Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0040850C FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00408604 FindFirstFileA,GetLastError, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00405210 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, |
Source: C:\covid21\Corona.exe | Code function: 12_2_00404F24 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_00404EB8 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0043892A _strlen,FindFirstFileA,FindFirstFileA,FindClose,FindFirstFileA,FindClose,_strcat, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00424873 _strlen,_strcat,_strcat,_strrchr,_strlen,_strrchr,FindFirstFileA,FindFirstFileA,GetTickCount,PeekMessageA,GetTickCount,_strlen,_strcat,SetFileAttributesA,FindNextFileA,FindClose,_strcat,FindFirstFileA,_strlen,GetTickCount,GetTickCount,PeekMessageA,GetTickCount,_strlen,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00423AD5 DeleteFileA,FindFirstFileA,_strcat,_strrchr,_strlen,GetTickCount,GetTickCount,PeekMessageA,GetTickCount,_strlen,_strcat,DeleteFileA,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0040A357 _strrchr,_strcat,_strlen,_strcat,FindFirstFileA,FindFirstFileA,FindNextFileA,FindNextFileA,FindClose,_strcat,FindFirstFileA,_strlen,_strlen,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0042C368 FindFirstFileA,GetTickCount,GetTickCount,PeekMessageA,GetTickCount,_strlen,_strcat,MoveFileA,DeleteFileA,MoveFileA,CopyFileA,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00423D09 FindFirstFileA,FindClose, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00423DE4 FindFirstFileA,FindClose,FileTimeToLocalFileTime, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00424DBB _strlen,_strcat,LocalFileTimeToFileTime,GetSystemTimeAsFileTime,_strcat,_strrchr,_strlen,_strrchr,FindFirstFileA,FindFirstFileA,SetFileTime,GetTickCount,PeekMessageA,GetTickCount,_strlen,_strcat,CreateFileA,SetFileTime,CloseHandle,FindNextFileA,FindClose,_strcat,FindFirstFileA,_strlen,GetTickCount,GetTickCount,PeekMessageA,GetTickCount,_strlen,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0042C603 GetFileAttributesA,FindFirstFileA,FindClose, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00439FDC FindFirstFileA,FindClose,GetFileAttributesA, |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_00404714 GetWindowLongA,CallWindowProcA,RemovePropA,RemovePropA,RemovePropA,RevokeDragDrop,SetWindowLongA,NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_00405B1F GetPropA,DefFrameProcA,SetLastError,NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_00407E1A sprintf,GetPropA,HeapFree,HeapFree,HeapFree,RemovePropA,CallWindowProcA,NtdllDefWindowProc_A, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00439164 NtdllDefWindowProc_A,GetCapture, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0045543C NtdllDefWindowProc_A, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0042E49C NtdllDefWindowProc_A, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00449828 GetSubMenu,SaveDC,RestoreDC,73BBB080,SaveDC,RestoreDC,NtdllDefWindowProc_A, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00455BEC IsIconic,SetActiveWindow,IsWindowEnabled,SetWindowPos,NtdllDefWindowProc_A, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00455CB0 IsIconic,SetActiveWindow,IsWindowEnabled,NtdllDefWindowProc_A,SetWindowPos,SetFocus, |
Source: C:\covid21\Corona.exe | Code function: 12_2_00432908 NtdllDefWindowProc_A,GetCapture,KiUserCallbackDispatcher, |
Source: C:\covid21\Corona.exe | Code function: 12_2_0044CEA8 NtdllDefWindowProc_A, |
Source: C:\covid21\Corona.exe | Code function: 12_2_004421FC GetSubMenu,SaveDC,RestoreDC,73BBB080,SaveDC,RestoreDC,NtdllDefWindowProc_A, |
Source: C:\covid21\Corona.exe | Code function: 12_2_0042738C NtdllDefWindowProc_A, |
Source: C:\covid21\Corona.exe | Code function: 12_2_0044D650 IsIconic,SetActiveWindow,IsWindowEnabled,SetWindowPos,NtdllDefWindowProc_A, |
Source: C:\covid21\Corona.exe | Code function: 12_2_0044D700 IsIconic,SetActiveWindow,IsWindowEnabled,NtdllDefWindowProc_A,SetWindowPos,SetFocus, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_0044A410 NtdllDefWindowProc_A, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_00424BF0 NtdllDefWindowProc_A, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_0044ABB8 IsIconic,SetActiveWindow,IsWindowEnabled,SetWindowPos,NtdllDefWindowProc_A, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_0044AC68 IsIconic,SetActiveWindow,IsWindowEnabled,NtdllDefWindowProc_A,SetWindowPos,SetFocus, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_0043F764 GetSubMenu,SaveDC,RestoreDC,73BBB080,SaveDC,RestoreDC,NtdllDefWindowProc_A, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_0042FFB8 NtdllDefWindowProc_A,GetCapture, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe | Code function: 37_2_00428F5C NtdllDefWindowProc_A, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe | Code function: 37_2_0042220A NtdllDefWindowProc_A, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe | Code function: 37_2_00422218 NtdllDefWindowProc_A, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe | Code function: 37_2_0042E808 NtdllDefWindowProc_A, |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_00406960 |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_00406C10 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00458A98 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0044EE08 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00465050 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00449828 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00463A68 |
Source: C:\covid21\Corona.exe | Code function: 12_2_004421FC |
Source: C:\covid21\Corona.exe | Code function: 12_2_004473A0 |
Source: C:\covid21\Corona.exe | Code function: 12_2_0041B3AA |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_00444908 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_0043F764 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_004075C4 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0040DE8C |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00458854 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00424873 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0044207B |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00414803 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_004071FF |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0044522E |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0044B395 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00421466 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00452C20 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0042F514 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00450529 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00449D8E |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0042963D |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0040CF24 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0041B735 |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0044179A |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe | Code function: 37_2_0042E58C |
Source: unknown | Process created: C:\Users\user\Desktop\Covid21 2.0.exe 'C:\Users\user\Desktop\Covid21 2.0.exe' |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Users\user\AppData\Local\Temp\2870.tmp\Covid21.bat' ' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cscript.exe cscript prompt.vbs |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe Reg add 'HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender' /v DisableAntiSpyware /t REG_DWORD /d 1 /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe clwcp c:\covid21\covid.jpg |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop /v NoChangingWallPaper /t REG_DWORD /d 1 /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\x.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /K coronaloop.bat |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 5 /nobreak |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\covid21\Corona.exe c:\covid21\corona.exe |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe inv.exe |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\y.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 5 /nobreak |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe z.exe |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\y.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 5 /nobreak |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\mlt.exe mlt.exe |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\y.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 5 /nobreak |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\y.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\icons.exe icons.exe |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 5 /nobreak |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\icons.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe screenscrew.exe |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\y.vbs' |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Users\user\AppData\Local\Temp\2870.tmp\Covid21.bat' ' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cscript.exe cscript prompt.vbs |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe Reg add 'HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender' /v DisableAntiSpyware /t REG_DWORD /d 1 /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe clwcp c:\covid21\covid.jpg |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop /v NoChangingWallPaper /t REG_DWORD /d 1 /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\x.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /K coronaloop.bat |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 5 /nobreak |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe inv.exe |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\y.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 5 /nobreak |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe z.exe |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\y.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 5 /nobreak |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\mlt.exe mlt.exe |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\y.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 5 /nobreak |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\y.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\icons.exe icons.exe |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 5 /nobreak |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe screenscrew.exe |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\y.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\covid21\Corona.exe c:\covid21\corona.exe |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_00478069 push 004112A1h; ret |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_004780BA push 004112D8h; ret |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_004775D7 push 0041083Ah; ret |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_00477651 push 004108E4h; ret |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_004776FB push 00410A14h; ret |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_0046DAD9 push 00406CF0h; ret |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_0046CB59 push 00405D95h; ret |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_00473B01 push ecx; mov dword ptr [esp], edx |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_0046DB11 push 00407000h; ret |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_0046CD7D push 00405F94h; ret |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_00469DB9 push eax; ret |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_0046CE0D push 00406024h; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00441090 push 0044111Dh; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0040D62C push 0040D69Bh; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00405D44 push 00405D95h; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00442080 push ecx; mov dword ptr [esp], edx |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_004162B8 push ecx; mov dword ptr [esp], edx |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0044237C push 004423A8h; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0044A328 push 0044A393h; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00428488 push 004284CAh; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0042E5E8 push 0042E614h; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0042E63C push 0042E668h; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_004107C2 push 0041083Ah; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_004107C4 push 0041083Ah; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0042C844 push 0042C870h; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0042C87C push 0042C8A8h; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0042C80C push 0042C838h; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0041083C push 004108E4h; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_004108E6 push 00410A14h; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0042C8EC push 0042C918h; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0042C8B4 push 0042C8E0h; ret |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_004554C4 PostMessageA,PostMessageA,SendMessageA,GetProcAddress,GetLastError,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00452098 SendMessageA,ShowWindow,ShowWindow,CallWindowProcA,SendMessageA,ShowWindow,SetWindowPos,GetActiveWindow,IsIconic,SetWindowPos,SetActiveWindow,ShowWindow,ShowWindow, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0043AB48 IsIconic,GetCapture, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0043B440 IsIconic,SetWindowPos,GetWindowPlacement,SetWindowPlacement, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00425458 IsIconic,GetWindowPlacement,GetWindowRect, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00455BEC IsIconic,SetActiveWindow,IsWindowEnabled,SetWindowPos,NtdllDefWindowProc_A, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00455CB0 IsIconic,SetActiveWindow,IsWindowEnabled,NtdllDefWindowProc_A,SetWindowPos,SetFocus, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0043BD64 IsIconic,GetWindowPlacement,GetWindowRect,GetWindowLongA,GetWindowLongA,ScreenToClient,ScreenToClient, |
Source: C:\covid21\Corona.exe | Code function: 12_2_0044CF30 PostMessageA,PostMessageA,SendMessageA,GetProcAddress,GetLastError,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, |
Source: C:\covid21\Corona.exe | Code function: 12_2_00449F58 SendMessageA,ShowWindow,ShowWindow,CallWindowProcA,SendMessageA,ShowWindow,SetWindowPos,GetActiveWindow,IsIconic,SetWindowPos,SetActiveWindow,ShowWindow, |
Source: C:\covid21\Corona.exe | Code function: 12_2_0043402C IsIconic,GetCapture, |
Source: C:\covid21\Corona.exe | Code function: 12_2_004348E0 IsIconic,SetWindowPos,GetWindowPlacement,SetWindowPlacement, |
Source: C:\covid21\Corona.exe | Code function: 12_2_00435160 IsIconic,GetWindowPlacement,GetWindowRect,GetWindowLongA,GetWindowLongA,ScreenToClient,ScreenToClient, |
Source: C:\covid21\Corona.exe | Code function: 12_2_0044D650 IsIconic,SetActiveWindow,IsWindowEnabled,SetWindowPos,NtdllDefWindowProc_A, |
Source: C:\covid21\Corona.exe | Code function: 12_2_0044D700 IsIconic,SetActiveWindow,IsWindowEnabled,NtdllDefWindowProc_A,SetWindowPos,SetFocus, |
Source: C:\covid21\Corona.exe | Code function: 12_2_0042397C MonitorFromWindow,MonitorFromWindow,IsIconic,GetWindowPlacement,GetWindowRect, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_0044A498 PostMessageA,PostMessageA,SendMessageA,GetProcAddress,GetLastError,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_00432810 IsIconic,GetWindowPlacement,GetWindowRect,GetWindowLongA,GetWindowLongA,ScreenToClient,ScreenToClient, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_0044ABB8 IsIconic,SetActiveWindow,IsWindowEnabled,SetWindowPos,NtdllDefWindowProc_A, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_0044AC68 IsIconic,SetActiveWindow,IsWindowEnabled,NtdllDefWindowProc_A,SetWindowPos,SetFocus, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_004474C0 SendMessageA,ShowWindow,ShowWindow,CallWindowProcA,SendMessageA,ShowWindow,SetWindowPos,GetActiveWindow,IsIconic,SetWindowPos,SetActiveWindow,ShowWindow, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_004316DC IsIconic,GetCapture, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_00421D38 IsIconic,GetWindowPlacement,GetWindowRect, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_00431F90 IsIconic,SetWindowPos,GetWindowPlacement,SetWindowPlacement, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0043A0D6 GetForegroundWindow,IsWindowVisible,GetWindowThreadProcessId,IsZoomed,IsIconic,GetWindowLongA,GetModuleHandleA,GetProcAddress, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_004360F9 SetWindowTextA,IsZoomed,IsIconic,ShowWindow,IsIconic,GetWindowLongA,GetWindowLongA,GetWindowRect,MapWindowPoints,GetWindowLongA,GetWindowRect,GetWindowLongA,GetWindowRect,GetClientRect,IsWindowVisible,GetWindowLongA,GetMenu,GetWindowLongA,AdjustWindowRectEx,SystemParametersInfoA,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetForegroundWindow,GetFocus,UpdateWindow,SetFocus, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_004360F9 SetWindowTextA,IsZoomed,IsIconic,ShowWindow,IsIconic,GetWindowLongA,GetWindowLongA,GetWindowRect,MapWindowPoints,GetWindowLongA,GetWindowRect,GetWindowLongA,GetWindowRect,GetClientRect,IsWindowVisible,GetWindowLongA,GetMenu,GetWindowLongA,AdjustWindowRectEx,SystemParametersInfoA,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetForegroundWindow,GetFocus,UpdateWindow,SetFocus, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0043536F GetWindowLongA,GetWindowLongA,GetWindowLongA,_strlen,SetWindowPos,EnableWindow,IsWindowVisible,IsIconic,SetWindowLongA,SetWindowLongA,SetWindowLongA,SetWindowPos,ShowWindow,ShowWindow,ShowWindow, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0043C3F2 GetWindowThreadProcessId,GetWindowThreadProcessId,GetForegroundWindow,FindWindowA,IsIconic,ShowWindow,AttachThreadInput,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,BringWindowToTop, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00439C0E GetAsyncKeyState,GetForegroundWindow,IsIconic,GetWindowRect, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0044C66D SendMessageA,SendMessageA,SendMessageA,IsWindowVisible,ShowWindow,ShowWindow,IsIconic,ShowWindow,GetForegroundWindow,SetForegroundWindow,SendMessageA, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00431E81 SendMessageA,GetWindowLongA,IsWindowVisible,IsIconic,GetFocus,GetWindowRect,SendMessageA,GetWindowLongA,ShowWindow,EnableWindow,GetWindowRect,PtInRect,PtInRect,PtInRect,SetFocus,SendMessageA,SetFocus,MapWindowPoints,InvalidateRect, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0042CF3C GetDC,SelectObject,GetTextMetricsA,GetSystemMetrics,GetDC,SelectObject,GetTextMetricsA,GetSystemMetrics,GetDC,SelectObject,GetTextMetricsA,GetSystemMetrics,DrawTextA,GetSystemMetrics,GetSystemMetrics,GetDC,SelectObject,GetTextMetricsA,GetSystemMetrics,IsWindowVisible,IsIconic,SendMessageA,GetWindowLongA,SendMessageA,CreateWindowExA,SetWindowLongA,SendMessageA,CreateWindowExA,GetWindowLongA,SendMessageA,SendMessageA,CreateWindowExA,CreateWindowExA,CreateWindowExA,SendMessageA,SendMessageA,CreateWindowExA,SendMessageA,SendMessageA,SendMessageA,GetSystemMetrics,GetSystemMetrics,MoveWindow,SendMessageA,SelectObject,ReleaseDC,SendMessageA,SendMessageA,GetClientRect,SetWindowLongA,SendMessageA,SetWindowLongA,MoveWindow,GetWindowRect,SendMessageA,SetWindowPos,GetWindowRect,MapWindowPoints,InvalidateRect,SetWindowPos,SetWindowPos, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe | Code function: 37_2_00428FE4 PostMessageA,PostMessageA,SendMessageA,LoadLibraryA,GetProcAddress,GetLastError,IsWindowEnabled,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe | Code function: 37_2_0041F210 IsIconic,GetWindowPlacement,GetWindowRect,GetWindowLongA,GetWindowLongA,ScreenToClient,ScreenToClient, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe | Code function: 37_2_0041E320 IsIconic,GetCapture, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe | Code function: 37_2_0041EABA IsIconic,SetWindowPos, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe | Code function: 37_2_0041EABC IsIconic,SetWindowPos,GetWindowPlacement,SetWindowPlacement, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe | Code function: 37_2_004275F8 SendMessageA,ShowWindow,ShowWindow,CallWindowProcA,SendMessageA,ShowWindow,SetWindowPos,GetActiveWindow,IsIconic,SetWindowPos,SetActiveWindow,ShowWindow, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe | Code function: 37_2_00429678 IsIconic,SetActiveWindow, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe | Code function: 37_2_004296C0 IsIconic,SetActiveWindow,SetFocus, |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\cscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\cscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_0040850C FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00408604 FindFirstFileA,GetLastError, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: 6_2_00405210 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, |
Source: C:\covid21\Corona.exe | Code function: 12_2_00404F24 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: 13_2_00404EB8 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0043892A _strlen,FindFirstFileA,FindFirstFileA,FindClose,FindFirstFileA,FindClose,_strcat, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00424873 _strlen,_strcat,_strcat,_strrchr,_strlen,_strrchr,FindFirstFileA,FindFirstFileA,GetTickCount,PeekMessageA,GetTickCount,_strlen,_strcat,SetFileAttributesA,FindNextFileA,FindClose,_strcat,FindFirstFileA,_strlen,GetTickCount,GetTickCount,PeekMessageA,GetTickCount,_strlen,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00423AD5 DeleteFileA,FindFirstFileA,_strcat,_strrchr,_strlen,GetTickCount,GetTickCount,PeekMessageA,GetTickCount,_strlen,_strcat,DeleteFileA,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0040A357 _strrchr,_strcat,_strlen,_strcat,FindFirstFileA,FindFirstFileA,FindNextFileA,FindNextFileA,FindClose,_strcat,FindFirstFileA,_strlen,_strlen,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0042C368 FindFirstFileA,GetTickCount,GetTickCount,PeekMessageA,GetTickCount,_strlen,_strcat,MoveFileA,DeleteFileA,MoveFileA,CopyFileA,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00423D09 FindFirstFileA,FindClose, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00423DE4 FindFirstFileA,FindClose,FileTimeToLocalFileTime, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00424DBB _strlen,_strcat,LocalFileTimeToFileTime,GetSystemTimeAsFileTime,_strcat,_strrchr,_strlen,_strrchr,FindFirstFileA,FindFirstFileA,SetFileTime,GetTickCount,PeekMessageA,GetTickCount,_strlen,_strcat,CreateFileA,SetFileTime,CloseHandle,FindNextFileA,FindClose,_strcat,FindFirstFileA,_strlen,GetTickCount,GetTickCount,PeekMessageA,GetTickCount,_strlen,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_0042C603 GetFileAttributesA,FindFirstFileA,FindClose, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: 18_2_00439FDC FindFirstFileA,FindClose,GetFileAttributesA, |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_00403B70 SetUnhandledExceptionFilter,SetUnhandledExceptionFilter,SetUnhandledExceptionFilter, |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Code function: 0_2_00403CC0 SetUnhandledExceptionFilter, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\mlt.exe | Code function: 23_2_004011B0 Sleep,Sleep,SetUnhandledExceptionFilter,GetStartupInfoA, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\mlt.exe | Code function: 23_2_004082CC SetUnhandledExceptionFilter, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\mlt.exe | Code function: 23_2_00402C51 SetUnhandledExceptionFilter, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\mlt.exe | Code function: 23_2_00402290 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\icons.exe | Code function: 28_2_00401179 Sleep,Sleep,SetUnhandledExceptionFilter,_acmdln,malloc,strlen,malloc,memcpy,__initenv,_cexit,_amsg_exit,_initterm,GetStartupInfoA,_initterm,exit, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\icons.exe | Code function: 28_2_0040201C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\icons.exe | Code function: 28_2_00402020 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, |
Source: C:\Users\user\Desktop\Covid21 2.0.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Users\user\AppData\Local\Temp\2870.tmp\Covid21.bat' ' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cscript.exe cscript prompt.vbs |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe Reg add 'HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender' /v DisableAntiSpyware /t REG_DWORD /d 1 /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe clwcp c:\covid21\covid.jpg |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop /v NoChangingWallPaper /t REG_DWORD /d 1 /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\x.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /K coronaloop.bat |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 5 /nobreak |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe inv.exe |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\y.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 5 /nobreak |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe z.exe |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\y.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 5 /nobreak |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\mlt.exe mlt.exe |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\y.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 5 /nobreak |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\y.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\icons.exe icons.exe |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 5 /nobreak |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe screenscrew.exe |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\user\AppData\Local\Temp\2870.tmp\y.vbs' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\covid21\Corona.exe c:\covid21\corona.exe |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\CLWCP.exe | Code function: GetLocaleInfoA, |
Source: C:\covid21\Corona.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, |
Source: C:\covid21\Corona.exe | Code function: GetLocaleInfoA, |
Source: C:\covid21\Corona.exe | Code function: GetLocaleInfoA, |
Source: C:\covid21\Corona.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, |
Source: C:\covid21\Corona.exe | Code function: GetLocaleInfoA, |
Source: C:\covid21\Corona.exe | Code function: GetLocaleInfoA, |
Source: C:\covid21\Corona.exe | Code function: GetLocaleInfoA,GetACP, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\inv.exe | Code function: GetLocaleInfoA,GetACP, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\z.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpy,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\AppData\Local\Temp\2870.tmp\screenscrew.exe | Code function: GetLocaleInfoA, |