: .retplne |
Source: chrome_proxy.exe.2.dr | Static PE information: section name: _RDATA |
Source: crashreporter.exe.2.dr | Static PE information: section name: .00cfg |
Source: crashreporter.exe.2.dr | Static PE information: section name: .voltbl |
Source: default-browser-agent.exe.2.dr | Static PE information: section name: .00cfg |
Source: default-browser-agent.exe.2.dr | Static PE information: section name: .voltbl |
Source: firefox.exe.2.dr | Static PE information: section name: .00cfg |
Source: firefox.exe.2.dr | Static PE information: section name: .freestd |
Source: firefox.exe.2.dr | Static PE information: section name: .retplne |
Source: firefox.exe.2.dr | Static PE information: section name: .voltbl |
Source: updater.exe.2.dr | Static PE information: section name: CPADinfo |
Source: updater.exe.2.dr | Static PE information: section name: malloc_h |
Source: maintenanceservice.exe.2.dr | Static PE information: section name: .00cfg |
Source: maintenanceservice.exe.2.dr | Static PE information: section name: .voltbl |
Source: maintenanceservice.exe.2.dr | Static PE information: section name: _RDATA |
Source: elevation_service.exe.2.dr | Static PE information: section name: .00cfg |
Source: elevation_service.exe.2.dr | Static PE information: section name: .gxfg |
Source: elevation_service.exe.2.dr | Static PE information: section name: .retplne |
Source: elevation_service.exe.2.dr | Static PE information: section name: _RDATA |
Source: elevation_service.exe.2.dr | Static PE information: section name: malloc_h |
Source: maintenanceservice.exe0.2.dr | Static PE information: section name: .00cfg |
Source: maintenanceservice.exe0.2.dr | Static PE information: section name: .voltbl |
Source: maintenanceservice.exe0.2.dr | Static PE information: section name: _RDATA |
Source: elevation_service.exe0.2.dr | Static PE information: section name: .gxfg |
Source: elevation_service.exe0.2.dr | Static PE information: section name: .retplne |
Source: elevation_service.exe0.2.dr | Static PE information: section name: _RDATA |
Source: Acrobat.exe.2.dr | Static PE information: section name: .didat |
Source: Acrobat.exe.2.dr | Static PE information: section name: _RDATA |
Source: unpack200.exe.2.dr | Static PE information: section name: .00cfg |
Source: ie_to_edge_stub.exe.2.dr | Static PE information: section name: .00cfg |
Source: ie_to_edge_stub.exe.2.dr | Static PE information: section name: .gxfg |
Source: ie_to_edge_stub.exe.2.dr | Static PE information: section name: .retplne |
Source: ie_to_edge_stub.exe.2.dr | Static PE information: section name: _RDATA |
Source: cookie_exporter.exe.2.dr | Static PE information: section name: .00cfg |
Source: cookie_exporter.exe.2.dr | Static PE information: section name: .gxfg |
Source: cookie_exporter.exe.2.dr | Static PE information: section name: .retplne |
Source: cookie_exporter.exe.2.dr | Static PE information: section name: _RDATA |
Source: identity_helper.exe.2.dr | Static PE information: section name: .00cfg |
Source: identity_helper.exe.2.dr | Static PE information: section name: .gxfg |
Source: identity_helper.exe.2.dr | Static PE information: section name: .retplne |
Source: identity_helper.exe.2.dr | Static PE information: section name: _RDATA |
Source: identity_helper.exe.2.dr | Static PE information: section name: malloc_h |
Source: setup.exe0.2.dr | Static PE information: section name: .00cfg |
Source: setup.exe0.2.dr | Static PE information: section name: .gxfg |
Source: setup.exe0.2.dr | Static PE information: section name: .retplne |
Source: setup.exe0.2.dr | Static PE information: section name: LZMADEC |
Source: setup.exe0.2.dr | Static PE information: section name: _RDATA |
Source: setup.exe0.2.dr | Static PE information: section name: malloc_h |
Source: msedgewebview2.exe.2.dr | Static PE information: section name: .00cfg |
Source: msedgewebview2.exe.2.dr | Static PE information: section name: .gxfg |
Source: msedgewebview2.exe.2.dr | Static PE information: section name: .retplne |
Source: msedgewebview2.exe.2.dr | Static PE information: section name: CPADinfo |
Source: msedgewebview2.exe.2.dr | Static PE information: section name: LZMADEC |
Source: msedgewebview2.exe.2.dr | Static PE information: section name: _RDATA |
Source: msedgewebview2.exe.2.dr | Static PE information: section name: malloc_h |
Source: msedge_proxy.exe.2.dr | Static PE information: section name: .00cfg |
Source: msedge_proxy.exe.2.dr | Static PE information: section name: .gxfg |
Source: msedge_proxy.exe.2.dr | Static PE information: section name: .retplne |
Source: msedge_proxy.exe.2.dr | Static PE information: section name: _RDATA |
Source: msedge_proxy.exe.2.dr | Static PE information: section name: malloc_h |
Source: msedge_pwa_launcher.exe.2.dr | Static PE information: section name: .00cfg |
Source: msedge_pwa_launcher.exe.2.dr | Static PE information: section name: .gxfg |
Source: msedge_pwa_launcher.exe.2.dr | Static PE information: section name: .retplne |
Source: msedge_pwa_launcher.exe.2.dr | Static PE information: section name: LZMADEC |
Source: msedge_pwa_launcher.exe.2.dr | Static PE information: section name: _RDATA |
Source: msedge_pwa_launcher.exe.2.dr | Static PE information: section name: malloc_h |
Source: notification_click_helper.exe.2.dr | Static PE information: section name: .00cfg |
Source: notification_click_helper.exe.2.dr | Static PE information: section name: .gxfg |
Source: notification_click_helper.exe.2.dr | Static PE information: section name: .retplne |
Source: notification_click_helper.exe.2.dr | Static PE information: section name: CPADinfo |
Source: notification_click_helper.exe.2.dr | Static PE information: section name: _RDATA |
Source: notification_click_helper.exe.2.dr | Static PE information: section name: malloc_h |
Source: pwahelper.exe.2.dr | Static PE information: section name: .00cfg |
Source: pwahelper.exe.2.dr | Static PE information: section name: .gxfg |
Source: pwahelper.exe.2.dr | Static PE information: section name: .retplne |
Source: pwahelper.exe.2.dr | Static PE information: section name: _RDATA |
Source: pwahelper.exe.2.dr | Static PE information: section name: malloc_h |
Source: AcroCEF.exe.2.dr | Static PE information: section name: .didat |
Source: AcroCEF.exe.2.dr | Static PE information: section name: _RDATA |
Source: SingleClientServicesUpdater.exe.2.dr | Static PE information: section name: .didat |
Source: SingleClientServicesUpdater.exe.2.dr | Static PE information: section name: _RDATA |
Source: AcroCEF.exe0.2.dr | Static PE information: section name: .didat |
Source: AcroCEF.exe0.2.dr | Static PE information: section name: _RDATA |
Source: SingleClientServicesUpdater.exe0.2.dr | Static PE information: section name: .didat |
Source: SingleClientServicesUpdater.exe0.2.dr | Static PE information: section name: _RDATA |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSACCESS.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\servertool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\Locator.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7z.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | System file written: C:\Windows\System32\AppVClient.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7zG.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\SysWOW64\perfhost.exe | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\msiexec.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\keytool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\notification_click_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_proxy.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\pwahelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\kinit.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\policytool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.ShowHelp.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\Uninstall.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\FXSSVC.exe | |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\rmiregistry.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\SensorDataService.exe | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\msdtc.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java-rmi.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedgewebview2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\pack200.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jabswitch.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | System file written: C:\Windows\System32\alg.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\rmid.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7zFM.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\klist.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\tnameserv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\excelcnv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jjs.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\Installer\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\orbd.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_pwa_launcher.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ktab.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\servertool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File created: C:\Users\user\AppData\Local\differences\niellist.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\Locator.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\7-Zip\7z.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File created: C:\Windows\System32\AppVClient.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\7-Zip\7zG.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\SysWOW64\perfhost.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\msiexec.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\keytool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\build.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\notification_click_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_proxy.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\pwahelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\updater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\kinit.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\policytool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.ShowHelp.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\7-Zip\Uninstall.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\FXSSVC.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File created: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\rmiregistry.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\SensorDataService.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\msdtc.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\java-rmi.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedgewebview2.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\pack200.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\jabswitch.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File created: C:\Windows\System32\alg.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\XClient.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\rmid.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\7-Zip\7zFM.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\klist.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | File created: C:\Users\user\AppData\Roaming\XClient.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\tnameserv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\excelcnv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\jjs.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\Installer\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\orbd.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_pwa_launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\ktab.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Users\user\AppData\Roaming\a8259331cca430bb.bin offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 162304 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 735820 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 737280 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 1285120 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 1286144 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 1289427 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 735744 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 31704 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Users\user\AppData\Local\Temp\aut9353.tmp offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Users\user\AppData\Local\Temp\aut9353.tmp offset: 520192 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Users\user\AppData\Local\Temp\unnervousness offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\alg.exe offset: 95744 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\alg.exe offset: 669260 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\alg.exe offset: 672768 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\alg.exe offset: 1220608 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\alg.exe offset: 1221632 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\alg.exe offset: 1224840 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\alg.exe offset: 669184 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\alg.exe offset: 53125 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Users\user\AppData\Local\differences\niellist.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\AppVClient.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\AppVClient.exe offset: 767488 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\AppVClient.exe offset: 1341004 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\AppVClient.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\AppVClient.exe offset: 1344512 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\AppVClient.exe offset: 1347720 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\AppVClient.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\AppVClient.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\AppVClient.exe offset: 1340928 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | File written: C:\Windows\System32\AppVClient.exe offset: 409168 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Windows\System32\config\systemprofile\AppData\Roaming\a8259331cca430bb.bin offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe offset: 2136576 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe offset: 2710092 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe offset: 2710016 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe offset: 1093484 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 1776128 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 2349644 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 2349568 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 677164 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 228352 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 801868 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 801792 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 43297 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 557056 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 1130572 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 1130496 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 382726 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 952832 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 1526348 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 1526272 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 614020 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 700416 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 1273932 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 1273856 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 464916 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 14848 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 588364 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 588288 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 5610 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 5630464 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 6203980 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 6203904 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 3201596 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 27136 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 600652 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 600576 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 8988 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 31744 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 605260 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 605184 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 12684 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 332800 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 906316 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 906240 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 232412 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 3571200 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 4144716 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 4144640 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 1485948 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 59362816 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 59936332 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 59936256 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 140924 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 3571200 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 4144716 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 4144640 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 1485948 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 59362816 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 59936332 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 59936256 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 140924 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 50176 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 623692 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 623616 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 24668 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe offset: 328192 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe offset: 901708 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe offset: 901632 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe offset: 4988 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 642048 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 1215564 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 1215488 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 132252 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 11459072 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 12032588 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 12032512 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 4630732 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 192512 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 766028 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 765952 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 95345 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 759296 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 1332812 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 1332736 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 285633 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 385536 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 959052 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 958976 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 182364 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 123904 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 697420 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 697344 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 66716 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 1102848 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 1676364 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 1676288 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 753617 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 2531840 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 3105356 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 3105280 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 1150992 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 459776 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 1033292 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 1033216 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 209348 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 99840 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 673356 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 673280 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 69527 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 256512 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 830028 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 829952 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 72028 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 521216 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 1094732 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 1094656 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 321696 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 210944 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 784460 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 784384 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 126840 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 13312 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 586828 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 586752 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 2828 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 4785664 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 5359180 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 5359104 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 2430581 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 632832 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 1206348 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 1206272 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 206444 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 2578944 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 3152460 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 3152384 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 16859 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 1617920 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 2191436 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 2191360 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 860981 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 258048 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 831564 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 831488 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 82352 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 5274624 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 5848140 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 5848064 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 3286540 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 185344 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 758860 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 758784 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 151349 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 26954240 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 27527756 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 27527680 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 11401068 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 4392960 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 4966476 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 4966400 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 2843313 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe offset: 1755648 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe offset: 2329164 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe offset: 2329088 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe offset: 740604 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe offset: 3347968 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe offset: 3921484 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe offset: 3921408 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe offset: 1777084 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe offset: 6470144 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe offset: 7043660 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe offset: 7043584 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe offset: 2807964 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe offset: 6470144 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe offset: 7043660 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe offset: 7043584 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe offset: 2807964 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe offset: 1665536 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe offset: 2239052 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe offset: 2238976 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe offset: 853340 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe offset: 1861120 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe offset: 2434636 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe offset: 2434560 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe offset: 910188 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 1445888 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 2019404 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 2019328 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 728892 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 248832 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 822348 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 822272 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 121980 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 707072 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 1280588 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 1280512 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 346881 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 666112 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 1239628 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 1239552 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 193089 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 228352 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 801868 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 801792 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 43297 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 762368 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 1335884 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 1335808 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 239297 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 70144 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 643660 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 643584 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 32241 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 279040 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 852556 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 852480 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 111633 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 55296 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 628812 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 628736 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 4108 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 403968 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 977484 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 977408 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 79009 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 224256 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 797772 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 797696 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 35826 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\servertool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\7-Zip\7z.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Dropped PE file which has not been started: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Dropped PE file which has not been started: C:\Windows\System32\AppVClient.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\7-Zip\7zG.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Dropped PE file which has not been started: C:\Windows\System32\msiexec.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\keytool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\notification_click_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_proxy.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\pwahelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\updater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\kinit.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\policytool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.ShowHelp.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\7-Zip\Uninstall.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\rmiregistry.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Dropped PE file which has not been started: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\java-rmi.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedgewebview2.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\pack200.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\jabswitch.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\rmid.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\7-Zip\7zFM.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\klist.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\tnameserv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\excelcnv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\jjs.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\Installer\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\orbd.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_pwa_launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\ktab.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Ziraat_Bankasi_Swift-Messaji_Notifications.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\build.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\XClient.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\XClient.exe VolumeInformation | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | |
Source: C:\Users\user\AppData\Local\differences\niellist.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Queries volume information: C:\Users\user\AppData\Roaming\XClient.exe VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\XClient.exe | Queries volume information: C:\Users\user\AppData\Roaming\XClient.exe VolumeInformation | |
Source: C:\Windows\System32\FXSSVC.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\FXSSVC.exe | Queries volume information: C:\ProgramData\Microsoft\Windows NT\MSFax\Queue\TST5268.tmp VolumeInformation | |
Source: C:\Windows\System32\FXSSVC.exe | Queries volume information: C:\ProgramData\Microsoft\Windows NT\MSFax\TST5269.tmp VolumeInformation | |
Source: C:\Windows\System32\msdtc.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\Locator.exe | Queries volume information: C:\ VolumeInformation | |