Source: | Binary string: slui.pdb source: slui.exe, 0000001C.00000000.587339760.00007FF6A3F4C000.00000002.00000001.01000000.00000012.sdmp, slui.exe, 0000001C.00000002.616193744.00007FF6A3F4C000.00000002.00000001.01000000.00000012.sdmp |
Source: | Binary string: DmNotificationBroker.pdb source: DmNotificationBroker.exe, 00000026.00000000.760434884.00007FF7BFEF5000.00000002.00000001.01000000.0000001D.sdmp, DmNotificationBroker.exe, 00000026.00000002.790979828.00007FF7BFEF5000.00000002.00000001.01000000.0000001D.sdmp |
Source: | Binary string: rdpinput.pdbGCTL source: rdpinput.exe, 00000014.00000000.489595034.00007FF7BADC3000.00000002.00000001.01000000.0000000B.sdmp, rdpinput.exe, 00000014.00000002.512462840.00007FF7BADC3000.00000002.00000001.01000000.0000000B.sdmp, rdpinput.exe, 0000001E.00000000.622861932.00007FF64DBA3000.00000002.00000001.01000000.00000014.sdmp, rdpinput.exe, 0000001E.00000002.646379506.00007FF64DBA3000.00000002.00000001.01000000.00000014.sdmp |
Source: | Binary string: SndVol.pdbGCTL source: SndVol.exe, 00000016.00000000.518686092.00007FF6C1BD2000.00000002.00000001.01000000.0000000D.sdmp, SndVol.exe, 00000016.00000002.541746435.00007FF6C1BD2000.00000002.00000001.01000000.0000000D.sdmp |
Source: | Binary string: Utilman.pdb source: Utilman.exe, 00000022.00000000.683097194.00007FF7C58C0000.00000002.00000001.01000000.00000018.sdmp, Utilman.exe, 00000022.00000002.705894496.00007FF7C58C0000.00000002.00000001.01000000.00000018.sdmp |
Source: | Binary string: ProximityUxHost.pdbGCTL source: ProximityUxHost.exe, 00000028.00000002.836601819.00007FF777332000.00000002.00000001.01000000.0000001F.sdmp, ProximityUxHost.exe, 00000028.00000000.805041652.00007FF777332000.00000002.00000001.01000000.0000001F.sdmp |
Source: | Binary string: PrintFilterPipelineSvc.pdbGCTL source: printfilterpipelinesvc.exe, 00000020.00000000.654903742.00007FF6B41A7000.00000002.00000001.01000000.00000016.sdmp, printfilterpipelinesvc.exe, 00000020.00000002.677939240.00007FF6B41A7000.00000002.00000001.01000000.00000016.sdmp |
Source: | Binary string: DmNotificationBroker.pdbGCTL source: DmNotificationBroker.exe, 00000026.00000000.760434884.00007FF7BFEF5000.00000002.00000001.01000000.0000001D.sdmp, DmNotificationBroker.exe, 00000026.00000002.790979828.00007FF7BFEF5000.00000002.00000001.01000000.0000001D.sdmp |
Source: | Binary string: phoneactivate.pdb source: phoneactivate.exe, 00000024.00000000.718318485.00007FF7F2EC0000.00000002.00000001.01000000.0000001A.sdmp, phoneactivate.exe, 00000024.00000002.746413133.00007FF7F2EC0000.00000002.00000001.01000000.0000001A.sdmp |
Source: | Binary string: SnippingTool.pdb source: SnippingTool.exe, 00000019.00000002.579595026.00007FF70C420000.00000002.00000001.01000000.0000000F.sdmp, SnippingTool.exe, 00000019.00000000.550318199.00007FF70C420000.00000002.00000001.01000000.0000000F.sdmp |
Source: | Binary string: SnippingTool.pdbGCTL source: SnippingTool.exe, 00000019.00000002.579595026.00007FF70C420000.00000002.00000001.01000000.0000000F.sdmp, SnippingTool.exe, 00000019.00000000.550318199.00007FF70C420000.00000002.00000001.01000000.0000000F.sdmp |
Source: | Binary string: PrintFilterPipelineSvc.pdb source: printfilterpipelinesvc.exe, 00000020.00000000.654903742.00007FF6B41A7000.00000002.00000001.01000000.00000016.sdmp, printfilterpipelinesvc.exe, 00000020.00000002.677939240.00007FF6B41A7000.00000002.00000001.01000000.00000016.sdmp |
Source: | Binary string: FileHistory.pdbGCTL source: FileHistory.exe, 00000012.00000000.478980793.00007FF6D0A39000.00000002.00000001.01000000.00000007.sdmp, FileHistory.exe, 00000012.00000002.484212875.00007FF6D0A39000.00000002.00000001.01000000.00000007.sdmp |
Source: | Binary string: rdpinput.pdb source: rdpinput.exe, 00000014.00000000.489595034.00007FF7BADC3000.00000002.00000001.01000000.0000000B.sdmp, rdpinput.exe, 00000014.00000002.512462840.00007FF7BADC3000.00000002.00000001.01000000.0000000B.sdmp, rdpinput.exe, 0000001E.00000000.622861932.00007FF64DBA3000.00000002.00000001.01000000.00000014.sdmp, rdpinput.exe, 0000001E.00000002.646379506.00007FF64DBA3000.00000002.00000001.01000000.00000014.sdmp |
Source: | Binary string: Utilman.pdbGCTL source: Utilman.exe, 00000022.00000000.683097194.00007FF7C58C0000.00000002.00000001.01000000.00000018.sdmp, Utilman.exe, 00000022.00000002.705894496.00007FF7C58C0000.00000002.00000001.01000000.00000018.sdmp |
Source: | Binary string: phoneactivate.pdbGCTL source: phoneactivate.exe, 00000024.00000000.718318485.00007FF7F2EC0000.00000002.00000001.01000000.0000001A.sdmp, phoneactivate.exe, 00000024.00000002.746413133.00007FF7F2EC0000.00000002.00000001.01000000.0000001A.sdmp |
Source: | Binary string: slui.pdbUGP source: slui.exe, 0000001C.00000000.587339760.00007FF6A3F4C000.00000002.00000001.01000000.00000012.sdmp, slui.exe, 0000001C.00000002.616193744.00007FF6A3F4C000.00000002.00000001.01000000.00000012.sdmp |
Source: | Binary string: SndVol.pdb source: SndVol.exe, 00000016.00000000.518686092.00007FF6C1BD2000.00000002.00000001.01000000.0000000D.sdmp, SndVol.exe, 00000016.00000002.541746435.00007FF6C1BD2000.00000002.00000001.01000000.0000000D.sdmp |
Source: | Binary string: ProximityUxHost.pdb source: ProximityUxHost.exe, 00000028.00000002.836601819.00007FF777332000.00000002.00000001.01000000.0000001F.sdmp, ProximityUxHost.exe, 00000028.00000000.805041652.00007FF777332000.00000002.00000001.01000000.0000001F.sdmp |
Source: | Binary string: FileHistory.pdb source: FileHistory.exe, 00000012.00000000.478980793.00007FF6D0A39000.00000002.00000001.01000000.00000007.sdmp, FileHistory.exe, 00000012.00000002.484212875.00007FF6D0A39000.00000002.00000001.01000000.00000007.sdmp |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA623150 | 0_2_00007FF8BA623150 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA6059F0 | 0_2_00007FF8BA6059F0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA60AA70 | 0_2_00007FF8BA60AA70 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA61CA50 | 0_2_00007FF8BA61CA50 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA61A2C0 | 0_2_00007FF8BA61A2C0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA6197D0 | 0_2_00007FF8BA6197D0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA605020 | 0_2_00007FF8BA605020 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5F7880 | 0_2_00007FF8BA5F7880 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA63D520 | 0_2_00007FF8BA63D520 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA62DDC0 | 0_2_00007FF8BA62DDC0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA637650 | 0_2_00007FF8BA637650 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA604360 | 0_2_00007FF8BA604360 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5F3340 | 0_2_00007FF8BA5F3340 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5E8340 | 0_2_00007FF8BA5E8340 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA635B50 | 0_2_00007FF8BA635B50 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5D5350 | 0_2_00007FF8BA5D5350 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5DBB20 | 0_2_00007FF8BA5DBB20 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA601B30 | 0_2_00007FF8BA601B30 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA600300 | 0_2_00007FF8BA600300 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5FA310 | 0_2_00007FF8BA5FA310 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5E23F0 | 0_2_00007FF8BA5E23F0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA624BC0 | 0_2_00007FF8BA624BC0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA634390 | 0_2_00007FF8BA634390 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5D5C20 | 0_2_00007FF8BA5D5C20 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5E5420 | 0_2_00007FF8BA5E5420 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA639410 | 0_2_00007FF8BA639410 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5E7410 | 0_2_00007FF8BA5E7410 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA63E400 | 0_2_00007FF8BA63E400 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA603CF0 | 0_2_00007FF8BA603CF0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5E3CD0 | 0_2_00007FF8BA5E3CD0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA605CD0 | 0_2_00007FF8BA605CD0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA63E4AD | 0_2_00007FF8BA63E4AD |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA63E4B6 | 0_2_00007FF8BA63E4B6 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA63E49D | 0_2_00007FF8BA63E49D |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA632CA0 | 0_2_00007FF8BA632CA0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA63E4A6 | 0_2_00007FF8BA63E4A6 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA63E48B | 0_2_00007FF8BA63E48B |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5FAC80 | 0_2_00007FF8BA5FAC80 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA63A490 | 0_2_00007FF8BA63A490 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA63E494 | 0_2_00007FF8BA63E494 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA63B960 | 0_2_00007FF8BA63B960 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5F4140 | 0_2_00007FF8BA5F4140 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA636950 | 0_2_00007FF8BA636950 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA606130 | 0_2_00007FF8BA606130 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5DB100 | 0_2_00007FF8BA5DB100 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5EE110 | 0_2_00007FF8BA5EE110 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5F3910 | 0_2_00007FF8BA5F3910 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA6091F0 | 0_2_00007FF8BA6091F0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA6089F0 | 0_2_00007FF8BA6089F0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5FF1F0 | 0_2_00007FF8BA5FF1F0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5F69C0 | 0_2_00007FF8BA5F69C0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA6021D0 | 0_2_00007FF8BA6021D0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5FE9A0 | 0_2_00007FF8BA5FE9A0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5EE9B0 | 0_2_00007FF8BA5EE9B0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5F11B0 | 0_2_00007FF8BA5F11B0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5D2980 | 0_2_00007FF8BA5D2980 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA609990 | 0_2_00007FF8BA609990 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA63B260 | 0_2_00007FF8BA63B260 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5D7A40 | 0_2_00007FF8BA5D7A40 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA60B250 | 0_2_00007FF8BA60B250 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5F82E0 | 0_2_00007FF8BA5F82E0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA637AF0 | 0_2_00007FF8BA637AF0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA60BAE0 | 0_2_00007FF8BA60BAE0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA632AE0 | 0_2_00007FF8BA632AE0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5F92C0 | 0_2_00007FF8BA5F92C0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA62F2C0 | 0_2_00007FF8BA62F2C0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5FDAA0 | 0_2_00007FF8BA5FDAA0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA6382A0 | 0_2_00007FF8BA6382A0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA63AAA0 | 0_2_00007FF8BA63AAA0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA630770 | 0_2_00007FF8BA630770 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5EE770 | 0_2_00007FF8BA5EE770 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA635760 | 0_2_00007FF8BA635760 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5F2F50 | 0_2_00007FF8BA5F2F50 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA630F30 | 0_2_00007FF8BA630F30 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5F872B | 0_2_00007FF8BA5F872B |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5F6FE0 | 0_2_00007FF8BA5F6FE0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA644FF0 | 0_2_00007FF8BA644FF0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5E8FC0 | 0_2_00007FF8BA5E8FC0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5EA7D0 | 0_2_00007FF8BA5EA7D0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5FE7B0 | 0_2_00007FF8BA5FE7B0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA64B7A0 | 0_2_00007FF8BA64B7A0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5D6790 | 0_2_00007FF8BA5D6790 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA63C780 | 0_2_00007FF8BA63C780 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA64EF80 | 0_2_00007FF8BA64EF80 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA60F870 | 0_2_00007FF8BA60F870 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA61F870 | 0_2_00007FF8BA61F870 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5F5050 | 0_2_00007FF8BA5F5050 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA625840 | 0_2_00007FF8BA625840 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA600020 | 0_2_00007FF8BA600020 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5FC030 | 0_2_00007FF8BA5FC030 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5F4800 | 0_2_00007FF8BA5F4800 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5D1010 | 0_2_00007FF8BA5D1010 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5D18D0 | 0_2_00007FF8BA5D18D0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5E08B0 | 0_2_00007FF8BA5E08B0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5ED890 | 0_2_00007FF8BA5ED890 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FF8BA5E9D70 | 0_2_00007FF8BA5E9D70 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B5CD0 | 18_2_00007FF8CA9B5CD0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9CA2C0 | 18_2_00007FF8CA9CA2C0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9BAA70 | 18_2_00007FF8CA9BAA70 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9CCA50 | 18_2_00007FF8CA9CCA50 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B5020 | 18_2_00007FF8CA9B5020 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9DDDC0 | 18_2_00007FF8CA9DDDC0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9E4390 | 18_2_00007FF8CA9E4390 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9923F0 | 18_2_00007FF8CA9923F0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9D4BC0 | 18_2_00007FF8CA9D4BC0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA98BB20 | 18_2_00007FF8CA98BB20 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B1B30 | 18_2_00007FF8CA9B1B30 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B0300 | 18_2_00007FF8CA9B0300 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9AA310 | 18_2_00007FF8CA9AA310 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B4360 | 18_2_00007FF8CA9B4360 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9A3340 | 18_2_00007FF8CA9A3340 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA998340 | 18_2_00007FF8CA998340 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9E5B50 | 18_2_00007FF8CA9E5B50 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA985350 | 18_2_00007FF8CA985350 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9E2CA0 | 18_2_00007FF8CA9E2CA0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9AAC80 | 18_2_00007FF8CA9AAC80 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B3CF0 | 18_2_00007FF8CA9B3CF0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA993CD0 | 18_2_00007FF8CA993CD0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA995420 | 18_2_00007FF8CA995420 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA985C20 | 18_2_00007FF8CA985C20 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9EE400 | 18_2_00007FF8CA9EE400 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA997410 | 18_2_00007FF8CA997410 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9E9410 | 18_2_00007FF8CA9E9410 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9AE9A0 | 18_2_00007FF8CA9AE9A0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA99E9B0 | 18_2_00007FF8CA99E9B0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9A11B0 | 18_2_00007FF8CA9A11B0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA982980 | 18_2_00007FF8CA982980 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B9990 | 18_2_00007FF8CA9B9990 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B59F0 | 18_2_00007FF8CA9B59F0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9AF1F0 | 18_2_00007FF8CA9AF1F0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B91F0 | 18_2_00007FF8CA9B91F0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B89F0 | 18_2_00007FF8CA9B89F0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9A69C0 | 18_2_00007FF8CA9A69C0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B21D0 | 18_2_00007FF8CA9B21D0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B6130 | 18_2_00007FF8CA9B6130 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA98B100 | 18_2_00007FF8CA98B100 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA99E110 | 18_2_00007FF8CA99E110 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9A3910 | 18_2_00007FF8CA9A3910 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9EB960 | 18_2_00007FF8CA9EB960 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9A4140 | 18_2_00007FF8CA9A4140 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9D3150 | 18_2_00007FF8CA9D3150 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9E6950 | 18_2_00007FF8CA9E6950 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9ADAA0 | 18_2_00007FF8CA9ADAA0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9E82A0 | 18_2_00007FF8CA9E82A0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9EAAA0 | 18_2_00007FF8CA9EAAA0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9A82E0 | 18_2_00007FF8CA9A82E0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9BBAE0 | 18_2_00007FF8CA9BBAE0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9E2AE0 | 18_2_00007FF8CA9E2AE0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9A92C0 | 18_2_00007FF8CA9A92C0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9DF2C0 | 18_2_00007FF8CA9DF2C0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9EB260 | 18_2_00007FF8CA9EB260 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA987A40 | 18_2_00007FF8CA987A40 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9BB250 | 18_2_00007FF8CA9BB250 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9FB7A0 | 18_2_00007FF8CA9FB7A0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9AE7B0 | 18_2_00007FF8CA9AE7B0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9FEF80 | 18_2_00007FF8CA9FEF80 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA986790 | 18_2_00007FF8CA986790 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9A6FE0 | 18_2_00007FF8CA9A6FE0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9F4FF0 | 18_2_00007FF8CA9F4FF0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA998FC0 | 18_2_00007FF8CA998FC0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA99A7D0 | 18_2_00007FF8CA99A7D0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9C97D0 | 18_2_00007FF8CA9C97D0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9E0F30 | 18_2_00007FF8CA9E0F30 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9A872B | 18_2_00007FF8CA9A872B |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9E5760 | 18_2_00007FF8CA9E5760 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA99E770 | 18_2_00007FF8CA99E770 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9E0770 | 18_2_00007FF8CA9E0770 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9A2F50 | 18_2_00007FF8CA9A2F50 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9908B0 | 18_2_00007FF8CA9908B0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9A7880 | 18_2_00007FF8CA9A7880 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA99D890 | 18_2_00007FF8CA99D890 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9818D0 | 18_2_00007FF8CA9818D0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B0020 | 18_2_00007FF8CA9B0020 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9AC030 | 18_2_00007FF8CA9AC030 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9A4800 | 18_2_00007FF8CA9A4800 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA981010 | 18_2_00007FF8CA981010 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9BF870 | 18_2_00007FF8CA9BF870 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9D5840 | 18_2_00007FF8CA9D5840 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9A5050 | 18_2_00007FF8CA9A5050 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA98C5A0 | 18_2_00007FF8CA98C5A0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9965E0 | 18_2_00007FF8CA9965E0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9995C0 | 18_2_00007FF8CA9995C0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B25C0 | 18_2_00007FF8CA9B25C0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9ED520 | 18_2_00007FF8CA9ED520 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B1D30 | 18_2_00007FF8CA9B1D30 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B0D10 | 18_2_00007FF8CA9B0D10 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA999D70 | 18_2_00007FF8CA999D70 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9A3D50 | 18_2_00007FF8CA9A3D50 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9AD550 | 18_2_00007FF8CA9AD550 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B06A0 | 18_2_00007FF8CA9B06A0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9AF6B0 | 18_2_00007FF8CA9AF6B0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA987E80 | 18_2_00007FF8CA987E80 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA986E90 | 18_2_00007FF8CA986E90 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9E7EC0 | 18_2_00007FF8CA9E7EC0 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA98DE20 | 18_2_00007FF8CA98DE20 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA981620 | 18_2_00007FF8CA981620 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9A3610 | 18_2_00007FF8CA9A3610 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9B2E10 | 18_2_00007FF8CA9B2E10 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA998670 | 18_2_00007FF8CA998670 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9D0650 | 18_2_00007FF8CA9D0650 |
Source: C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Code function: 18_2_00007FF8CA9E7650 | 18_2_00007FF8CA9E7650 |
Source: C:\Users\user\AppData\Local\Kyz7D\rdpinput.exe | Code function: 20_2_00007FF7BADA3BE0 | 20_2_00007FF7BADA3BE0 |
Source: C:\Users\user\AppData\Local\Kyz7D\rdpinput.exe | Code function: 20_2_00007FF7BADA2578 | 20_2_00007FF7BADA2578 |
Source: C:\Users\user\AppData\Local\Kyz7D\rdpinput.exe | Code function: 20_2_00007FF7BADAFD48 | 20_2_00007FF7BADAFD48 |
Source: C:\Users\user\AppData\Local\bTcR2e\SndVol.exe | Code function: 22_2_00007FF6C1BB8310 | 22_2_00007FF6C1BB8310 |
Source: C:\Users\user\AppData\Local\bTcR2e\SndVol.exe | Code function: 22_2_00007FF6C1BC4F10 | 22_2_00007FF6C1BC4F10 |
Source: C:\Users\user\AppData\Local\bTcR2e\SndVol.exe | Code function: 22_2_00007FF6C1BC3718 | 22_2_00007FF6C1BC3718 |
Source: C:\Users\user\AppData\Local\bTcR2e\SndVol.exe | Code function: 22_2_00007FF6C1BB6218 | 22_2_00007FF6C1BB6218 |
Source: C:\Users\user\AppData\Local\bTcR2e\SndVol.exe | Code function: 22_2_00007FF6C1BBA5C8 | 22_2_00007FF6C1BBA5C8 |
Source: C:\Users\user\AppData\Local\bTcR2e\SndVol.exe | Code function: 22_2_00007FF6C1BBA1A0 | 22_2_00007FF6C1BBA1A0 |
Source: C:\Users\user\AppData\Local\bTcR2e\SndVol.exe | Code function: 22_2_00007FF6C1BB3514 | 22_2_00007FF6C1BB3514 |
Source: C:\Users\user\AppData\Local\bTcR2e\SndVol.exe | Code function: 22_2_00007FF6C1BCC4D0 | 22_2_00007FF6C1BCC4D0 |
Source: C:\Users\user\AppData\Local\bTcR2e\SndVol.exe | Code function: 22_2_00007FF6C1BB44E8 | 22_2_00007FF6C1BB44E8 |
Source: C:\Users\user\AppData\Local\bTcR2e\SndVol.exe | Code function: 22_2_00007FF6C1BB3080 | 22_2_00007FF6C1BB3080 |
Source: C:\Users\user\AppData\Local\bTcR2e\SndVol.exe | Code function: 22_2_00007FF6C1BCB088 | 22_2_00007FF6C1BCB088 |
Source: C:\Users\user\AppData\Local\bTcR2e\SndVol.exe | Code function: 22_2_00007FF6C1BC0CA8 | 22_2_00007FF6C1BC0CA8 |
Source: C:\Users\user\AppData\Local\bTcR2e\SndVol.exe | Code function: 22_2_00007FF6C1BC2BD8 | 22_2_00007FF6C1BC2BD8 |
Source: C:\Users\user\AppData\Local\bTcR2e\SndVol.exe | Code function: 22_2_00007FF6C1BC03A0 | 22_2_00007FF6C1BC03A0 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C3F9978 | 25_2_00007FF70C3F9978 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C3F8D50 | 25_2_00007FF70C3F8D50 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C3F29F4 | 25_2_00007FF70C3F29F4 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C3F1600 | 25_2_00007FF70C3F1600 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C404598 | 25_2_00007FF70C404598 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C4039A8 | 25_2_00007FF70C4039A8 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C408A64 | 25_2_00007FF70C408A64 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C3FAE80 | 25_2_00007FF70C3FAE80 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C3F5EBC | 25_2_00007FF70C3F5EBC |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C3F1F60 | 25_2_00007FF70C3F1F60 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C3F9338 | 25_2_00007FF70C3F9338 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C40EF38 | 25_2_00007FF70C40EF38 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C409008 | 25_2_00007FF70C409008 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C405FF8 | 25_2_00007FF70C405FF8 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C3FEB98 | 25_2_00007FF70C3FEB98 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C40F3CC | 25_2_00007FF70C40F3CC |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C40C470 | 25_2_00007FF70C40C470 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C41EC80 | 25_2_00007FF70C41EC80 |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C3F250C | 25_2_00007FF70C3F250C |
Source: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Code function: 25_2_00007FF70C3F58C0 | 25_2_00007FF70C3F58C0 |
Source: C:\Users\user\AppData\Local\2Yf2pw501\slui.exe | Code function: 28_2_00007FF6A3F231D0 | 28_2_00007FF6A3F231D0 |
Source: C:\Users\user\AppData\Local\2Yf2pw501\slui.exe | Code function: 28_2_00007FF6A3F21A80 | 28_2_00007FF6A3F21A80 |
Source: C:\Users\user\AppData\Local\2Yf2pw501\slui.exe | Code function: 28_2_00007FF6A3F242A0 | 28_2_00007FF6A3F242A0 |
Source: C:\Users\user\AppData\Local\2Yf2pw501\slui.exe | Code function: 28_2_00007FF6A3F246C0 | 28_2_00007FF6A3F246C0 |
Source: C:\Users\user\AppData\Local\2Yf2pw501\slui.exe | Code function: 28_2_00007FF6A3F256F4 | 28_2_00007FF6A3F256F4 |
Source: C:\Users\user\AppData\Local\2Yf2pw501\slui.exe | Code function: 28_2_00007FF6A3F262F4 | 28_2_00007FF6A3F262F4 |
Source: C:\Users\user\AppData\Local\2Yf2pw501\slui.exe | Code function: 28_2_00007FF6A3F42128 | 28_2_00007FF6A3F42128 |
Source: unknown | Process created: C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\GpUSRuIBHx.dll" | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\GpUSRuIBHx.dll",#1 | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\GpUSRuIBHx.dll,??0VolumeFveStatus@@IEAA@XZ | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\GpUSRuIBHx.dll",#1 | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\GpUSRuIBHx.dll,??0VolumeFveStatus@@QEAA@K_KJW4_FVE_WIPING_STATE@@@Z | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\GpUSRuIBHx.dll,??4BuiVolume@@QEAAAEAV0@AEBV0@@Z | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\BackgroundTransferHost.exe "BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1 | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\FileHistory.exe C:\Windows\system32\FileHistory.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\6f22a\FileHistory.exe C:\Users\user\AppData\Local\6f22a\FileHistory.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\rdpinput.exe C:\Windows\system32\rdpinput.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\Kyz7D\rdpinput.exe C:\Users\user\AppData\Local\Kyz7D\rdpinput.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\SndVol.exe C:\Windows\system32\SndVol.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\bTcR2e\SndVol.exe C:\Users\user\AppData\Local\bTcR2e\SndVol.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\SnippingTool.exe C:\Windows\system32\SnippingTool.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\slui.exe C:\Windows\system32\slui.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\2Yf2pw501\slui.exe C:\Users\user\AppData\Local\2Yf2pw501\slui.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\rdpinput.exe C:\Windows\system32\rdpinput.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\Fjrn\rdpinput.exe C:\Users\user\AppData\Local\Fjrn\rdpinput.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\printfilterpipelinesvc.exe C:\Windows\system32\printfilterpipelinesvc.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\2HophZ6P\printfilterpipelinesvc.exe C:\Users\user\AppData\Local\2HophZ6P\printfilterpipelinesvc.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\Utilman.exe C:\Windows\system32\Utilman.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\D6R1uM\Utilman.exe C:\Users\user\AppData\Local\D6R1uM\Utilman.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\phoneactivate.exe C:\Windows\system32\phoneactivate.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\op5PCy\phoneactivate.exe C:\Users\user\AppData\Local\op5PCy\phoneactivate.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\DmNotificationBroker.exe C:\Windows\system32\DmNotificationBroker.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\CSYG\DmNotificationBroker.exe C:\Users\user\AppData\Local\CSYG\DmNotificationBroker.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\ProximityUxHost.exe C:\Windows\system32\ProximityUxHost.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\oOQGGow\ProximityUxHost.exe C:\Users\user\AppData\Local\oOQGGow\ProximityUxHost.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\omadmclient.exe C:\Windows\system32\omadmclient.exe | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\GpUSRuIBHx.dll",#1 | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\GpUSRuIBHx.dll,??0VolumeFveStatus@@IEAA@XZ | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\GpUSRuIBHx.dll,??0VolumeFveStatus@@QEAA@K_KJW4_FVE_WIPING_STATE@@@Z | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\GpUSRuIBHx.dll,??4BuiVolume@@QEAAAEAV0@AEBV0@@Z | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\GpUSRuIBHx.dll",#1 | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\FileHistory.exe C:\Windows\system32\FileHistory.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\6f22a\FileHistory.exe C:\Users\user\AppData\Local\6f22a\FileHistory.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\rdpinput.exe C:\Windows\system32\rdpinput.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\Kyz7D\rdpinput.exe C:\Users\user\AppData\Local\Kyz7D\rdpinput.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\SndVol.exe C:\Windows\system32\SndVol.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\bTcR2e\SndVol.exe C:\Users\user\AppData\Local\bTcR2e\SndVol.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\SnippingTool.exe C:\Windows\system32\SnippingTool.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\LoReH\SnippingTool.exe C:\Users\user\AppData\Local\LoReH\SnippingTool.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\slui.exe C:\Windows\system32\slui.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\2Yf2pw501\slui.exe C:\Users\user\AppData\Local\2Yf2pw501\slui.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\rdpinput.exe C:\Windows\system32\rdpinput.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\Fjrn\rdpinput.exe C:\Users\user\AppData\Local\Fjrn\rdpinput.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\printfilterpipelinesvc.exe C:\Windows\system32\printfilterpipelinesvc.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\2HophZ6P\printfilterpipelinesvc.exe C:\Users\user\AppData\Local\2HophZ6P\printfilterpipelinesvc.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\Utilman.exe C:\Windows\system32\Utilman.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\D6R1uM\Utilman.exe C:\Users\user\AppData\Local\D6R1uM\Utilman.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\phoneactivate.exe C:\Windows\system32\phoneactivate.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\BackgroundTransferHost.exe "BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1 | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\DmNotificationBroker.exe C:\Windows\system32\DmNotificationBroker.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\CSYG\DmNotificationBroker.exe C:\Users\user\AppData\Local\CSYG\DmNotificationBroker.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\ProximityUxHost.exe C:\Windows\system32\ProximityUxHost.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\oOQGGow\ProximityUxHost.exe C:\Users\user\AppData\Local\oOQGGow\ProximityUxHost.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\omadmclient.exe C:\Windows\system32\omadmclient.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: unknown unknown | Jump to behavior |