Source: RegSvcs.exe, 00000003.00000002.464101728.0000000003331000.00000004.00000001.sdmp | String found in binary or memory: http://127.0.0.1:HTTP/1.1 |
Source: RegSvcs.exe, 00000003.00000002.465723831.0000000003696000.00000004.00000001.sdmp, RegSvcs.exe, 00000003.00000002.465745478.00000000036A0000.00000004.00000001.sdmp, RegSvcs.exe, 00000003.00000002.464101728.0000000003331000.00000004.00000001.sdmp, RegSvcs.exe, 00000003.00000002.465591581.0000000003659000.00000004.00000001.sdmp | String found in binary or memory: http://C0BJotQhI3.net |
Source: RegSvcs.exe, 00000003.00000002.464101728.0000000003331000.00000004.00000001.sdmp | String found in binary or memory: http://DynDns.comDynDNS |
Source: RegSvcs.exe, 00000003.00000002.464101728.0000000003331000.00000004.00000001.sdmp | String found in binary or memory: http://TDhznh.com |
Source: RegSvcs.exe, 00000003.00000002.465723831.0000000003696000.00000004.00000001.sdmp | String found in binary or memory: http://mail.hemetek.com |
Source: QUOTATION REQUEST.exe, 00000000.00000002.212172469.0000000002AA1000.00000004.00000001.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: RegSvcs.exe, 00000003.00000002.464101728.0000000003331000.00000004.00000001.sdmp | String found in binary or memory: https://api.ipify.orgGETMozilla/5.0 |
Source: QUOTATION REQUEST.exe, 00000000.00000002.212843504.0000000003B43000.00000004.00000001.sdmp, RegSvcs.exe, 00000003.00000002.462144655.0000000000402000.00000040.00000001.sdmp | String found in binary or memory: https://api.telegram.org/bot%telegramapi%/ |
Source: RegSvcs.exe, 00000003.00000002.464101728.0000000003331000.00000004.00000001.sdmp | String found in binary or memory: https://api.telegram.org/bot%telegramapi%/sendDocumentdocument---------------------------x |
Source: QUOTATION REQUEST.exe, 00000000.00000002.212843504.0000000003B43000.00000004.00000001.sdmp, RegSvcs.exe, 00000003.00000002.462144655.0000000000402000.00000040.00000001.sdmp | String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip |
Source: RegSvcs.exe, 00000003.00000002.464101728.0000000003331000.00000004.00000001.sdmp | String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Process information set: NOOPENFILEERRORBOX |
Source: QUOTATION REQUEST.exe, 00000000.00000002.212705548.0000000002E3E000.00000004.00000001.sdmp | Binary or memory string: VMware |
Source: RegSvcs.exe, 00000003.00000002.467751584.00000000064B0000.00000002.00000001.sdmp | Binary or memory string: A Virtual Machine could not be started because Hyper-V is not installed. |
Source: QUOTATION REQUEST.exe, 00000000.00000002.212172469.0000000002AA1000.00000004.00000001.sdmp | Binary or memory string: vmware |
Source: QUOTATION REQUEST.exe, 00000000.00000002.212172469.0000000002AA1000.00000004.00000001.sdmp | Binary or memory string: l%C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\ |
Source: QUOTATION REQUEST.exe, 00000000.00000002.212172469.0000000002AA1000.00000004.00000001.sdmp | Binary or memory string: VMWARE |
Source: RegSvcs.exe, 00000003.00000002.467684080.00000000063B0000.00000004.00000001.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllurrentControlSet\Control\ProductOptions|ProductSuiteOSType |
Source: QUOTATION REQUEST.exe, 00000000.00000002.212705548.0000000002E3E000.00000004.00000001.sdmp | Binary or memory string: InstallPath%C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\ |
Source: RegSvcs.exe, 00000003.00000002.467751584.00000000064B0000.00000002.00000001.sdmp | Binary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service. |
Source: RegSvcs.exe, 00000003.00000002.467751584.00000000064B0000.00000002.00000001.sdmp | Binary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported. |
Source: QUOTATION REQUEST.exe, 00000000.00000002.212172469.0000000002AA1000.00000004.00000001.sdmp | Binary or memory string: VMware SVGA II |
Source: QUOTATION REQUEST.exe, 00000000.00000002.212705548.0000000002E3E000.00000004.00000001.sdmp | Binary or memory string: VMware |
Source: QUOTATION REQUEST.exe, 00000000.00000002.212705548.0000000002E3E000.00000004.00000001.sdmp | Binary or memory string: VMWARE"SOFTWARE\VMware, Inc.\VMware ToolsLHARDWARE\DEVICEMAP\Scsi\Scsi Port 1\Scsi Bus 0\Target Id 0\Logical Unit Id 0LHARDWARE\DEVICEMAP\Scsi\Scsi Port 2\Scsi Bus 0\Target Id 0\Logical Unit Id 0'SYSTEM\ControlSet001\Services\Disk\Enum |
Source: QUOTATION REQUEST.exe, 00000000.00000002.212705548.0000000002E3E000.00000004.00000001.sdmp | Binary or memory string: vmwareNSYSTEM\ControlSet001\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000 |
Source: QUOTATION REQUEST.exe, 00000000.00000002.212172469.0000000002AA1000.00000004.00000001.sdmp | Binary or memory string: l"SOFTWARE\VMware, Inc.\VMware Tools |
Source: RegSvcs.exe, 00000003.00000002.467751584.00000000064B0000.00000002.00000001.sdmp | Binary or memory string: An unknown internal message was received by the Hyper-V Compute Service. |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Queries volume information: C:\Users\user\Desktop\QUOTATION REQUEST.exe VolumeInformation |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation |
Source: C:\Users\user\Desktop\QUOTATION REQUEST.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Queries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Queries volume information: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe VolumeInformation |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll VolumeInformation |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll VolumeInformation |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll VolumeInformation |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll VolumeInformation |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Queries volume information: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe VolumeInformation |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll VolumeInformation |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll VolumeInformation |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll VolumeInformation |
Source: C:\Users\user\AppData\Roaming\lEmohP\lEmohP.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll VolumeInformation |