Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\DESKTOP\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\DEFAULT\DESKTOP\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\PLAYREADY\INTERNET EXPLORER\DESKTOP\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\PLAYREADY\INTERNET EXPLORER\INPRIVATE\DESKTOP\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\AC\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\AC\INETCACHE\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\AC\TEMP\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\APPDATA\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\LOCALCACHE\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\LOCALSTATE\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\ROAMINGSTATE\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\SETTINGS\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\SYSTEMAPPDATA\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\TEMPSTATE\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\AC\INETCOOKIES\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\AC\INETHISTORY\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCALLOW\ADOBE\ACROBAT\DC\READER\DESKTOPNOTIFICATION\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCALLOW\ADOBE\ACROBAT\DC\READER\DESKTOPNOTIFICATION\NOTIFICATIONSDB\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\BNAGMGSPLO\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\EOWRVPQCCS\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\GAOBCVIQIJ\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\KLIZUSIQEN\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\PALRGUCVEH\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\QCFWYSKMHA\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\QCOILOQIKC\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\QNCYCDFIJJ\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\SQSJKEBWDT\readme.txt | Jump to behavior |
Source: explorer.exe, 00000004.00000000.244760159.0000000008815000.00000004.00000001.sdmp, explorer.exe, 00000007.00000003.304293863.00000000086A4000.00000004.00000001.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: SearchUI.exe, 00000010.00000002.388127839.000001D3D0153000.00000004.00000001.sdmp | String found in binary or memory: http://crl3.digicert.com/Omniroot2025.crl0 |
Source: SearchUI.exe, 00000010.00000002.402422907.000001DBD1FA0000.00000004.00000001.sdmp, SearchUI.exe, 00000010.00000003.315552702.000001DBD10D5000.00000004.00000001.sdmp, SearchUI.exe, 0000001C.00000003.471307339.0000015F3591D000.00000004.00000001.sdmp | String found in binary or memory: http://facebook.github.io/react/docs/error-decoder.html?invariant |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://fontfabrik.com |
Source: SearchUI.exe, 00000010.00000002.388127839.000001D3D0153000.00000004.00000001.sdmp | String found in binary or memory: http://ocsp.digicert.com0: |
Source: SearchUI.exe, 00000010.00000002.390778572.000001DBD0713000.00000004.00000001.sdmp | String found in binary or memory: http://ocsp.msocsp.com0 |
Source: SearchUI.exe, 00000010.00000002.360389895.000001D3C8829000.00000004.00000001.sdmp | String found in binary or memory: http://schema.org/reminder |
Source: SearchUI.exe, 00000010.00000002.382569753.000001D3CED5D000.00000004.00000001.sdmp, SearchUI.exe, 0000001C.00000003.444095457.0000015734983000.00000004.00000001.sdmp | String found in binary or memory: http://schemas.live.com/Web/ |
Source: SearchUI.exe, 00000010.00000002.360813914.000001D3C88B2000.00000004.00000001.sdmp | String found in binary or memory: http://schemas.live.com/Web/1bet |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.carterandcone.coml |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com |
Source: SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/? |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/frere-jones.html |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers8 |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers? |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designersG |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.fonts.com |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.founder.com.cn/cn |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.founder.com.cn/cn/bThe |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.founder.com.cn/cn/cThe |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.galapagosdesign.com/DPlease |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.goodfont.co.kr |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/ |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.sajatypeworks.com |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.sakkal.com |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.sandoll.co.kr |
Source: SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.tiro.com |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.typography.netD |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.urwpp.deDPlease |
Source: explorer.exe, 00000004.00000000.245472359.0000000008B46000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.381017627.000001D3CD176000.00000002.00000001.sdmp | String found in binary or memory: http://www.zhongyicts.com.cn |
Source: SearchUI.exe, 00000010.00000003.314054866.000001DBD0CB8000.00000004.00000001.sdmp | String found in binary or memory: https://aefd.nelreports.ne |
Source: SearchUI.exe, 0000001C.00000003.470980310.0000015F358EE000.00000004.00000001.sdmp | String found in binary or memory: https://aefd.nelreports.net/api/report?cat=bingaot |
Source: SearchUI.exe, 0000001C.00000003.470980310.0000015F358EE000.00000004.00000001.sdmp | String found in binary or memory: https://aefd.nelreports.net/api/report?cat=bingrms |
Source: SearchUI.exe, 0000001C.00000003.440038340.0000015F35845000.00000004.00000001.sdmp | String found in binary or memory: https://aefd.nelreports.net/api/report?catHTTP/1.1 |
Source: SearchUI.exe, 00000010.00000002.362630751.000001D3C89B1000.00000004.00000001.sdmp | String found in binary or memory: https://api.msn.com/news/feed?m |
Source: SearchUI.exe, 00000010.00000002.399294977.000001DBD1939000.00000004.00000001.sdmp | String found in binary or memory: https://api.msn.com/news/feed?market=en-us&query= |
Source: SearchUI.exe, 00000010.00000003.314210472.000001DBD0760000.00000004.00000001.sdmp, SearchUI.exe, 0000001C.00000003.435616084.0000015F35883000.00000004.00000001.sdmp | String found in binary or memory: https://mths.be/fromcodepoint |
Source: SearchUI.exe, 00000010.00000002.398688297.000001DBD18B0000.00000004.00000001.sdmp | String found in binary or memory: https://onedrive.live.com |
Source: SearchUI.exe, 00000010.00000002.393819543.000001DBD0FD0000.00000004.00000001.sdmp, SearchUI.exe, 00000010.00000002.392775499.000001DBD0C35000.00000004.00000001.sdmp, SearchUI.exe, 00000010.00000002.392749175.000001DBD0C24000.00000004.00000001.sdmp | String found in binary or memory: https://outlook.office.com/ |
Source: SearchUI.exe, 00000010.00000002.393819543.000001DBD0FD0000.00000004.00000001.sdmp, SearchUI.exe, 00000010.00000002.392775499.000001DBD0C35000.00000004.00000001.sdmp, SearchUI.exe, 00000010.00000002.392749175.000001DBD0C24000.00000004.00000001.sdmp | String found in binary or memory: https://outlook.office.com/User.ReadWrite |
Source: SearchUI.exe, 00000010.00000002.404559929.000001DBD317C000.00000004.00000001.sdmp | String found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json/v1.0/ |
Source: SearchUI.exe, 00000010.00000002.360389895.000001D3C8829000.00000004.00000001.sdmp | String found in binary or memory: https://pf.directory.live.com/profile/profile.asmxModule |
Source: SearchUI.exe, 00000010.00000002.399079858.000001DBD1910000.00000004.00000001.sdmp | String found in binary or memory: https://substrate.office.com |
Source: SearchUI.exe, 00000010.00000002.393819543.000001DBD0FD0000.00000004.00000001.sdmp, SearchUI.exe, 00000010.00000002.392775499.000001DBD0C35000.00000004.00000001.sdmp, SearchUI.exe, 00000010.00000002.392749175.000001DBD0C24000.00000004.00000001.sdmp | String found in binary or memory: https://substrate.office.com/api/v2.0/Users( |
Source: SearchUI.exe, 00000010.00000002.393819543.000001DBD0FD0000.00000004.00000001.sdmp, SearchUI.exe, 00000010.00000002.392775499.000001DBD0C35000.00000004.00000001.sdmp, SearchUI.exe, 00000010.00000002.392749175.000001DBD0C24000.00000004.00000001.sdmp | String found in binary or memory: https://substrate.office.com/profile/v0/users/ |
Source: SearchUI.exe, 00000010.00000002.398360766.000001DBD1870000.00000004.00000001.sdmp, SearchUI.exe, 00000010.00000002.362630751.000001D3C89B1000.00000004.00000001.sdmp | String found in binary or memory: https://www.msn.com/news?ocid= |
Source: SearchUI.exe, 00000010.00000002.386080523.000001D3CFEA8000.00000004.00000001.sdmp | String found in binary or memory: https://www.msn.com/spartan/dhp |
Source: SearchUI.exe, 00000010.00000002.386080523.000001D3CFEA8000.00000004.00000001.sdmp | String found in binary or memory: https://www.msn.com/spartan/ntp |
Source: SearchUI.exe, 0000001C.00000003.444095457.0000015734983000.00000004.00000001.sdmp | String found in binary or memory: https://www.msn.com/spartan/ntpC: |
Source: bkscEXd86b.exe, 00000000.00000002.495560404.0000000000C80000.00000002.00020000.sdmp | String found in binary or memory: https://www.openssl.org/docs/faq.html |
Source: bkscEXd86b.exe, 00000000.00000002.495560404.0000000000C80000.00000002.00020000.sdmp | String found in binary or memory: https://www.openssl.org/docs/faq.html....................crypto |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\application data\application data\application data\application data\application data\application data\google\chrome\user data\chrome_shutdown_ms.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\internet explorer\brndlog.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\devicesearchcache\settingscache.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\devicesearchcache\appcache132600094041057726.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\devicesearchcache\appcache132600094049800822.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\input_{c489dd0d-bac7-4129-ae50-28d7b3fe49ef}\appsglobals.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\input_{c489dd0d-bac7-4129-ae50-28d7b3fe49ef}\appssynonyms.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_2[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_3[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_4[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_5[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_6[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_7[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_8[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_9[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\apps_{9cfaf1d6-6e29-48d5-bbca-37818f17724f}\0.0.filtertrie.intermediate.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\apps_{9cfaf1d6-6e29-48d5-bbca-37818f17724f}\0.1.filtertrie.intermediate.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\apps_{9cfaf1d6-6e29-48d5-bbca-37818f17724f}\0.2.filtertrie.intermediate.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\apps_{bd237dcd-6d0f-41da-b592-06046b8e7fc0}\0.0.filtertrie.intermediate.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\apps_{bd237dcd-6d0f-41da-b592-06046b8e7fc0}\0.1.filtertrie.intermediate.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\apps_{bd237dcd-6d0f-41da-b592-06046b8e7fc0}\0.2.filtertrie.intermediate.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\apps_{f2b360b1-22a9-410c-8bc0-d5be522c6486}\0.0.filtertrie.intermediate.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\apps_{f2b360b1-22a9-410c-8bc0-d5be522c6486}\0.1.filtertrie.intermediate.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\apps_{f2b360b1-22a9-410c-8bc0-d5be522c6486}\0.2.filtertrie.intermediate.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\input_{c489dd0d-bac7-4129-ae50-28d7b3fe49ef}\appsconversions.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\input_{c489dd0d-bac7-4129-ae50-28d7b3fe49ef}\settingsconversions.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\input_{c489dd0d-bac7-4129-ae50-28d7b3fe49ef}\settingsglobals.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\input_{c489dd0d-bac7-4129-ae50-28d7b3fe49ef}\settingssynonyms.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\settings_{311bc890-0d64-4a61-ae62-e2a43e6cb7e1}\0.0.filtertrie.intermediate.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\settings_{311bc890-0d64-4a61-ae62-e2a43e6cb7e1}\0.1.filtertrie.intermediate.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\settings_{311bc890-0d64-4a61-ae62-e2a43e6cb7e1}\0.2.filtertrie.intermediate.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\settings_{383cd175-ae3a-4e7b-8db0-9b5863f23264}\0.0.filtertrie.intermediate.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\settings_{383cd175-ae3a-4e7b-8db0-9b5863f23264}\0.1.filtertrie.intermediate.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\localstate\constraintindex\settings_{383cd175-ae3a-4e7b-8db0-9b5863f23264}\0.2.filtertrie.intermediate.txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_10[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_11[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_12[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_13[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_14[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_15[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_16[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_17[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_18[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_19[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_20[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_21[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_22[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_23[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_24[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_25[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_26[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\appdata\local\application data\application data\packages\microsoft.windows.cortana_cw5n1h2txyewy\ac\appcache\n5v1zr9c\1\c__windows_systemapps_microsoft.windows.cortana_cw5n1h2txyewy_cache_desktop_27[1].txt.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\desktop\gaobcviqij\gaobcviqij.docx.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\desktop\gaobcviqij.docx.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\desktop\qcfwyskmha\qcfwyskmha.docx.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\desktop\qcfwyskmha.docx.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\desktop\qncycdfijj\qncycdfijj.docx.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\desktop\qncycdfijj.docx.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\documents\gaobcviqij\gaobcviqij.docx.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: c:\documents and settings\user\documents\gaobcviqij.docx.crypt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9A8B0 | 0_2_00B9A8B0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BA4080 | 0_2_00BA4080 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9E8F0 | 0_2_00B9E8F0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BB40F0 | 0_2_00BB40F0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B99030 | 0_2_00B99030 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9F830 | 0_2_00B9F830 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BCA800 | 0_2_00BCA800 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BB9070 | 0_2_00BB9070 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BB605D | 0_2_00BB605D |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BA2850 | 0_2_00BA2850 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9E1E0 | 0_2_00B9E1E0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9D1E0 | 0_2_00B9D1E0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9D9D9 | 0_2_00B9D9D9 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BA41C0 | 0_2_00BA41C0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BA2100 | 0_2_00BA2100 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BC9100 | 0_2_00BC9100 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9D960 | 0_2_00B9D960 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B99160 | 0_2_00B99160 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9B940 | 0_2_00B9B940 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9B2D7 | 0_2_00B9B2D7 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9A230 | 0_2_00B9A230 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00C70271 | 0_2_00C70271 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9CA70 | 0_2_00B9CA70 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9C240 | 0_2_00B9C240 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9DBA0 | 0_2_00B9DBA0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9E380 | 0_2_00B9E380 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BA6B80 | 0_2_00BA6B80 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9CB30 | 0_2_00B9CB30 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B99310 | 0_2_00B99310 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BA8340 | 0_2_00BA8340 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9FCB1 | 0_2_00B9FCB1 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9FCB0 | 0_2_00B9FCB0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BA3CD0 | 0_2_00BA3CD0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B98CC0 | 0_2_00B98CC0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BA2C00 | 0_2_00BA2C00 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B99C40 | 0_2_00B99C40 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9CD90 | 0_2_00B9CD90 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9D5F0 | 0_2_00B9D5F0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BA1529 | 0_2_00BA1529 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B996B0 | 0_2_00B996B0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BC9690 | 0_2_00BC9690 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BA0E86 | 0_2_00BA0E86 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9E6E1 | 0_2_00B9E6E1 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9E6E0 | 0_2_00B9E6E0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9DEC0 | 0_2_00B9DEC0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BB9650 | 0_2_00BB9650 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BB4FA0 | 0_2_00BB4FA0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9FF80 | 0_2_00B9FF80 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9CFE0 | 0_2_00B9CFE0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00BA17E0 | 0_2_00BA17E0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9D7D0 | 0_2_00B9D7D0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9BFD0 | 0_2_00B9BFD0 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | Code function: 0_2_00B9AF30 | 0_2_00B9AF30 |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\main.html.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\main.js.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_0\main.html.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_0\main.js.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\main.html.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\main.js.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.14.0_0\page_embed_script.js.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\craw_background.js.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\craw_window.js.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\css\craw_window.css.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_0\angular.js.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_0\cast_sender.js.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_0\common.js.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_0\feedback.css.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_0\feedback.html.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.14.0_0\eventpage_bin_prod.js.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\html\craw_window.html.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_0\background_script.js.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_0\feedback_script.js.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_0\material_css_min.css.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_0\mirroring_cast_streaming.js.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_0\mirroring_common.js.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_0\mirroring_hangouts.js.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_0\mirroring_webrtc.js.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\DESKTOP\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\DEFAULT\DESKTOP\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\PLAYREADY\INTERNET EXPLORER\DESKTOP\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\PLAYREADY\INTERNET EXPLORER\INPRIVATE\DESKTOP\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\AC\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\AC\INETCACHE\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\AC\TEMP\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\APPDATA\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\LOCALCACHE\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\LOCALSTATE\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\ROAMINGSTATE\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\SETTINGS\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\SYSTEMAPPDATA\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\TEMPSTATE\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\AC\INETCOOKIES\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\PACKAGES\MICROSOFT.DESKTOPAPPINSTALLER_8WEKYB3D8BBWE\AC\INETHISTORY\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCALLOW\ADOBE\ACROBAT\DC\READER\DESKTOPNOTIFICATION\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\APPDATA\LOCALLOW\ADOBE\ACROBAT\DC\READER\DESKTOPNOTIFICATION\NOTIFICATIONSDB\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\BNAGMGSPLO\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\EOWRVPQCCS\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\GAOBCVIQIJ\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\KLIZUSIQEN\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\PALRGUCVEH\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\QCFWYSKMHA\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\QCOILOQIKC\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\QNCYCDFIJJ\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\DOCUMENTS AND SETTINGS\user\DESKTOP\SQSJKEBWDT\readme.txt | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu Places\desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessibility\Desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Maintenance\Desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\StartUp\desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\System Tools\Desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\System Tools\desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office 2016 Tools\desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Desktop.ini.CRYPT | Jump to behavior |
Source: C:\Users\user\Desktop\bkscEXd86b.exe | File created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\desktop.ini.CRYPT | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: explorer.exe, 00000007.00000003.420451429.000000000D19A000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}ProgramData |
Source: explorer.exe, 00000007.00000003.420451429.000000000D19A000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}b1~ |
Source: explorer.exe, 00000007.00000003.310585098.00000000084EA000.00000004.00000001.sdmp | Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\5&1ec51bf7&0&000000 |
Source: explorer.exe, 00000007.00000003.442433219.000000000D02D000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}LargeTile.png |
Source: explorer.exe, 00000007.00000003.395167657.000000000D07F000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}t |
Source: explorer.exe, 00000004.00000000.248428809.000000000F734000.00000004.00000001.sdmp | Binary or memory string: ?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f563\shD- |
Source: explorer.exe, 00000007.00000003.312934031.000000000D00B000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 00000007.00000003.420451429.000000000D19A000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}i |
Source: explorer.exe, 00000007.00000003.395167657.000000000D07F000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}j |
Source: explorer.exe, 00000007.00000003.395167657.000000000D07F000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}k |
Source: explorer.exe, 00000007.00000003.395167657.000000000D07F000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}m |
Source: explorer.exe, 00000007.00000003.395167657.000000000D07F000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}n |
Source: explorer.exe, 00000007.00000003.395167657.000000000D07F000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}o |
Source: explorer.exe, 00000007.00000003.365654527.000000000D235000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B0 |
Source: SearchUI.exe, 00000010.00000002.388454921.000001D3D0165000.00000004.00000001.sdmp | Binary or memory string: Hyper-V RAW |
Source: explorer.exe, 00000004.00000000.244442266.000000000871F000.00000004.00000001.sdmp | Binary or memory string: SCSI\CDROM&VEN_NECVMWAR&PROD_VMWARE_SATA_CD00\5&280B647&0&000000 |
Source: explorer.exe, 00000004.00000000.241740682.0000000008220000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.384082578.000001D3CFC00000.00000002.00000001.sdmp | Binary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported. |
Source: explorer.exe, 00000007.00000003.358711449.000000000D1FF000.00000004.00000001.sdmp | Binary or memory string: e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA2 |
Source: SearchUI.exe, 00000010.00000002.392411511.000001DBD0B40000.00000004.00000001.sdmp | Binary or memory string: visioitunesvmwarelynconenoteneroexceloutlook.ts.psd.ai.dwgx86amd64LDICobjdobjTOPPFEHbinLRA.vssx.vstxPTMPVD.iniMMUS:wux:.resxMFOL.config.bakIFF.etlIBA.bin.objFL.pdbLM.dllotstotetftutdtrtpto |
Source: explorer.exe, 00000007.00000003.358711449.000000000D1FF000.00000004.00000001.sdmp | Binary or memory string: 00100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B |
Source: explorer.exe, 00000007.00000003.324285365.000000000D0A0000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B9> |
Source: explorer.exe, 00000007.00000003.358711449.000000000D1FF000.00000004.00000001.sdmp | Binary or memory string: 11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B, |
Source: explorer.exe, 00000007.00000003.335462967.000000000D09F000.00000004.00000001.sdmp | Binary or memory string: _VMware_SATA |
Source: explorer.exe, 00000007.00000003.361935461.000000000D202000.00000004.00000001.sdmp | Binary or memory string: 6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94fH |
Source: explorer.exe, 00000007.00000003.445284088.000000000D02D000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}Public |
Source: explorer.exe, 00000004.00000000.248428809.000000000F734000.00000004.00000001.sdmp | Binary or memory string: War&Prod_VMware_SATA_CD00#5&K |
Source: explorer.exe, 00000004.00000000.248428809.000000000F734000.00000004.00000001.sdmp | Binary or memory string: 6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 00000007.00000003.358711449.000000000D1FF000.00000004.00000001.sdmp | Binary or memory string: STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_VirB |
Source: explorer.exe, 00000007.00000003.309158574.0000000008741000.00000004.00000001.sdmp | Binary or memory string: VMware SATA CD00 |
Source: explorer.exe, 00000007.00000003.362429381.000000000D030000.00000004.00000001.sdmp | Binary or memory string: 0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f$ |
Source: explorer.exe, 00000007.00000003.361755832.000000000D080000.00000004.00000001.sdmp | Binary or memory string: \?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 00000007.00000003.324285365.000000000D0A0000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B]?2 |
Source: explorer.exe, 00000007.00000003.445284088.000000000D02D000.00000004.00000001.sdmp | Binary or memory string: #CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&{ |
Source: explorer.exe, 00000007.00000003.335462967.000000000D09F000.00000004.00000001.sdmp | Binary or memory string: _VMware_SATAy>V |
Source: explorer.exe, 00000007.00000003.322302501.000000000D0A0000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}Bk1H |
Source: explorer.exe, 00000004.00000000.232968132.00000000055D0000.00000004.00000001.sdmp | Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#5&280b647&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}V*(E |
Source: explorer.exe, 00000004.00000000.244442266.000000000871F000.00000004.00000001.sdmp | Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#5&280b647&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}~ |
Source: explorer.exe, 00000004.00000000.244692343.00000000087D1000.00000004.00000001.sdmp | Binary or memory string: VMware SATA CD00ices |
Source: explorer.exe, 00000007.00000003.446576781.000000000D02F000.00000004.00000001.sdmp | Binary or memory string: c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}png11SPS |
Source: explorer.exe, 00000007.00000003.358711449.000000000D1FF000.00000004.00000001.sdmp | Binary or memory string: War&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B |
Source: explorer.exe, 00000007.00000003.312934031.000000000D00B000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}e |
Source: explorer.exe, 00000007.00000003.312934031.000000000D00B000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}f |
Source: explorer.exe, 00000007.00000003.312934031.000000000D00B000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}g |
Source: explorer.exe, 00000007.00000003.420451429.000000000D19A000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}Extras |
Source: explorer.exe, 00000007.00000003.395167657.000000000D07F000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}h |
Source: explorer.exe, 00000007.00000003.442433219.000000000D02D000.00000004.00000001.sdmp | Binary or memory string: c6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B |
Source: explorer.exe, 00000007.00000003.358711449.000000000D1FF000.00000004.00000001.sdmp | Binary or memory string: e-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B^ |
Source: explorer.exe, 00000007.00000003.328147158.000000000D027000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f$ |
Source: explorer.exe, 00000004.00000000.241740682.0000000008220000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.384082578.000001D3CFC00000.00000002.00000001.sdmp | Binary or memory string: An unknown internal message was received by the Hyper-V Compute Service. |
Source: explorer.exe, 00000007.00000003.328806983.000000000D1ED000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B@ |
Source: explorer.exe, 00000007.00000003.304293863.00000000086A4000.00000004.00000001.sdmp | Binary or memory string: SCSI\CDROM&VEN_NECVMWAR&PROD_VMWARE_SATA_CD00\5&280B647&0&000000!] |
Source: SearchUI.exe, 00000010.00000002.389452659.000001D3D01E4000.00000004.00000001.sdmp | Binary or memory string: Hyper-V RAW(( H |
Source: explorer.exe, 00000007.00000003.328806983.000000000D1ED000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}3 |
Source: explorer.exe, 00000007.00000003.358711449.000000000D1FF000.00000004.00000001.sdmp | Binary or memory string: -94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI& |
Source: explorer.exe, 00000007.00000003.304293863.00000000086A4000.00000004.00000001.sdmp | Binary or memory string: NECVMWarVMware SATA CD001.00 |
Source: explorer.exe, 00000004.00000000.241740682.0000000008220000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.384082578.000001D3CFC00000.00000002.00000001.sdmp | Binary or memory string: A Virtual Machine could not be started because Hyper-V is not installed. |
Source: explorer.exe, 00000007.00000003.420451429.000000000D19A000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}S*4Extras |
Source: explorer.exe, 00000007.00000003.445938262.000000000D0C2000.00000004.00000001.sdmp | Binary or memory string: 0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B |
Source: explorer.exe, 00000007.00000003.322302501.000000000D0A0000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B6? |
Source: explorer.exe, 00000007.00000003.394797344.000000000D138000.00000004.00000001.sdmp | Binary or memory string: 6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}x |
Source: explorer.exe, 00000007.00000003.394797344.000000000D138000.00000004.00000001.sdmp | Binary or memory string: f-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B |
Source: explorer.exe, 00000007.00000003.304293863.00000000086A4000.00000004.00000001.sdmp | Binary or memory string: NECVMWarVMware SATA CD001.00BN |
Source: explorer.exe, 00000007.00000003.358711449.000000000D1FF000.00000004.00000001.sdmp | Binary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}BK |
Source: explorer.exe, 00000007.00000003.361935461.000000000D202000.00000004.00000001.sdmp | Binary or memory string: 1efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000^ |
Source: explorer.exe, 00000007.00000003.420451429.000000000D19A000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B |
Source: explorer.exe, 00000007.00000003.444138100.000000000D02D000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}png11SPS |
Source: explorer.exe, 00000007.00000003.303770661.0000000008707000.00000004.00000001.sdmp | Binary or memory string: k\\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#5&280b647&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 00000007.00000003.361935461.000000000D202000.00000004.00000001.sdmp | Binary or memory string: War&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft& |
Source: explorer.exe, 00000004.00000000.233003562.0000000005603000.00000004.00000001.sdmp | Binary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, |
Source: explorer.exe, 00000007.00000003.395167657.000000000D07F000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}: |
Source: explorer.exe, 00000007.00000003.310457564.00000000087A8000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}FL. |
Source: explorer.exe, 00000007.00000003.395167657.000000000D07F000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}; |
Source: explorer.exe, 00000007.00000003.394797344.000000000D138000.00000004.00000001.sdmp | Binary or memory string: dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B |
Source: explorer.exe, 00000007.00000003.420451429.000000000D19A000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}A} |
Source: explorer.exe, 00000007.00000003.445129469.000000000D09E000.00000004.00000001.sdmp | Binary or memory string: en_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001 |
Source: explorer.exe, 00000007.00000003.420451429.000000000D19A000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}b1 |
Source: explorer.exe, 00000004.00000000.244442266.000000000871F000.00000004.00000001.sdmp | Binary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\5&280b647&0&000000: |
Source: explorer.exe, 00000007.00000003.358711449.000000000D1FF000.00000004.00000001.sdmp | Binary or memory string: 0000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f |
Source: explorer.exe, 00000004.00000000.243875446.0000000008640000.00000004.00000001.sdmp | Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#5&280b647&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 00000007.00000003.361935461.000000000D202000.00000004.00000001.sdmp | Binary or memory string: #CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI& |
Source: explorer.exe, 00000007.00000003.446576781.000000000D02F000.00000004.00000001.sdmp | Binary or memory string: 6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f |
Source: explorer.exe, 00000007.00000003.394797344.000000000D138000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B |
Source: explorer.exe, 00000007.00000003.394797344.000000000D138000.00000004.00000001.sdmp | Binary or memory string: -90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B |
Source: explorer.exe, 00000007.00000003.358711449.000000000D1FF000.00000004.00000001.sdmp | Binary or memory string: 6e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000^ |
Source: explorer.exe, 00000007.00000003.365967246.000000000D22E000.00000004.00000001.sdmp | Binary or memory string: ?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B |
Source: explorer.exe, 00000007.00000003.322302501.000000000D0A0000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B`>? |
Source: explorer.exe, 00000004.00000000.241740682.0000000008220000.00000002.00000001.sdmp, SearchUI.exe, 00000010.00000002.384082578.000001D3CFC00000.00000002.00000001.sdmp | Binary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service. |
Source: explorer.exe, 00000007.00000003.358517403.000000000D080000.00000004.00000001.sdmp | Binary or memory string: War&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Source: SearchUI.exe, 00000010.00000002.365408456.000001D3CABCF000.00000004.00000001.sdmp | Binary or memory string: Hyper-V RAW@ |
Source: explorer.exe, 00000007.00000003.366164128.000000000D02D000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}Roaming |
Source: explorer.exe, 00000007.00000003.307759036.0000000008761000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |