Source: | Binary string: D:\DCB\CBT_Main\BuildResults\bin\Win32\Release\armsvc.pdb source: gE3uqW5GsF.exe, 00000000.00000003.879053304.0000000003F20000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\AcrobatInfo.pdb source: alg.exe, 00000002.00000003.1000828344.00000000014D0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ssh-agent.pdb source: elevation_service.exe, 0000000A.00000003.1833564379.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\TextExtractor.pdb444 source: alg.exe, 00000002.00000003.1096078215.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\TextExtractor.pdb source: alg.exe, 00000002.00000003.1096078215.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\jjs_objs\jjs.pdb source: elevation_service.exe, 0000000A.00000003.2029694758.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: msiexec.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1727072878.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: mavinject32.pdbGCTL source: alg.exe, 00000002.00000003.1275188675.0000000001570000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1278243532.00000000014D0000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1991807866.00000000007C0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PresentationFontCache.pdb source: elevation_service.exe, 0000000A.00000003.1710332802.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PerceptionSimulationService.pdb source: elevation_service.exe, 0000000A.00000003.1743710201.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: wntdll.pdb source: hypopygidium.exe, 00000003.00000003.909654251.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, hypopygidium.exe, 00000003.00000003.908605538.00000000049D0000.00000004.00001000.00020000.00000000.sdmp, hypopygidium.exe, 00000005.00000003.925887188.0000000004090000.00000004.00001000.00020000.00000000.sdmp, hypopygidium.exe, 00000005.00000003.924943395.0000000004500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WebInstaller\AcroMiniServicesUpdater.pdb source: alg.exe, 00000002.00000003.1074204227.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: MsSense.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1772919470.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x64\ship\click2run\x-none\InspectorOfficeGadget.pdb source: alg.exe, 00000002.00000003.1263628953.0000000001440000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1990443076.00000000007C0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: MsSense.pdb source: elevation_service.exe, 0000000A.00000003.1772919470.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\Acrobat\Installers\ShowAppPickerForPDF\Release_x64\ShowAppPickerForPDF.pdb source: alg.exe, 00000002.00000003.1205596936.0000000001440000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1210405910.0000000000400000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1968363318.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\tnameserv_objs\tnameserv.pdb source: elevation_service.exe, 0000000A.00000003.2036250927.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\servertool_objs\servertool.pdb source: elevation_service.exe, 0000000A.00000003.2035341861.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: DiagnosticsHub.StandardCollector.Service.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1695564330.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\rmid_objs\rmid.pdb source: elevation_service.exe, 0000000A.00000003.2034354690.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\java-rmi_objs\java-rmi.pdb source: elevation_service.exe, 0000000A.00000003.2026847938.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\AcroBroker.pdb source: alg.exe, 00000002.00000003.1015092732.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: Acrobat_SL.pdb source: alg.exe, 00000002.00000003.1006248457.00000000014D0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\policytool_objs\policytool.pdb source: elevation_service.exe, 0000000A.00000003.2033866814.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: maintenanceservice.pdb source: alg.exe, 00000002.00000003.951477961.00000000015A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x64\ship\click2run\x-none\InspectorOfficeGadget.pdbY source: alg.exe, 00000002.00000003.1263628953.0000000001440000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1990443076.00000000007C0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PerfHost.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1750225775.0000000000830000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1759048672.00000000007A0000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1751836179.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WCChromeNativeMessagingHost.pdb source: alg.exe, 00000002.00000003.1129130053.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\rmid_objs\rmid.pdb source: elevation_service.exe, 0000000A.00000003.2034354690.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\elevation_service.exe.pdb source: alg.exe, 00000002.00000003.946145680.0000000001580000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\workspace\CR-Windows-x64-Client-Builder\x64\Release\CRWindowsClientService.pdb source: alg.exe, 00000002.00000003.1143061380.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PerfHost.pdb source: elevation_service.exe, 0000000A.00000003.1750225775.0000000000830000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1759048672.00000000007A0000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1751836179.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\keytool_objs\keytool.pdb source: elevation_service.exe, 0000000A.00000003.2030748443.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\tnameserv_objs\tnameserv.pdb source: elevation_service.exe, 0000000A.00000003.2036250927.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\java-rmi_objs\java-rmi.pdb source: elevation_service.exe, 0000000A.00000003.2026847938.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\Acrobat\Installers\ShowAppPickerForPDF\Release_x64\ShowAppPickerForPDF.pdb$$ source: alg.exe, 00000002.00000003.1205596936.0000000001440000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1210405910.0000000000400000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1968363318.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: wntdll.pdbUGP source: hypopygidium.exe, 00000003.00000003.909654251.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, hypopygidium.exe, 00000003.00000003.908605538.00000000049D0000.00000004.00001000.00020000.00000000.sdmp, hypopygidium.exe, 00000005.00000003.925887188.0000000004090000.00000004.00001000.00020000.00000000.sdmp, hypopygidium.exe, 00000005.00000003.924943395.0000000004500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: TieringEngineService.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1844908082.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: TieringEngineService.pdb source: elevation_service.exe, 0000000A.00000003.1844908082.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ALG.pdb source: gE3uqW5GsF.exe, 00000000.00000003.883729283.0000000003F80000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\orbd_objs\orbd.pdb source: elevation_service.exe, 0000000A.00000003.2032911355.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: msdtcexe.pdb source: elevation_service.exe, 0000000A.00000003.1716338540.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: DiagnosticsHub.StandardCollector.Service.pdb source: elevation_service.exe, 0000000A.00000003.1695564330.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\orbd_objs\orbd.pdb source: elevation_service.exe, 0000000A.00000003.2032911355.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: snmptrap.pdb source: elevation_service.exe, 0000000A.00000003.1790913162.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release\Plug_ins\pi_brokers\32BitMAPIBroker.pdb source: alg.exe, 00000002.00000003.1178415273.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: AppVShNotify.pdbGCTL source: alg.exe, 00000002.00000003.1259584185.00000000014D0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\work\p4\splinters\Splinters\S\BuildResults\bin\Win32\ReaderRelease\FullTrustNotifier\FullTrustNotifier.pdb77.GCTL source: alg.exe, 00000002.00000003.1200066656.0000000001440000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: E:\PkgInstaller\base\ntsetup\SrvPack.Main\tools\sfxcab\sfxcab\objfre\i386\sfxcab.pdb source: alg.exe, 00000002.00000003.1246662600.0000000000400000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1240552902.00000000014D0000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1239695831.0000000001440000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1987913181.0000000000730000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1987701227.00000000007C0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: msiexec.pdb source: elevation_service.exe, 0000000A.00000003.1727072878.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\ktab_objs\ktab.pdb source: elevation_service.exe, 0000000A.00000003.2032427153.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ADelRCP_Exec.pdb source: alg.exe, 00000002.00000003.1104546090.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\pack200_objs\pack200.pdb source: elevation_service.exe, 0000000A.00000003.2033381877.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: crashreporter.pdb source: alg.exe, 00000002.00000003.1398014622.00000000014D0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\rmiregistry_objs\rmiregistry.pdb source: elevation_service.exe, 0000000A.00000003.2034874855.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\plug_ins\pi_brokers\MSRMSPIBroker.pdbAAAGCTL source: alg.exe, 00000002.00000003.1195971677.0000000001440000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: WmiApSrv.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1906964717.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WCChromeNativeMessagingHost.pdb888 source: alg.exe, 00000002.00000003.1129130053.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: Acrobat_SL.pdb((( source: alg.exe, 00000002.00000003.1006248457.00000000014D0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: locator.pdb source: elevation_service.exe, 0000000A.00000003.1768517438.00000000007A0000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1761105676.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ADelRCP_Exec.pdbCC9 source: alg.exe, 00000002.00000003.1104546090.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: E:\PkgInstaller\base\ntsetup\SrvPack.Main\tools\sfxcab\sfxcab\objfre\i386\sfxcab.pdbU source: alg.exe, 00000002.00000003.1246662600.0000000000400000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1240552902.00000000014D0000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1239695831.0000000001440000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1987913181.0000000000730000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1987701227.00000000007C0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WebInstaller\AcroMiniServicesUpdater.pdbT source: alg.exe, 00000002.00000003.1074204227.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\workspace\CR-Windows-x64-Client-Builder\x64\Release\CRWindowsClientService.pdbGG source: alg.exe, 00000002.00000003.1143061380.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\keytool_objs\keytool.pdb source: elevation_service.exe, 0000000A.00000003.2030748443.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\AcrobatInfo.pdb))) source: alg.exe, 00000002.00000003.1000828344.00000000014D0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\jjs_objs\jjs.pdb source: elevation_service.exe, 0000000A.00000003.2029694758.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: mavinject32.pdb source: alg.exe, 00000002.00000003.1275188675.0000000001570000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1278243532.00000000014D0000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1991807866.00000000007C0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: 64BitMAPIBroker.pdb source: alg.exe, 00000002.00000003.1186382661.0000000000400000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: snmptrap.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1790913162.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PerceptionSimulationService.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1743710201.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: msdtcexe.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1716338540.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: E:\jenkins\workspace\NGL_WORKFLOW\build\master\win64\Release\Acrobat\project\win\ngl-workflow\x64\Release (Acrobat)\adobe_licensing_wf_helper_acro.pdb source: alg.exe, 00000002.00000003.1175055133.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\servertool_objs\servertool.pdb source: elevation_service.exe, 0000000A.00000003.2035341861.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\policytool_objs\policytool.pdb source: elevation_service.exe, 0000000A.00000003.2033866814.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release\Plug_ins\pi_brokers\32BitMAPIBroker.pdb@@ source: alg.exe, 00000002.00000003.1178415273.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\work\p4\splinters\Splinters\S\BuildResults\bin\Win32\ReaderRelease\FullTrustNotifier\FullTrustNotifier.pdb source: alg.exe, 00000002.00000003.1200066656.0000000001440000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\klist_objs\klist.pdb source: elevation_service.exe, 0000000A.00000003.2031946678.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\ktab_objs\ktab.pdb source: elevation_service.exe, 0000000A.00000003.2032427153.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\plug_ins\pi_brokers\MSRMSPIBroker.pdb source: alg.exe, 00000002.00000003.1195971677.0000000001440000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: maintenanceservice.pdb` source: alg.exe, 00000002.00000003.951477961.00000000015A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\kinit_objs\kinit.pdb source: elevation_service.exe, 0000000A.00000003.2031244213.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: WmiApSrv.pdb source: elevation_service.exe, 0000000A.00000003.1906964717.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\Eula.pdb source: alg.exe, 00000002.00000003.1147837409.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\elevation_service.exe.pdbOGP source: alg.exe, 00000002.00000003.946145680.0000000001580000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\pack200_objs\pack200.pdb source: elevation_service.exe, 0000000A.00000003.2033381877.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\rmiregistry_objs\rmiregistry.pdb source: elevation_service.exe, 0000000A.00000003.2034874855.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ALG.pdbGCTL source: gE3uqW5GsF.exe, 00000000.00000003.883729283.0000000003F80000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PresentationFontCache.pdbHt^t Pt_CorExeMainmscoree.dll source: elevation_service.exe, 0000000A.00000003.1710332802.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\AcroBroker.pdbTTT source: alg.exe, 00000002.00000003.1015092732.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: locator.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1768517438.00000000007A0000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1761105676.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\klist_objs\klist.pdb source: elevation_service.exe, 0000000A.00000003.2031946678.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\kinit_objs\kinit.pdb source: elevation_service.exe, 0000000A.00000003.2031244213.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ssh-agent.pdbX source: elevation_service.exe, 0000000A.00000003.1833564379.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: AppVShNotify.pdb source: alg.exe, 00000002.00000003.1259584185.00000000014D0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\Eula.pdb888 source: alg.exe, 00000002.00000003.1147837409.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSACCESS.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\servertool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\vds.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\snmptrap.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\Spectrum.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Program Files\Windows Media Player\wmpnetwk.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\Locator.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7z.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | System file written: C:\Windows\System32\AppVClient.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7zG.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\SysWOW64\perfhost.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\msiexec.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\keytool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\notification_click_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_proxy.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\pwahelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\TieringEngineService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\kinit.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\policytool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.ShowHelp.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\Uninstall.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\FXSSVC.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\rmiregistry.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\sppsvc.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\SensorDataService.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\msdtc.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java-rmi.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\wbem\WmiApSrv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedgewebview2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\pack200.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jabswitch.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | System file written: C:\Windows\System32\alg.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\rmid.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7zFM.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\klist.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\tnameserv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\VSSVC.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\wbengine.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\SearchIndexer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\excelcnv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jjs.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\Installer\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\orbd.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\AgentService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_pwa_launcher.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ktab.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\OpenSSH\ssh-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to behavior |
Source: alg.exe, 00000002.00000003.923374644.000000000056F000.00000004.00000020.00020000.00000000.sdmp, hypopygidium.exe, 00000005.00000002.939293947.0000000000CF6000.00000004.00000020.00020000.00000000.sdmp, hypopygidium.exe, 00000005.00000002.939293947.0000000000C4B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/ |
Source: alg.exe, 00000002.00000003.923374644.000000000056F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/P |
Source: alg.exe, 00000002.00000003.966765292.0000000000590000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/ksatkbvjbcbp |
Source: alg.exe, 00000002.00000003.963103436.0000000000590000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.966765292.0000000000590000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/ksatkbvjbcbpW |
Source: alg.exe, 00000002.00000003.963521761.000000000056F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/ngs |
Source: alg.exe, 00000002.00000003.923210611.000000000058E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/pgpsyvgolqpmc |
Source: hypopygidium.exe, 00000005.00000002.939293947.0000000000D05000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196/ywdxws |
Source: alg.exe, 00000002.00000003.963521761.0000000000567000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196:80/ksatkbvjbcbpxdaqem?usid=16&utid=37772501427 |
Source: alg.exe, 00000002.00000003.923374644.0000000000567000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196:80/pgpsyvgolqpmc |
Source: hypopygidium.exe, 00000005.00000002.939293947.0000000000C4B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.213.51.196:80/ywdxws~ |
Source: alg.exe, 00000002.00000003.1009654756.00000000005A3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://192.64.119.165/kgtovhqlcaeuqkq |
Source: alg.exe, 00000002.00000003.1010138757.0000000000567000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://192.64.119.165:80/kgtovhqlcaeuqkqY |
Source: alg.exe, 00000002.00000003.937636528.000000000056F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.229.117.57/ |
Source: alg.exe, 00000002.00000003.937636528.000000000056F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.229.117.57/S |
Source: alg.exe, 00000002.00000003.937636528.000000000056F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.229.117.57/ings |
Source: alg.exe, 00000002.00000003.937410326.0000000000590000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.940515974.0000000000590000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.229.117.57/qamcchldsfnvj |
Source: alg.exe, 00000002.00000003.937410326.00000000005A3000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.940891496.00000000005A3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.229.117.57/qamcchldsfnvjFI |
Source: alg.exe, 00000002.00000003.937410326.0000000000590000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.940515974.0000000000590000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.229.117.57/qamcchldsfnvjn |
Source: alg.exe, 00000002.00000003.937636528.0000000000567000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.229.117.57:80/qamcchldsfnvja |
Source: hypopygidium.exe, 00000003.00000002.914323644.0000000000E0E000.00000004.00000020.00020000.00000000.sdmp, hypopygidium.exe, 00000005.00000002.938962227.0000000000BE8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/ |
Source: alg.exe, 00000002.00000003.910445253.000000000056F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/% |
Source: alg.exe, 00000002.00000003.931424391.000000000056F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/7 |
Source: hypopygidium.exe, 00000005.00000002.939293947.0000000000C4B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/arlkrogjfneqy |
Source: alg.exe, 00000002.00000003.1222995328.000000000056F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.937636528.000000000056F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.910267480.000000000058E000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1010138757.000000000056F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.948812783.000000000056F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.910445253.000000000056F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.963521761.000000000056F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.923374644.000000000056F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.911711145.000000000058B000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.931424391.000000000056F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/dissempitywbyhp |
Source: alg.exe, 00000002.00000003.1222995328.000000000056F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.937636528.000000000056F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1010138757.000000000056F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.948812783.000000000056F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.910445253.000000000056F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.963521761.000000000056F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.923374644.000000000056F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.931424391.000000000056F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/dissempitywbyhpc |
Source: alg.exe, 00000002.00000003.930874914.0000000000590000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.934628164.0000000000590000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.940515974.0000000000590000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.934884165.0000000000598000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.940891496.0000000000598000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/kpjugxagueypvqtl |
Source: gE3uqW5GsF.exe, 00000000.00000002.893240057.0000000000E9C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/l |
Source: hypopygidium.exe, 00000003.00000003.910819925.0000000000E19000.00000004.00000020.00020000.00000000.sdmp, hypopygidium.exe, 00000003.00000002.914455628.0000000000E1C000.00000004.00000020.00020000.00000000.sdmp, hypopygidium.exe, 00000003.00000002.913932138.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp, hypopygidium.exe, 00000003.00000003.911057264.0000000000E1B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/npwlwkgarqxg |
Source: hypopygidium.exe, 00000003.00000002.913932138.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/npwlwkgarqxggs |
Source: hypopygidium.exe, 00000003.00000002.913335669.0000000000D08000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/p |
Source: gE3uqW5GsF.exe, 00000000.00000002.893240057.0000000000E8A000.00000004.00000020.00020000.00000000.sdmp, gE3uqW5GsF.exe, 00000000.00000002.893240057.0000000000E73000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/rskwdg |
Source: gE3uqW5GsF.exe, 00000000.00000002.893240057.0000000000E73000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239/rskwdgX |
Source: alg.exe, 00000002.00000003.910445253.0000000000568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239:80/dissempitywbyhp |
Source: alg.exe, 00000002.00000003.931424391.0000000000567000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239:80/kpjugxagueypvqtl |
Source: gE3uqW5GsF.exe, 00000000.00000002.893240057.0000000000EB2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://52.11.240.239:80/rskwdg |
Source: alg.exe, 00000002.00000003.948650933.00000000005A3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23/vrqavsilxhxdaqem |
Source: alg.exe, 00000002.00000003.948812783.0000000000567000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23:80/vrqavsilxhxdaqem |
Source: alg.exe, 00000002.00000003.1222995328.000000000056F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/ |
Source: alg.exe, 00000002.00000003.1222617056.000000000058E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/fngevnwdrjs |
Source: alg.exe, 00000002.00000003.1223366017.00000000005A3000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1222617056.00000000005A3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/fngevnwdrjsqkq |
Source: alg.exe, 00000002.00000003.1222995328.000000000056F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/gs |
Source: alg.exe, 00000002.00000003.1222995328.0000000000568000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197:80/fngevnwdrjsP |
Source: hypopygidium.exe, 00000003.00000002.913335669.0000000000D08000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://pywolwnvd.biz/ |
Source: alg.exe, 00000002.00000003.948812783.000000000056F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/ |
Source: alg.exe, 00000002.00000003.948650933.00000000005A3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/vrqavsilxhxdaqem?usid=16&utid=37772501427 |
Source: alg.exe, 00000002.00000003.948650933.0000000000590000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/vrqavsilxhxdaqem?usid=16&utid=37772501427LocationETagAuthentication-InfoAgeA |
Source: alg.exe, 00000002.00000003.948812783.0000000000567000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz:80/vrqavsilxhxdaqem?usid=16&utid=37772501427 |
Source: alg.exe, 00000002.00000003.1010138757.000000000056F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.anpmnmxo.biz/ |
Source: alg.exe, 00000002.00000003.1009654756.00000000005A3000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1010425718.00000000005B5000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1009654756.0000000000590000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.anpmnmxo.biz/kgtovhqlcaeuqkq |
Source: alg.exe, 00000002.00000003.1009654756.00000000005A3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.anpmnmxo.biz/kgtovhqlcaeuqkq5/kgtovhqlcaeuqkq |
Source: alg.exe, 00000002.00000003.1012023395.0000000000590000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1009654756.0000000000590000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.anpmnmxo.biz/kgtovhqlcaeuqkqe |
Source: alg.exe, 00000002.00000003.1009654756.00000000005B5000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1010425718.00000000005B5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.anpmnmxo.biz:80/kgtovhqlcaeuqkq |
Source: alg.exe, 00000002.00000003.1073555637.0000000001500000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://www.winimage.com/zLibDll |
Source: alg.exe, 00000002.00000003.1103233090.0000000001500000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://clients2.google.com/service/update2/crxFailed |
Source: alg.exe, 00000002.00000003.1103751768.0000000001500000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1103910646.0000000001500000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://clients2.google.com/service/update2/crxHKEY_LOCAL_MACHINE |
Source: alg.exe, 00000002.00000003.945334879.0000000001580000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://github.com/pq-crystals/kyber/commit/28413dfbf523fdde181246451c2bd77199c0f7ff |
Source: alg.exe, 00000002.00000003.945334879.0000000001580000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://github.com/pq-crystals/kyber/commit/28413dfbf523fdde181246451c2bd77199c0f7ffDilithium2Dilith |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_0040E6A0 | 0_2_0040E6A0 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_0042D975 | 0_2_0042D975 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_004221C5 | 0_2_004221C5 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_004362D2 | 0_2_004362D2 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_004803DA | 0_2_004803DA |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_0043242E | 0_2_0043242E |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_004225FA | 0_2_004225FA |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_0045E616 | 0_2_0045E616 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_004166E1 | 0_2_004166E1 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_0043878F | 0_2_0043878F |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00436844 | 0_2_00436844 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00480857 | 0_2_00480857 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00418808 | 0_2_00418808 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00468889 | 0_2_00468889 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_0042CB21 | 0_2_0042CB21 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00436DB6 | 0_2_00436DB6 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00416F9E | 0_2_00416F9E |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00413030 | 0_2_00413030 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_0042F1D9 | 0_2_0042F1D9 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00423187 | 0_2_00423187 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00421484 | 0_2_00421484 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00415520 | 0_2_00415520 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00427696 | 0_2_00427696 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00415760 | 0_2_00415760 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00421978 | 0_2_00421978 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_0040192B | 0_2_0040192B |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_0040FCE0 | 0_2_0040FCE0 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00487DDB | 0_2_00487DDB |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00421D90 | 0_2_00421D90 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_0042BDA6 | 0_2_0042BDA6 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_0040DF00 | 0_2_0040DF00 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00C700D9 | 0_2_00C700D9 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00C6C7F0 | 0_2_00C6C7F0 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00C351EE | 0_2_00C351EE |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00C36EAF | 0_2_00C36EAF |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00C7515C | 0_2_00C7515C |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00C6D580 | 0_2_00C6D580 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00C63780 | 0_2_00C63780 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00C65980 | 0_2_00C65980 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00C739A3 | 0_2_00C739A3 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00C37B71 | 0_2_00C37B71 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00C37F80 | 0_2_00C37F80 |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Code function: 0_2_00DD8458 | 0_2_00DD8458 |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Code function: 3_2_00B539A3 | 3_2_00B539A3 |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Code function: 3_2_00B16EAF | 3_2_00B16EAF |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Code function: 3_2_00B45980 | 3_2_00B45980 |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Code function: 3_2_00B151EE | 3_2_00B151EE |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Code function: 3_2_00B4D580 | 3_2_00B4D580 |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Code function: 3_2_00B17F80 | 3_2_00B17F80 |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Code function: 3_2_00B43780 | 3_2_00B43780 |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Code function: 3_2_00B4C7F0 | 3_2_00B4C7F0 |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Code function: 3_2_00D57C50 | 3_2_00D57C50 |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Code function: 5_2_00C46DE0 | 5_2_00C46DE0 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 11_2_00C07C00 | 11_2_00C07C00 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 11_2_00C2A810 | 11_2_00C2A810 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 11_2_00C079F0 | 11_2_00C079F0 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 11_2_00C32D40 | 11_2_00C32D40 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 11_2_00C292A0 | 11_2_00C292A0 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 11_2_00C2EEB0 | 11_2_00C2EEB0 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 11_2_00C293B0 | 11_2_00C293B0 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 22_2_0092A810 | 22_2_0092A810 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 22_2_00907C00 | 22_2_00907C00 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 22_2_009079F0 | 22_2_009079F0 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 22_2_00932D40 | 22_2_00932D40 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 22_2_0092EEB0 | 22_2_0092EEB0 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 22_2_009292A0 | 22_2_009292A0 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 22_2_009293B0 | 22_2_009293B0 |
Source: C:\Windows\System32\msdtc.exe | Code function: 23_2_00D7A810 | 23_2_00D7A810 |
Source: C:\Windows\System32\msdtc.exe | Code function: 23_2_00D57C00 | 23_2_00D57C00 |
Source: C:\Windows\System32\msdtc.exe | Code function: 23_2_00D579F0 | 23_2_00D579F0 |
Source: C:\Windows\System32\msdtc.exe | Code function: 23_2_00D82D40 | 23_2_00D82D40 |
Source: C:\Windows\System32\msdtc.exe | Code function: 23_2_00D7EEB0 | 23_2_00D7EEB0 |
Source: C:\Windows\System32\msdtc.exe | Code function: 23_2_00D792A0 | 23_2_00D792A0 |
Source: C:\Windows\System32\msdtc.exe | Code function: 23_2_00D793B0 | 23_2_00D793B0 |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Code function: 24_2_007BA810 | 24_2_007BA810 |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Code function: 24_2_00797C00 | 24_2_00797C00 |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Code function: 24_2_007C2D40 | 24_2_007C2D40 |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Code function: 24_2_007979F0 | 24_2_007979F0 |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Code function: 24_2_007BEEB0 | 24_2_007BEEB0 |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Code function: 24_2_007B92A0 | 24_2_007B92A0 |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Code function: 24_2_007B93B0 | 24_2_007B93B0 |
Source: C:\Windows\System32\Locator.exe | Code function: 26_2_0075A810 | 26_2_0075A810 |
Source: C:\Windows\System32\Locator.exe | Code function: 26_2_00737C00 | 26_2_00737C00 |
Source: C:\Windows\System32\Locator.exe | Code function: 26_2_00762D40 | 26_2_00762D40 |
Source: C:\Windows\System32\Locator.exe | Code function: 26_2_007379F0 | 26_2_007379F0 |
Source: C:\Windows\System32\Locator.exe | Code function: 26_2_0075EEB0 | 26_2_0075EEB0 |
Source: C:\Windows\System32\Locator.exe | Code function: 26_2_007592A0 | 26_2_007592A0 |
Source: C:\Windows\System32\Locator.exe | Code function: 26_2_007593B0 | 26_2_007593B0 |
Source: C:\Windows\System32\SensorDataService.exe | Code function: 27_2_0076A810 | 27_2_0076A810 |
Source: C:\Windows\System32\SensorDataService.exe | Code function: 27_2_00747C00 | 27_2_00747C00 |
Source: C:\Windows\System32\SensorDataService.exe | Code function: 27_2_00772D40 | 27_2_00772D40 |
Source: C:\Windows\System32\SensorDataService.exe | Code function: 27_2_007479F0 | 27_2_007479F0 |
Source: C:\Windows\System32\SensorDataService.exe | Code function: 27_2_0076EEB0 | 27_2_0076EEB0 |
Source: C:\Windows\System32\SensorDataService.exe | Code function: 27_2_007692A0 | 27_2_007692A0 |
Source: C:\Windows\System32\SensorDataService.exe | Code function: 27_2_007693B0 | 27_2_007693B0 |
Source: C:\Windows\System32\snmptrap.exe | Code function: 28_2_0078A810 | 28_2_0078A810 |
Source: C:\Windows\System32\snmptrap.exe | Code function: 28_2_00767C00 | 28_2_00767C00 |
Source: C:\Windows\System32\snmptrap.exe | Code function: 28_2_00792D40 | 28_2_00792D40 |
Source: C:\Windows\System32\snmptrap.exe | Code function: 28_2_007679F0 | 28_2_007679F0 |
Source: C:\Windows\System32\snmptrap.exe | Code function: 28_2_0078EEB0 | 28_2_0078EEB0 |
Source: C:\Windows\System32\snmptrap.exe | Code function: 28_2_007892A0 | 28_2_007892A0 |
Source: C:\Windows\System32\snmptrap.exe | Code function: 28_2_007893B0 | 28_2_007893B0 |
Source: C:\Windows\System32\Spectrum.exe | Code function: 29_2_0070A810 | 29_2_0070A810 |
Source: C:\Windows\System32\Spectrum.exe | Code function: 29_2_006E7C00 | 29_2_006E7C00 |
Source: C:\Windows\System32\Spectrum.exe | Code function: 29_2_00712D40 | 29_2_00712D40 |
Source: C:\Windows\System32\Spectrum.exe | Code function: 29_2_006E79F0 | 29_2_006E79F0 |
Source: C:\Windows\System32\Spectrum.exe | Code function: 29_2_0070EEB0 | 29_2_0070EEB0 |
Source: C:\Windows\System32\Spectrum.exe | Code function: 29_2_007092A0 | 29_2_007092A0 |
Source: C:\Windows\System32\Spectrum.exe | Code function: 29_2_007093B0 | 29_2_007093B0 |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Code function: 31_2_00A87C00 | 31_2_00A87C00 |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Code function: 31_2_00AAA810 | 31_2_00AAA810 |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Code function: 31_2_00A879F0 | 31_2_00A879F0 |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Code function: 31_2_00AB2D40 | 31_2_00AB2D40 |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Code function: 31_2_00AA92A0 | 31_2_00AA92A0 |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Code function: 31_2_00AAEEB0 | 31_2_00AAEEB0 |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Code function: 31_2_00AA93B0 | 31_2_00AA93B0 |
Source: C:\Windows\System32\TieringEngineService.exe | Code function: 32_2_0077A810 | 32_2_0077A810 |
Source: C:\Windows\System32\TieringEngineService.exe | Code function: 32_2_00757C00 | 32_2_00757C00 |
Source: C:\Windows\System32\TieringEngineService.exe | Code function: 32_2_00782D40 | 32_2_00782D40 |
Source: C:\Windows\System32\TieringEngineService.exe | Code function: 32_2_007579F0 | 32_2_007579F0 |
Source: C:\Windows\System32\TieringEngineService.exe | Code function: 32_2_0077EEB0 | 32_2_0077EEB0 |
Source: C:\Windows\System32\TieringEngineService.exe | Code function: 32_2_007792A0 | 32_2_007792A0 |
Source: C:\Windows\System32\TieringEngineService.exe | Code function: 32_2_007793B0 | 32_2_007793B0 |
Source: C:\Windows\System32\AgentService.exe | Code function: 33_2_00647C00 | 33_2_00647C00 |
Source: C:\Windows\System32\AgentService.exe | Code function: 33_2_0066A810 | 33_2_0066A810 |
Source: C:\Windows\System32\AgentService.exe | Code function: 33_2_00672D40 | 33_2_00672D40 |
Source: C:\Windows\System32\AgentService.exe | Code function: 33_2_006479F0 | 33_2_006479F0 |
Source: C:\Windows\System32\AgentService.exe | Code function: 33_2_006692A0 | 33_2_006692A0 |
Source: C:\Windows\System32\AgentService.exe | Code function: 33_2_0066EEB0 | 33_2_0066EEB0 |
Source: C:\Windows\System32\AgentService.exe | Code function: 33_2_006693B0 | 33_2_006693B0 |
Source: C:\Windows\System32\vds.exe | Code function: 34_2_00C17C00 | 34_2_00C17C00 |
Source: C:\Windows\System32\vds.exe | Code function: 34_2_00C3A810 | 34_2_00C3A810 |
Source: C:\Windows\System32\vds.exe | Code function: 34_2_00C179F0 | 34_2_00C179F0 |
Source: C:\Windows\System32\vds.exe | Code function: 34_2_00C42D40 | 34_2_00C42D40 |
Source: C:\Windows\System32\vds.exe | Code function: 34_2_00C392A0 | 34_2_00C392A0 |
Source: C:\Windows\System32\vds.exe | Code function: 34_2_00C3EEB0 | 34_2_00C3EEB0 |
Source: C:\Windows\System32\vds.exe | Code function: 34_2_00C393B0 | 34_2_00C393B0 |
Source: C:\Windows\System32\wbengine.exe | Code function: 38_2_007E7C00 | 38_2_007E7C00 |
Source: C:\Windows\System32\wbengine.exe | Code function: 38_2_0080A810 | 38_2_0080A810 |
Source: C:\Windows\System32\wbengine.exe | Code function: 38_2_007E79F0 | 38_2_007E79F0 |
Source: C:\Windows\System32\wbengine.exe | Code function: 38_2_00812D40 | 38_2_00812D40 |
Source: C:\Windows\System32\wbengine.exe | Code function: 38_2_008092A0 | 38_2_008092A0 |
Source: C:\Windows\System32\wbengine.exe | Code function: 38_2_0080EEB0 | 38_2_0080EEB0 |
Source: C:\Windows\System32\wbengine.exe | Code function: 38_2_008093B0 | 38_2_008093B0 |
Source: gE3uqW5GsF.exe | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: armsvc.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: alg.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: hypopygidium.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVClient.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AutoIt3Help.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AutoIt3_x64.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: klist.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ktab.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: orbd.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: pack200.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: policytool.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: rmid.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: rmiregistry.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: servertool.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ssvagent.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SciTE.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: tnameserv.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AdobeARMHelper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jaureg.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jucheck.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jusched.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: java.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevation_service.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaw.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaws.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: updater.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevation_service.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: maintenanceservice.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7z.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7zFM.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7zG.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: unpack200.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ie_to_edge_stub.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: cookie_exporter.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: identity_helper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: setup.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedgewebview2.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedge_proxy.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedge_pwa_launcher.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: notification_click_helper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: pwahelper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Acrobat.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcrobatInfo.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: acrobat_sl.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedge_proxy.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: pwahelper.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVDllSurrogate.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVDllSurrogate32.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVDllSurrogate64.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVLP.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: OneDriveSetup.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Integrator.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppSharingHookController.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroBroker.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroCEF.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SingleClientServicesUpdater.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroCEF.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SingleClientServicesUpdater.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroTextExtractor.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Common.ShowHelp.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: filecompare.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: excelcnv.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ADelRCP.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: gE3uqW5GsF.exe | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: armsvc.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: alg.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: hypopygidium.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVClient.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AutoIt3Help.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AutoIt3_x64.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: klist.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ktab.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: orbd.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: pack200.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: policytool.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: rmid.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: rmiregistry.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: servertool.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ssvagent.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SciTE.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: tnameserv.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AdobeARMHelper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jaureg.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jucheck.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jusched.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: java.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevation_service.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaw.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaws.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: updater.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevation_service.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: maintenanceservice.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7z.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7zFM.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7zG.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: unpack200.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ie_to_edge_stub.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: cookie_exporter.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: identity_helper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: setup.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedgewebview2.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedge_proxy.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedge_pwa_launcher.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: notification_click_helper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: pwahelper.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Acrobat.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcrobatInfo.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: acrobat_sl.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedge_proxy.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: pwahelper.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVDllSurrogate.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVDllSurrogate32.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVDllSurrogate64.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVLP.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: OneDriveSetup.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Integrator.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppSharingHookController.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroBroker.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroCEF.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SingleClientServicesUpdater.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroCEF.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SingleClientServicesUpdater.exe0.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroTextExtractor.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Common.ShowHelp.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: filecompare.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: excelcnv.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ADelRCP.exe.2.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: drprov.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ntlanman.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: davclnt.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: davhlpr.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: browcli.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: drprov.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: ntlanman.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: davclnt.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: davhlpr.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: browcli.dll | Jump to behavior |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: mpr.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: ntmarta.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: tapi32.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: credui.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: fxstiff.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: fxsresm.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: ualapi.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: msdtctm.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: msdtcprx.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: msdtclog.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mtxclu.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: winmm.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: clusapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: xolehlp.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: ktmw32.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: clusapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: resutils.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: clusapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: resutils.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: comres.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: msdtcvsp1res.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mtxoci.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: oci.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: cscapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: firewallapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: fwbase.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: fwpolicyiomgr.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: hid.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: dxgi.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: devobj.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: mfplat.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: rtworkq.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: windows.devices.perception.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: mediafoundation.defaultperceptionprovider.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: windows.devices.enumeration.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: structuredquery.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: windows.globalization.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: bcp47mrm.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: icu.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: mswb7.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: devdispitemprovider.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: napinsp.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: wshbth.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: winrnr.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: powrprof.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: rmclient.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: rmclient.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: spectrumsyncclient.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: umpdc.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: perceptionsimulationextensions.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: hid.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: holographicruntimes.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: perceptiondevice.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: spatialstore.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: esent.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: analogcommonproxystub.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: capabilityaccessmanagerclient.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: windows.devices.enumeration.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: structuredquery.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: windows.globalization.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: bcp47mrm.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: icu.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: mswb7.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: devdispitemprovider.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: apphelp.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: libcrypto.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: esent.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: clusapi.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: fltlib.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: activeds.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: adsldpc.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: appmanagementconfiguration.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: atl.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: osuninst.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: vdsutil.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: bcd.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: uexfat.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: ulib.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: ifsutil.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: devobj.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: uudf.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: untfs.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: ufat.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: fmifs.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: vssapi.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: virtdisk.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: bcd.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: spp.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: netapi32.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: xmllite.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: clusapi.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: wer.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: vsstrace.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: fltlib.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: fveapi.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: cscapi.dll | |
Source: | Binary string: D:\DCB\CBT_Main\BuildResults\bin\Win32\Release\armsvc.pdb source: gE3uqW5GsF.exe, 00000000.00000003.879053304.0000000003F20000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\AcrobatInfo.pdb source: alg.exe, 00000002.00000003.1000828344.00000000014D0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ssh-agent.pdb source: elevation_service.exe, 0000000A.00000003.1833564379.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\TextExtractor.pdb444 source: alg.exe, 00000002.00000003.1096078215.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\TextExtractor.pdb source: alg.exe, 00000002.00000003.1096078215.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\jjs_objs\jjs.pdb source: elevation_service.exe, 0000000A.00000003.2029694758.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: msiexec.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1727072878.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: mavinject32.pdbGCTL source: alg.exe, 00000002.00000003.1275188675.0000000001570000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1278243532.00000000014D0000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1991807866.00000000007C0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PresentationFontCache.pdb source: elevation_service.exe, 0000000A.00000003.1710332802.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PerceptionSimulationService.pdb source: elevation_service.exe, 0000000A.00000003.1743710201.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: wntdll.pdb source: hypopygidium.exe, 00000003.00000003.909654251.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, hypopygidium.exe, 00000003.00000003.908605538.00000000049D0000.00000004.00001000.00020000.00000000.sdmp, hypopygidium.exe, 00000005.00000003.925887188.0000000004090000.00000004.00001000.00020000.00000000.sdmp, hypopygidium.exe, 00000005.00000003.924943395.0000000004500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WebInstaller\AcroMiniServicesUpdater.pdb source: alg.exe, 00000002.00000003.1074204227.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: MsSense.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1772919470.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x64\ship\click2run\x-none\InspectorOfficeGadget.pdb source: alg.exe, 00000002.00000003.1263628953.0000000001440000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1990443076.00000000007C0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: MsSense.pdb source: elevation_service.exe, 0000000A.00000003.1772919470.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\Acrobat\Installers\ShowAppPickerForPDF\Release_x64\ShowAppPickerForPDF.pdb source: alg.exe, 00000002.00000003.1205596936.0000000001440000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1210405910.0000000000400000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1968363318.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\tnameserv_objs\tnameserv.pdb source: elevation_service.exe, 0000000A.00000003.2036250927.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\servertool_objs\servertool.pdb source: elevation_service.exe, 0000000A.00000003.2035341861.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: DiagnosticsHub.StandardCollector.Service.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1695564330.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\rmid_objs\rmid.pdb source: elevation_service.exe, 0000000A.00000003.2034354690.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\java-rmi_objs\java-rmi.pdb source: elevation_service.exe, 0000000A.00000003.2026847938.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\AcroBroker.pdb source: alg.exe, 00000002.00000003.1015092732.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: Acrobat_SL.pdb source: alg.exe, 00000002.00000003.1006248457.00000000014D0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\policytool_objs\policytool.pdb source: elevation_service.exe, 0000000A.00000003.2033866814.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: maintenanceservice.pdb source: alg.exe, 00000002.00000003.951477961.00000000015A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x64\ship\click2run\x-none\InspectorOfficeGadget.pdbY source: alg.exe, 00000002.00000003.1263628953.0000000001440000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1990443076.00000000007C0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PerfHost.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1750225775.0000000000830000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1759048672.00000000007A0000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1751836179.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WCChromeNativeMessagingHost.pdb source: alg.exe, 00000002.00000003.1129130053.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\rmid_objs\rmid.pdb source: elevation_service.exe, 0000000A.00000003.2034354690.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\elevation_service.exe.pdb source: alg.exe, 00000002.00000003.946145680.0000000001580000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\workspace\CR-Windows-x64-Client-Builder\x64\Release\CRWindowsClientService.pdb source: alg.exe, 00000002.00000003.1143061380.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PerfHost.pdb source: elevation_service.exe, 0000000A.00000003.1750225775.0000000000830000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1759048672.00000000007A0000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1751836179.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\keytool_objs\keytool.pdb source: elevation_service.exe, 0000000A.00000003.2030748443.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\tnameserv_objs\tnameserv.pdb source: elevation_service.exe, 0000000A.00000003.2036250927.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\java-rmi_objs\java-rmi.pdb source: elevation_service.exe, 0000000A.00000003.2026847938.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\Acrobat\Installers\ShowAppPickerForPDF\Release_x64\ShowAppPickerForPDF.pdb$$ source: alg.exe, 00000002.00000003.1205596936.0000000001440000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1210405910.0000000000400000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1968363318.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: wntdll.pdbUGP source: hypopygidium.exe, 00000003.00000003.909654251.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, hypopygidium.exe, 00000003.00000003.908605538.00000000049D0000.00000004.00001000.00020000.00000000.sdmp, hypopygidium.exe, 00000005.00000003.925887188.0000000004090000.00000004.00001000.00020000.00000000.sdmp, hypopygidium.exe, 00000005.00000003.924943395.0000000004500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: TieringEngineService.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1844908082.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: TieringEngineService.pdb source: elevation_service.exe, 0000000A.00000003.1844908082.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ALG.pdb source: gE3uqW5GsF.exe, 00000000.00000003.883729283.0000000003F80000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\orbd_objs\orbd.pdb source: elevation_service.exe, 0000000A.00000003.2032911355.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: msdtcexe.pdb source: elevation_service.exe, 0000000A.00000003.1716338540.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: DiagnosticsHub.StandardCollector.Service.pdb source: elevation_service.exe, 0000000A.00000003.1695564330.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\orbd_objs\orbd.pdb source: elevation_service.exe, 0000000A.00000003.2032911355.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: snmptrap.pdb source: elevation_service.exe, 0000000A.00000003.1790913162.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release\Plug_ins\pi_brokers\32BitMAPIBroker.pdb source: alg.exe, 00000002.00000003.1178415273.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: AppVShNotify.pdbGCTL source: alg.exe, 00000002.00000003.1259584185.00000000014D0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\work\p4\splinters\Splinters\S\BuildResults\bin\Win32\ReaderRelease\FullTrustNotifier\FullTrustNotifier.pdb77.GCTL source: alg.exe, 00000002.00000003.1200066656.0000000001440000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: E:\PkgInstaller\base\ntsetup\SrvPack.Main\tools\sfxcab\sfxcab\objfre\i386\sfxcab.pdb source: alg.exe, 00000002.00000003.1246662600.0000000000400000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1240552902.00000000014D0000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1239695831.0000000001440000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1987913181.0000000000730000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1987701227.00000000007C0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: msiexec.pdb source: elevation_service.exe, 0000000A.00000003.1727072878.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\ktab_objs\ktab.pdb source: elevation_service.exe, 0000000A.00000003.2032427153.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ADelRCP_Exec.pdb source: alg.exe, 00000002.00000003.1104546090.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\pack200_objs\pack200.pdb source: elevation_service.exe, 0000000A.00000003.2033381877.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: crashreporter.pdb source: alg.exe, 00000002.00000003.1398014622.00000000014D0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\rmiregistry_objs\rmiregistry.pdb source: elevation_service.exe, 0000000A.00000003.2034874855.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\plug_ins\pi_brokers\MSRMSPIBroker.pdbAAAGCTL source: alg.exe, 00000002.00000003.1195971677.0000000001440000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: WmiApSrv.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1906964717.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WCChromeNativeMessagingHost.pdb888 source: alg.exe, 00000002.00000003.1129130053.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: Acrobat_SL.pdb((( source: alg.exe, 00000002.00000003.1006248457.00000000014D0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: locator.pdb source: elevation_service.exe, 0000000A.00000003.1768517438.00000000007A0000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1761105676.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ADelRCP_Exec.pdbCC9 source: alg.exe, 00000002.00000003.1104546090.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: E:\PkgInstaller\base\ntsetup\SrvPack.Main\tools\sfxcab\sfxcab\objfre\i386\sfxcab.pdbU source: alg.exe, 00000002.00000003.1246662600.0000000000400000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1240552902.00000000014D0000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1239695831.0000000001440000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1987913181.0000000000730000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1987701227.00000000007C0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WebInstaller\AcroMiniServicesUpdater.pdbT source: alg.exe, 00000002.00000003.1074204227.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\workspace\CR-Windows-x64-Client-Builder\x64\Release\CRWindowsClientService.pdbGG source: alg.exe, 00000002.00000003.1143061380.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\keytool_objs\keytool.pdb source: elevation_service.exe, 0000000A.00000003.2030748443.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\AcrobatInfo.pdb))) source: alg.exe, 00000002.00000003.1000828344.00000000014D0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\jjs_objs\jjs.pdb source: elevation_service.exe, 0000000A.00000003.2029694758.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: mavinject32.pdb source: alg.exe, 00000002.00000003.1275188675.0000000001570000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 00000002.00000003.1278243532.00000000014D0000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1991807866.00000000007C0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: 64BitMAPIBroker.pdb source: alg.exe, 00000002.00000003.1186382661.0000000000400000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: snmptrap.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1790913162.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PerceptionSimulationService.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1743710201.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: msdtcexe.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1716338540.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: E:\jenkins\workspace\NGL_WORKFLOW\build\master\win64\Release\Acrobat\project\win\ngl-workflow\x64\Release (Acrobat)\adobe_licensing_wf_helper_acro.pdb source: alg.exe, 00000002.00000003.1175055133.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\servertool_objs\servertool.pdb source: elevation_service.exe, 0000000A.00000003.2035341861.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\policytool_objs\policytool.pdb source: elevation_service.exe, 0000000A.00000003.2033866814.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release\Plug_ins\pi_brokers\32BitMAPIBroker.pdb@@ source: alg.exe, 00000002.00000003.1178415273.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\work\p4\splinters\Splinters\S\BuildResults\bin\Win32\ReaderRelease\FullTrustNotifier\FullTrustNotifier.pdb source: alg.exe, 00000002.00000003.1200066656.0000000001440000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\klist_objs\klist.pdb source: elevation_service.exe, 0000000A.00000003.2031946678.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\ktab_objs\ktab.pdb source: elevation_service.exe, 0000000A.00000003.2032427153.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\plug_ins\pi_brokers\MSRMSPIBroker.pdb source: alg.exe, 00000002.00000003.1195971677.0000000001440000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: maintenanceservice.pdb` source: alg.exe, 00000002.00000003.951477961.00000000015A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\kinit_objs\kinit.pdb source: elevation_service.exe, 0000000A.00000003.2031244213.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: WmiApSrv.pdb source: elevation_service.exe, 0000000A.00000003.1906964717.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\Eula.pdb source: alg.exe, 00000002.00000003.1147837409.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\elevation_service.exe.pdbOGP source: alg.exe, 00000002.00000003.946145680.0000000001580000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\pack200_objs\pack200.pdb source: elevation_service.exe, 0000000A.00000003.2033381877.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\rmiregistry_objs\rmiregistry.pdb source: elevation_service.exe, 0000000A.00000003.2034874855.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ALG.pdbGCTL source: gE3uqW5GsF.exe, 00000000.00000003.883729283.0000000003F80000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PresentationFontCache.pdbHt^t Pt_CorExeMainmscoree.dll source: elevation_service.exe, 0000000A.00000003.1710332802.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\AcroBroker.pdbTTT source: alg.exe, 00000002.00000003.1015092732.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: locator.pdbGCTL source: elevation_service.exe, 0000000A.00000003.1768517438.00000000007A0000.00000004.00001000.00020000.00000000.sdmp, elevation_service.exe, 0000000A.00000003.1761105676.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\klist_objs\klist.pdb source: elevation_service.exe, 0000000A.00000003.2031946678.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\kinit_objs\kinit.pdb source: elevation_service.exe, 0000000A.00000003.2031244213.0000000000730000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ssh-agent.pdbX source: elevation_service.exe, 0000000A.00000003.1833564379.0000000000830000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: AppVShNotify.pdb source: alg.exe, 00000002.00000003.1259584185.00000000014D0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\Eula.pdb888 source: alg.exe, 00000002.00000003.1147837409.0000000001500000.00000004.00001000.00020000.00000000.sdmp |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSACCESS.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\servertool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\vds.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\snmptrap.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\Spectrum.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Program Files\Windows Media Player\wmpnetwk.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\Locator.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7z.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | System file written: C:\Windows\System32\AppVClient.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7zG.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\SysWOW64\perfhost.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\msiexec.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\keytool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\notification_click_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_proxy.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\pwahelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\TieringEngineService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\kinit.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\policytool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.ShowHelp.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\Uninstall.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\FXSSVC.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\rmiregistry.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\sppsvc.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\SensorDataService.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\msdtc.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java-rmi.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\wbem\WmiApSrv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedgewebview2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\pack200.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jabswitch.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | System file written: C:\Windows\System32\alg.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\rmid.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7zFM.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\klist.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\tnameserv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\VSSVC.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\wbengine.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\SearchIndexer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\excelcnv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jjs.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\Installer\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\orbd.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\AgentService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_pwa_launcher.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ktab.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\OpenSSH\ssh-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\servertool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\vds.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\snmptrap.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\Spectrum.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Program Files\Windows Media Player\wmpnetwk.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\Locator.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\7-Zip\7z.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File created: C:\Windows\System32\AppVClient.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\7-Zip\7zG.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\SysWOW64\perfhost.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\msiexec.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\keytool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\notification_click_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_proxy.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\pwahelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\TieringEngineService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\updater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\kinit.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\policytool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.ShowHelp.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\7-Zip\Uninstall.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\FXSSVC.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File created: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\rmiregistry.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\sppsvc.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\SensorDataService.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\msdtc.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\java-rmi.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\wbem\WmiApSrv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedgewebview2.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\pack200.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\jabswitch.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File created: C:\Windows\System32\alg.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File created: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\rmid.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\7-Zip\7zFM.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\klist.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\tnameserv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\VSSVC.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\wbengine.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\SearchIndexer.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\excelcnv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\jjs.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\Installer\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\orbd.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\AgentService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_pwa_launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\ktab.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\OpenSSH\ssh-agent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Users\user\AppData\Roaming\6dcd1f093e5cfc52.bin offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 162304 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 735820 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 737280 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 1285120 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 1286144 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 1289427 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 735744 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 31704 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Users\user\AppData\Local\Temp\aut3220.tmp offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Users\user\AppData\Local\Temp\aut3220.tmp offset: 737280 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Users\user\AppData\Local\Temp\Glagolitic offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\alg.exe offset: 95744 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\alg.exe offset: 669260 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\alg.exe offset: 672768 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\alg.exe offset: 1220608 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\alg.exe offset: 1221632 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\alg.exe offset: 1224840 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\alg.exe offset: 669184 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\alg.exe offset: 53125 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\AppVClient.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\AppVClient.exe offset: 767488 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\AppVClient.exe offset: 1341004 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\AppVClient.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\AppVClient.exe offset: 1344512 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\AppVClient.exe offset: 1347720 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\AppVClient.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\AppVClient.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\AppVClient.exe offset: 1340928 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Windows\System32\AppVClient.exe offset: 409168 | Jump to behavior |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | File written: C:\Users\user\AppData\Local\flexuosely\hypopygidium.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Windows\System32\config\systemprofile\AppData\Roaming\6dcd1f093e5cfc52.bin offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe offset: 2136576 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe offset: 2710092 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe offset: 2710016 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe offset: 1093484 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe offset: 5735424 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe offset: 6308940 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe offset: 6308864 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe offset: 2318133 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 1776128 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 2349644 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 2349568 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 677164 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 228352 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 801868 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 801792 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 43297 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 557056 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 1130572 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 1130496 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 382726 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 952832 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 1526348 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 1526272 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 614020 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 700416 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 1273932 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 1273856 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 464916 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 14848 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 588364 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 588288 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 5610 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 5630464 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 6203980 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 6203904 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 3201596 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 27136 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 600652 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 8988 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 31744 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 605260 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 605184 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 12684 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 332800 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 906316 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 906240 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 232412 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 3571200 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 4144716 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 4144640 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 1485948 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 59362816 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 59936332 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 59936256 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 140924 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 3571200 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 4144716 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 4144640 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 1485948 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 59362816 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 59936332 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 59936256 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 140924 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 50176 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 623692 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 623616 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 24668 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe offset: 328192 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe offset: 901708 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe offset: 901632 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe offset: 4988 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 642048 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 1215564 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 1215488 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 132252 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 11459072 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 12032588 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 12032512 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 4630732 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 192512 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 766028 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 765952 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 95345 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 759296 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 1332812 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 1332736 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 285633 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 385536 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 959052 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 958976 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 182364 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 123904 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 697420 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 697344 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 66716 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 1102848 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 1676364 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 1676288 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 753617 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 2531840 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 3105356 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 3105280 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 1150992 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 459776 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 1033292 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 1033216 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 209348 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 99840 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 673356 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 673280 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 69527 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 256512 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 830028 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 829952 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 72028 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 521216 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 1094732 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 1094656 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 321696 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 210944 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 784460 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 784384 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 126840 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 13312 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 586828 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 586752 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 2828 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 4785664 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 5359180 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 5359104 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 2430581 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 632832 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 1206348 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 1206272 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 206444 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 2578944 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 3152460 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 3152384 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 16859 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 1617920 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 2191436 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 2191360 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 860981 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 258048 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 831564 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 831488 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 82352 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 5274624 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 5848140 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 5848064 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 3286540 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 185344 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 758860 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 758784 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 151349 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 26954240 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 27527756 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 27527680 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 11401068 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 4392960 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 4966476 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 4966400 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 2843313 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe offset: 1755648 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe offset: 2329164 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe offset: 2329088 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe offset: 740604 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe offset: 3347968 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe offset: 3921484 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe offset: 3921408 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe offset: 1777084 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe offset: 6470144 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe offset: 7043660 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe offset: 7043584 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe offset: 2807964 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe offset: 6470144 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe offset: 7043660 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe offset: 7043584 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe offset: 2807964 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe offset: 1665536 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe offset: 2239052 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe offset: 2238976 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe offset: 853340 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe offset: 1861120 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe offset: 2434636 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe offset: 2434560 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe offset: 910188 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 1445888 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 2019404 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 2019328 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 728892 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 248832 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 822348 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 822272 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 121980 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 707072 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 1280588 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 1280512 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 346881 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 666112 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 1239628 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 1239552 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 193089 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 228352 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 801868 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 801792 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 43297 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 762368 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 1335884 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 1335808 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 239297 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 70144 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 643660 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 643584 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 32241 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 279040 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 852556 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 852480 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 111633 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 55296 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 628812 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 628736 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 4108 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 403968 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 977484 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 977408 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 79009 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\servertool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Dropped PE file which has not been started: C:\Program Files\Windows Media Player\wmpnetwk.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\7-Zip\7z.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Dropped PE file which has not been started: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\gE3uqW5GsF.exe | Dropped PE file which has not been started: C:\Windows\System32\AppVClient.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\7-Zip\7zG.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Dropped PE file which has not been started: C:\Windows\System32\msiexec.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\keytool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevation_service.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\134.0.6998.36\os_update_handler.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\notification_click_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_proxy.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\pwahelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\updater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\kinit.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\policytool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.ShowHelp.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\7-Zip\Uninstall.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\rmiregistry.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Dropped PE file which has not been started: C:\Windows\System32\sppsvc.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Dropped PE file which has not been started: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\java-rmi.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Dropped PE file which has not been started: C:\Windows\System32\wbem\WmiApSrv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedgewebview2.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\pack200.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\jabswitch.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\rmid.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\7-Zip\7zFM.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\klist.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\tnameserv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Dropped PE file which has not been started: C:\Windows\System32\VSSVC.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Dropped PE file which has not been started: C:\Windows\System32\SearchIndexer.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\excelcnv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\134.0.6998.36\Installer\chrmstp.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\134.0.6998.36\notification_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\jjs.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\Installer\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\orbd.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\134.0.6998.36\chrome_pwa_launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\134.0.6998.36\elevated_tracing_service.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_pwa_launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\ktab.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to dropped file |