Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 31.148.219.163 |
Source: C:\Users\user\text.doc.16147.scr | Code function: 3_2_01412A7B NtOpenProcess,NtOpenProcessToken,NtQueryInformationToken,NtQueryInformationToken,NtClose,NtClose, | 3_2_01412A7B |
Source: C:\Users\user\text.doc.16147.scr | Code function: 3_2_0141271B NtCreateSection,memset,RtlNtStatusToDosError,NtClose, | 3_2_0141271B |
Source: C:\Users\user\text.doc.16147.scr | Code function: 3_2_01413C1B NtQuerySystemInformation,RtlNtStatusToDosError, | 3_2_01413C1B |
Source: C:\Users\user\text.doc.16147.scr | Code function: 3_2_01411C29 memcpy,memcpy,memcpy,NtUnmapViewOfSection,RtlNtStatusToDosError,CloseHandle,memset, | 3_2_01411C29 |
Source: C:\Users\user\text.doc.16147.scr | Code function: 3_2_01413D34 NtAllocateVirtualMemory,RtlNtStatusToDosError,SetLastError, | 3_2_01413D34 |
Source: C:\Users\user\text.doc.16147.scr | Code function: 3_2_014126DC NtMapViewOfSection,RtlNtStatusToDosError, | 3_2_014126DC |
Source: C:\Users\user\text.doc.16147.scr | Code function: 3_2_01413CF3 NtWriteVirtualMemory,RtlNtStatusToDosError,SetLastError, | 3_2_01413CF3 |
Source: C:\Users\user\text.doc.16147.scr | Code function: 3_2_01413789 memset,memcpy,NtSetContextThread,RtlNtStatusToDosError,GetLastError, | 3_2_01413789 |
Source: C:\Users\user\text.doc.16147.scr | Code function: 3_2_01413CB2 NtReadVirtualMemory,RtlNtStatusToDosError,SetLastError, | 3_2_01413CB2 |
Source: C:\Users\user\text.doc.16147.scr | Code function: 3_2_01413B27 memset,NtQueryInformationProcess, | 3_2_01413B27 |
Source: C:\Users\user\text.doc.16147.scr | Code function: 3_2_01413D84 NtGetContextThread,NtGetContextThread, | 3_2_01413D84 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_0038A02C NtOpenProcess,NtOpenProcessToken,NtQueryInformationToken,NtQueryInformationToken,memcpy,NtClose,NtClose, | 16_2_0038A02C |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_0038885B NtQueryInformationProcess, | 16_2_0038885B |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_003890AF memset,NtQueryInformationProcess, | 16_2_003890AF |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_0038F8C5 GetVersion,NtCreateWaitablePort,NtCreateDirectoryObject,GetLastError, | 16_2_0038F8C5 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_0037C3A5 NtLoadKeyEx,memcpy, | 16_2_0037C3A5 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_00386B82 NtCreateWaitablePort,memset,FlushFileBuffers,GetLastError, | 16_2_00386B82 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_0038940B NtQuerySystemInformation,RtlNtStatusToDosError, | 16_2_0038940B |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_00390D1B memset,NtCancelIoFile,NtCancelIoFile,NtCancelIoFile,NtCancelIoFile,NtCancelIoFile,LocalFree,NtCancelIoFile, | 16_2_00390D1B |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_0038DE89 NtMapViewOfSection,RtlNtStatusToDosError, | 16_2_0038DE89 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_0038DEC8 NtCreateSection,memset,RtlNtStatusToDosError,NtClose, | 16_2_0038DEC8 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_0037DF75 NtUnmapViewOfSection,RtlNtStatusToDosError,HeapFree, | 16_2_0037DF75 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_0038CF9B memcpy,memcpy,memcpy,NtUnmapViewOfSection,RtlNtStatusToDosError,CloseHandle,memset, | 16_2_0038CF9B |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_0037D7EE memset,CreateMutexA,GetLastError,CloseHandle,RtlAllocateHeap,NtQueryInformationProcess,OpenProcess,GetLastError,CloseHandle,RtlAllocateHeap,LoadLibraryA,RtlAllocateHeap,wsprintfA, | 16_2_0037D7EE |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_003A3040 NtProtectVirtualMemory,NtProtectVirtualMemory, | 16_2_003A3040 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_00632A7B NtOpenProcess,NtOpenProcessToken,NtClose,NtClose, | 16_2_00632A7B |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_00633B27 memset,NtQueryInformationProcess, | 16_2_00633B27 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_00631C29 memcpy,memcpy,memcpy,NtUnmapViewOfSection,RtlNtStatusToDosError,CloseHandle,memset, | 16_2_00631C29 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_0063271B NtCreateSection,memset,RtlNtStatusToDosError,NtClose, | 16_2_0063271B |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_00633C1B NtQuerySystemInformation,RtlNtStatusToDosError, | 16_2_00633C1B |
Source: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe | Code function: 16_2_006326DC NtMapViewOfSection,RtlNtStatusToDosError, | 16_2_006326DC |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u..........)u..............)u..0.............8...9..................................w........................ | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u........L.o.a.d.i.n.g. .O.p.e.r.a.t.i.n.g. .S.y.s.t.e.m. .I.n.f.o.r.m.a.t.i.o.n. ...........P............... | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u..........)uX.............)u..0.............(...W..................................w........................ | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u........L.o.a.d.i.n.g. .C.o.m.p.u.t.e.r. .I.n.f.o.r.m.a.t.i.o.n. ..................w....D...@............... | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u..........)u..............)u..0.............(...e...............t...........X......wX....................... | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u........L.o.a.d.i.n.g. .P.r.o.c.e.s.s.o.r. .I.n.f.o.r.m.a.t.i.o.n. .........X......wX.......B............... | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u..........)u..............)u..0.............(...t...............\............$.....w.$...................... | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u........L.o.a.d.i.n.g. .B.I.O.S. .I.n.f.o.r.m.a.t.i.o.n. .......\............$.....w.$......8............... | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u..........)u..............)u..0.............(......................................w........................ | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u........L.o.a.d.i.n.g. .I.n.p.u.t. .L.o.c.a.l.e. .I.n.f.o.r.m.a.t.i.o.n. ..........w........H............... | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u..........)u..............)u..0.............(...a..................................vx....................... | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u........L.o.a.d.i.n.g. .T.i.m.e.Z.o.n.e. .I.n.f.o.r.m.a.t.i.o.n. ..................vx.......@............... | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u..........)u..............)u..0.............(...x..................................vx....................... | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u........L.o.a.d.i.n.g. .P.r.o.f.i.l.e. .I.n.f.o.r.m.a.t.i.o.n. ....................vx.......>............... | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u..........)u..............)u..0.............(...G..................................w........................ | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u........L.o.a.d.i.n.g. .P.a.g.e.f.i.l.e. .I.n.f.o.r.m.a.t.i.o.n. ..................w........@............... | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u..........)u..............)u..0.............(...x...............x............#.....w.#...................... | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u........L.o.a.d.i.n.g. .H.o.t.f.i.x. .I.n.f.o.r.m.a.t.i.o.n. ................#.....w.#......<............... | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u..........)ut.............)u..0.............(...................,..................w........................ | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u........L.o.a.d.i.n.g. .N.e.t.w.o.r.k. .C.a.r.d. .I.n.f.o.r.m.a.t.i.o.n. ..........w....`...H............... | Jump to behavior |
Source: C:\Windows\System32\systeminfo.exe | Console Write: ..........)u..........)u..............)u..0.................W...............D.b...........?. ........................... | Jump to behavior |
Source: C:\Windows\System32\net.exe | Console Write: ....................S.y.s.t.e.m. .e.r.r.o.r. .6.1.1.8. .h.a.s. .o.c.c.u.r.r.e.d.............t.,.%t....,.B...........8... | Jump to behavior |
Source: C:\Windows\System32\net.exe | Console Write: ..........................0.............................................r.r.e.d.............t.,.%t....,.......&......... | Jump to behavior |
Source: C:\Windows\System32\net.exe | Console Write: ....................a.+u..0.....................................................8...........t.,.%t..................8... | Jump to behavior |
Source: C:\Windows\System32\net.exe | Console Write: ..........................0.....................................................8...........t.,.%t....,................. | Jump to behavior |
Source: unknown | Process created: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE 'C:\Program Files\Microsoft Office\Office14\WINWORD.EXE' /Automation -Embedding | |
Source: unknown | Process created: C:\Users\user\text.doc.16147.scr C:\Users\user\text.doc.16147.scr | |
Source: unknown | Process created: C:\Windows\System32\cmd.exe cmd /C 'nslookup myip.opendns.com resolver1.opendns.com > C:\Users\user~1\AppData\Local\Temp\22E8.bi1' | |
Source: unknown | Process created: C:\Windows\System32\nslookup.exe nslookup myip.opendns.com resolver1.opendns.com | |
Source: unknown | Process created: C:\Windows\System32\cmd.exe cmd /C 'echo -------- >> C:\Users\user~1\AppData\Local\Temp\22E8.bi1' | |
Source: unknown | Process created: C:\Windows\System32\cmd.exe cmd /C 'systeminfo.exe > C:\Users\user~1\AppData\Local\Temp\152E.bin1' | |
Source: unknown | Process created: C:\Windows\System32\systeminfo.exe systeminfo.exe | |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe 'C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe' | |
Source: unknown | Process created: C:\Windows\System32\cmd.exe cmd /C 'echo -------- >> C:\Users\user~1\AppData\Local\Temp\152E.bin1' | |
Source: unknown | Process created: C:\Windows\System32\cmd.exe cmd /C 'net view >> C:\Users\user~1\AppData\Local\Temp\152E.bin1' | |
Source: unknown | Process created: C:\Windows\System32\net.exe net view | |
Source: unknown | Process created: C:\Windows\System32\cmd.exe cmd /C 'echo -------- >> C:\Users\user~1\AppData\Local\Temp\152E.bin1' | |
Source: unknown | Process created: C:\Windows\System32\cmd.exe cmd /C 'nslookup 127.0.0.1 >> C:\Users\user~1\AppData\Local\Temp\152E.bin1' | |
Source: unknown | Process created: C:\Windows\System32\nslookup.exe nslookup 127.0.0.1 | |
Source: unknown | Process created: C:\Windows\System32\cmd.exe cmd /C 'echo -------- >> C:\Users\user~1\AppData\Local\Temp\152E.bin1' | |
Source: unknown | Process created: C:\Windows\System32\cmd.exe cmd /C 'tasklist.exe /SVC >> C:\Users\user~1\AppData\Local\Temp\152E.bin1' | |
Source: unknown | Process created: C:\Windows\System32\tasklist.exe tasklist.exe /SVC | |
Source: unknown | Process created: C:\Windows\System32\cmd.exe cmd /C 'echo -------- >> C:\Users\user~1\AppData\Local\Temp\152E.bin1' | |
Source: unknown | Process created: C:\Windows\System32\cmd.exe cmd /C 'driverquery.exe >> C:\Users\user~1\AppData\Local\Temp\152E.bin1' | |
Source: unknown | Process created: C:\Windows\System32\driverquery.exe driverquery.exe | |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process created: C:\Users\user\text.doc.16147.scr C:\Users\user\text.doc.16147.scr | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\cmd.exe cmd /C 'nslookup myip.opendns.com resolver1.opendns.com > C:\Users\user~1\AppData\Local\Temp\22E8.bi1' | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\cmd.exe cmd /C 'echo -------- >> C:\Users\user~1\AppData\Local\Temp\22E8.bi1' | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\cmd.exe cmd /C 'systeminfo.exe > C:\Users\user~1\AppData\Local\Temp\152E.bin1' | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe 'C:\Users\user\AppData\Roaming\Microsoft\Aecaider\avicbrkr.exe' | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\cmd.exe cmd /C 'echo -------- >> C:\Users\user~1\AppData\Local\Temp\152E.bin1' | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\cmd.exe cmd /C 'net view >> C:\Users\user~1\AppData\Local\Temp\152E.bin1' | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\cmd.exe cmd /C 'echo -------- >> C:\Users\user~1\AppData\Local\Temp\152E.bin1' | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\cmd.exe cmd /C 'nslookup 127.0.0.1 >> C:\Users\user~1\AppData\Local\Temp\152E.bin1' | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\cmd.exe cmd /C 'echo -------- >> C:\Users\user~1\AppData\Local\Temp\152E.bin1' | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\cmd.exe cmd /C 'tasklist.exe /SVC >> C:\Users\user~1\AppData\Local\Temp\152E.bin1' | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\cmd.exe cmd /C 'echo -------- >> C:\Users\user~1\AppData\Local\Temp\152E.bin1' | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\cmd.exe cmd /C 'driverquery.exe >> C:\Users\user~1\AppData\Local\Temp\152E.bin1' | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\nslookup.exe nslookup myip.opendns.com resolver1.opendns.com | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\systeminfo.exe systeminfo.exe | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\net.exe net view | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\nslookup.exe nslookup 127.0.0.1 | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist.exe /SVC | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\driverquery.exe driverquery.exe | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |