General Info

URL

https://teams.microsoft.com/dl/launcher/launcher.html?url=%2f_%23%2fl%2fteam%2f19%3a8cf7dfcae0d14efeaa057dbc99bee101%40thread.skype%2fconversations%3ftenantId%3d7087a6be-5e7d-49e8-9ee5-3c7ffd3f1e65&type=team&deeplinkId=ca329099-d6db-4a01-832c-2703c9453ae2&directDl=true&msLaunch=true&enableMobilePage=true&suppressPrompt=true

Full analysis
https://app.any.run/tasks/18f231fd-f4a4-4c1a-b63f-41e3013b570b
Verdict
Malicious activity
Analysis date
9/10/2019, 23:42:04
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
180 seconds
Additional time used
120 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • Teams.exe (PID: 3052)
  • Teams.exe (PID: 3632)
  • Teams.exe (PID: 1816)
  • Teams.exe (PID: 3680)
  • Teams.exe (PID: 2572)
  • Teams.exe (PID: 2824)
  • Teams.exe (PID: 1016)
  • Teams.exe (PID: 3224)
  • Teams.exe (PID: 3568)
  • Teams.exe (PID: 3564)
  • Teams.exe (PID: 3192)
  • Teams.exe (PID: 3596)
  • Teams.exe (PID: 552)
  • Teams.exe (PID: 2244)
  • Teams.exe (PID: 1360)
  • Teams.exe (PID: 3148)
  • Teams.exe (PID: 3644)
  • Teams.exe (PID: 4068)
  • Teams.exe (PID: 2360)
  • Teams.exe (PID: 2588)
  • Teams.exe (PID: 2528)
  • regsvr32.exe (PID: 528)
  • Teams.exe (PID: 3792)
  • Teams.exe (PID: 1156)
  • Teams.exe (PID: 1260)
Changes the autorun value in the registry
  • Teams.exe (PID: 3632)
  • Teams.exe (PID: 2528)
  • Teams.exe (PID: 2244)
Application was dropped or rewritten from another process
  • Squirrel.exe (PID: 2472)
  • update.exe (PID: 3800)
  • Update.exe (PID: 3044)
  • Teams_windows_s_8D73638194D5326-2-0_.exe (PID: 2932)
Registers / Runs the DLL via REGSVR32.EXE
  • Update.exe (PID: 3044)
Application launched itself
  • Teams.exe (PID: 3632)
  • Teams.exe (PID: 2244)
  • Teams.exe (PID: 1156)
  • Teams.exe (PID: 2528)
Reads internet explorer settings
  • Teams.exe (PID: 2244)
Reads Internet Cache Settings
  • Teams.exe (PID: 2244)
Creates files in the user directory
  • Teams.exe (PID: 3632)
  • Teams.exe (PID: 2244)
  • Teams.exe (PID: 2528)
  • update.exe (PID: 3800)
  • Teams.exe (PID: 1156)
Modifies the open verb of a shell class
  • Teams.exe (PID: 3632)
  • Teams.exe (PID: 2244)
  • Teams.exe (PID: 2528)
Reads CPU info
  • Teams.exe (PID: 3632)
  • Teams.exe (PID: 2244)
  • Teams.exe (PID: 1156)
  • Teams.exe (PID: 2528)
Reads Environment values
  • Update.exe (PID: 3044)
Creates a software uninstall entry
  • Update.exe (PID: 3044)
Executable content was dropped or overwritten
  • Teams_windows_s_8D73638194D5326-2-0_.exe (PID: 2932)
  • Squirrel.exe (PID: 2472)
  • chrome.exe (PID: 2912)
  • Update.exe (PID: 3044)
Creates COM task schedule object
  • regsvr32.exe (PID: 528)
Modifies files in Chrome extension folder
  • chrome.exe (PID: 2912)
Reads the hosts file
  • Teams.exe (PID: 3632)
  • Teams.exe (PID: 2244)
  • Teams.exe (PID: 2528)
  • Teams.exe (PID: 1156)
  • chrome.exe (PID: 2912)
  • chrome.exe (PID: 2392)
Reads settings of System Certificates
  • Teams.exe (PID: 2244)
  • Teams.exe (PID: 2528)
  • Update.exe (PID: 3044)
  • chrome.exe (PID: 2392)
Reads Internet Cache Settings
  • chrome.exe (PID: 2912)
Application launched itself
  • chrome.exe (PID: 2912)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
84
Monitored processes
50
Malicious processes
28
Suspicious processes
0

Behavior graph

+
drop and start start drop and start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs teams_windows_s_8d73638194d5326-2-0_.exe update.exe squirrel.exe teams.exe update.exe no specs teams.exe no specs teams.exe no specs teams.exe regsvr32.exe no specs teams.exe no specs teams.exe no specs teams.exe no specs teams.exe no specs teams.exe no specs teams.exe no specs teams.exe teams.exe no specs teams.exe no specs teams.exe no specs teams.exe no specs teams.exe no specs teams.exe no specs teams.exe no specs teams.exe teams.exe no specs teams.exe no specs teams.exe no specs teams.exe no specs teams.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2912
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://teams.microsoft.com/dl/launcher/launcher.html?url=%2f_%23%2fl%2fteam%2f19%3a8cf7dfcae0d14efeaa057dbc99bee101%40thread.skype%2fconversations%3ftenantId%3d7087a6be-5e7d-49e8-9ee5-3c7ffd3f1e65&type=team&deeplinkId=ca329099-d6db-4a01-832c-2703c9453ae2&directDl=true&msLaunch=true&enableMobilePage=true&suppressPrompt=true"
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\hid.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winusb.dll
c:\windows\system32\msi.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mscms.dll
c:\windows\system32\winsta.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\wpc.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\samlib.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\wbem\wmiperfinst.dll
c:\windows\system32\pdh.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\imagehlp.dll
c:\program files\winrar\rarext.dll
c:\program files\microsoft office\office14\olkfstub.dll
c:\progra~1\micros~1\office14\mlshext.dll
c:\program files\microsoft office\office14\onfilter.dll
c:\program files\microsoft office\office14\visshe.dll
c:\program files\common files\microsoft shared\office14\msoshext.dll
c:\program files\microsoft office\office14\msohevi.dll
c:\windows\system32\mf.dll
c:\windows\system32\shdocvw.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\syncui.dll
c:\program files\notepad++\nppshell_06.dll
c:\program files\windows sidebar\sbdrop.dll
c:\windows\system32\stobject.dll
c:\windows\system32\cryptext.dll
c:\windows\system32\colorui.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\winspool.drv
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\audioses.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\rasadhlp.dll
c:\users\admin\downloads\teams_windows_s_8d73638194d5326-2-0_.exe
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\mpr.dll

PID
3584
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x6fdea9d0,0x6fdea9e0,0x6fdea9ec
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\cryptbase.dll

PID
2800
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2916 --on-initialized-event-handle=312 --parent-handle=316 /prefetch:6
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_watcher.dll

PID
4076
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=11887315092805064951 --mojo-platform-channel-handle=1000 --ignored=" --type=renderer " /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\program files\google\chrome\application\75.0.3770.100\swiftshader\libglesv2.dll
c:\program files\google\chrome\application\75.0.3770.100\swiftshader\libegl.dll

PID
2392
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=14335879791012145700 --mojo-platform-channel-handle=1568 /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ntmarta.dll

PID
3860
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4072639779794736149 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2156 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2668
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=13082818434744030117 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1988 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3504
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=14999772758230222346 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2548 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3456
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=5993573536800396435 --mojo-platform-channel-handle=3004 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3500
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=1301821397332809957 --mojo-platform-channel-handle=3464 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3244
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=4110136067564827104 --mojo-platform-channel-handle=3008 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3152
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=10828136414992086082 --mojo-platform-channel-handle=3340 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2192
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=3960847473709533248 --mojo-platform-channel-handle=3412 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3420
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=9247356049867796715 --mojo-platform-channel-handle=3672 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2368
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=3202291499520351735 --mojo-platform-channel-handle=3660 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3120
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=5026710652802770911 --mojo-platform-channel-handle=3816 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3088
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=643990286108108996 --mojo-platform-channel-handle=3832 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3092
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=18196593764721876613 --mojo-platform-channel-handle=3912 /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll

PID
3212
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=7852613361852170898 --renderer-client-id=17 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2944 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
1216
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=1530379318811630506 --mojo-platform-channel-handle=3176 /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\twext.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\zipfldr.dll
c:\program files\winrar\rarext.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\syncui.dll
c:\windows\system32\synceng.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\acppage.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\msi.dll
c:\windows\system32\wer.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\netutils.dll

PID
3648
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,15063037570338234419,11209023755964087141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=8934388150931886054 --mojo-platform-channel-handle=2408 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2932
CMD
"C:\Users\admin\Downloads\Teams_windows_s_8D73638194D5326-2-0_.exe"
Path
C:\Users\admin\Downloads\Teams_windows_s_8D73638194D5326-2-0_.exe
Indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\downloads\teams_windows_s_8d73638194d5326-2-0_.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\squirreltemp\update.exe

PID
3044
CMD
"C:\Users\admin\AppData\Local\SquirrelTemp\Update.exe" --install . --exeName=Teams_windows_s_8D73638194D5326-2-0_.exe
Path
C:\Users\admin\AppData\Local\SquirrelTemp\Update.exe
Indicators
Parent process
Teams_windows_s_8D73638194D5326-2-0_.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.4.4.0
Modules
Image
c:\users\admin\appdata\local\squirreltemp\update.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\system32\oleaut32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\windowsbase\0d5a8e6f89227cc5d954e65856f9cf1a\windowsbase.ni.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentationcore\e7873d3bd71f6122c2a954be1bb5bb28\presentationcore.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatio5ae0f00f#\b34cda03a984c515b31faf410e5b7e39\presentationframework.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xaml\4d290752f65a065fcde70178562c3383\system.xaml.ni.dll
c:\windows\system32\dwrite.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\wpfgfx_v0400.dll
c:\windows\system32\msvcp120_clr0400.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\presentationnative_v0400.dll
c:\windows\system32\shell32.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.runteb92aa12#\62a6b39f4f68c25dfd2f6308d7541401\system.runtime.serialization.ni.dll
c:\windows\system32\profapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\microsoft.net\framework\v4.0.30319\diasymreader.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\cd03f9386e02f56502e01a25ddd7e0a7\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\7c8f75f367134a030cba4a127dc62a2f\system.xml.ni.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\uxtheme.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatiod51afaa5#\867cbe7462b04e2cf1ae39abb576ae2a\presentationframework.classic.ni.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\vga.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msctfui.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\uiautomationtypes\1e1a1bd97e618bc4934ee967bea27ae8\uiautomationtypes.ni.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\sxs.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\sspicli.dll
c:\users\admin\appdata\local\microsoft\teams\current\squirrel.exe
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\windows\system32\linkinfo.dll
c:\windows\system32\regsvr32.exe
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\61dfb69c9ad6ed96809170d54d80b8a6\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.comp46f2b404#\0a6fed4a3d60bba766a643e4bc2e5968\system.componentmodel.dataannotations.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml.linq\f68563fb25af65c25de37130ebcd576c\system.xml.linq.ni.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\credssp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\secur32.dll
c:\windows\system32\schannel.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll

PID
2472
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Squirrel.exe" --updateSelf=C:\Users\admin\AppData\Local\SquirrelTemp\Update.exe
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Squirrel.exe
Indicators
Parent process
Update.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.4.4.0
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\squirrel.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\system32\oleaut32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\windowsbase\0d5a8e6f89227cc5d954e65856f9cf1a\windowsbase.ni.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentationcore\e7873d3bd71f6122c2a954be1bb5bb28\presentationcore.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatio5ae0f00f#\b34cda03a984c515b31faf410e5b7e39\presentationframework.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xaml\4d290752f65a065fcde70178562c3383\system.xaml.ni.dll
c:\windows\system32\dwrite.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\wpfgfx_v0400.dll
c:\windows\system32\msvcp120_clr0400.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\presentationnative_v0400.dll
c:\windows\system32\shell32.dll

PID
1156
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --squirrel-install 1.2.00.22654
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
Parent process
Update.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\native-utils\build\release\native-utils.node
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\bcryptprimitives.dll
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\keytar3\build\release\keytar.node
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\microsoft\teams\update.exe
c:\windows\system32\mscms.dll
c:\windows\system32\audioses.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\wintrust.dll

PID
3800
CMD
C:\Users\admin\AppData\Local\Microsoft\Teams\update.exe --createShortcut=Teams.exe -l=StartMenu,Desktop
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\update.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.4.4.0
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\update.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\system32\oleaut32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\windowsbase\0d5a8e6f89227cc5d954e65856f9cf1a\windowsbase.ni.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentationcore\e7873d3bd71f6122c2a954be1bb5bb28\presentationcore.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatio5ae0f00f#\b34cda03a984c515b31faf410e5b7e39\presentationframework.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xaml\4d290752f65a065fcde70178562c3383\system.xaml.ni.dll
c:\windows\system32\dwrite.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\wpfgfx_v0400.dll
c:\windows\system32\msvcp120_clr0400.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\presentationnative_v0400.dll
c:\windows\system32\shell32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\7c8f75f367134a030cba4a127dc62a2f\system.xml.ni.dll
c:\windows\system32\profapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.comp46f2b404#\0a6fed4a3d60bba766a643e4bc2e5968\system.componentmodel.dataannotations.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml.linq\f68563fb25af65c25de37130ebcd576c\system.xml.linq.ni.dll
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\windows\system32\clbcatq.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\netutils.dll

PID
1260
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=gpu-process --enable-features=FixAltGraph --no-sandbox --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --service-request-channel-token=780C2F5384A9E7576E9473CF8898D5E0 --mojo-platform-channel-handle=1240 /prefetch:2
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Exit code
4
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\dxva2.dll
c:\users\admin\appdata\local\microsoft\teams\current\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll

PID
3792
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=gpu-process --enable-features=FixAltGraph --no-sandbox --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --use-gl=swiftshader-webgl --service-request-channel-token=8E697AD57D5BB5FA77B178206542F6C3 --mojo-platform-channel-handle=1092 /prefetch:2
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Exit code
4
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\dxva2.dll
c:\users\admin\appdata\local\microsoft\teams\current\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll

PID
2528
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --squirrel-firstrun
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
Parent process
Update.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\native-utils\build\release\native-utils.node
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\bcryptprimitives.dll
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\keytar3\build\release\keytar.node
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\@msteams\node-locale-info-provider\build\release\addon.node
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\@msteams\electron-modules-package-utils\build\release\package-utils.node
c:\windows\system32\wintrust.dll
c:\windows\system32\winsta.dll
c:\windows\system32\mscms.dll
c:\windows\system32\audioses.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\adal-win\build\release\adal-win.node
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\adal-win\build\release\adal.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wkscli.dll

PID
528
CMD
"C:\Windows\system32\regsvr32.exe" /s /n /i:user "C:\Users\admin\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.19178.2\x86\Microsoft.Teams.AddinLoader.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
Update.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\local\microsoft\teamsmeetingaddin\1.0.19178.2\x86\microsoft.teams.addinloader.dll
c:\windows\system32\mscoree.dll
c:\users\admin\appdata\local\microsoft\teamsmeetingaddin\1.0.19178.2\x86\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teamsmeetingaddin\1.0.19178.2\x86\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teamsmeetingaddin\1.0.19178.2\x86\api-ms-win-crt-runtime-l1-1-0.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
c:\windows\system32\api-ms-win-core-file-l2-1-0.dll
c:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
c:\windows\system32\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teamsmeetingaddin\1.0.19178.2\x86\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teamsmeetingaddin\1.0.19178.2\x86\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teamsmeetingaddin\1.0.19178.2\x86\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teamsmeetingaddin\1.0.19178.2\x86\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teamsmeetingaddin\1.0.19178.2\x86\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teamsmeetingaddin\1.0.19178.2\x86\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teamsmeetingaddin\1.0.19178.2\x86\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teamsmeetingaddin\1.0.19178.2\x86\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teamsmeetingaddin\1.0.19178.2\x86\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teamsmeetingaddin\1.0.19178.2\x86\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teamsmeetingaddin\1.0.19178.2\x86\api-ms-win-crt-utility-l1-1-0.dll

PID
3596
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=gpu-process --enable-features=FixAltGraph --no-sandbox --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --service-request-channel-token=DEE3E42049A1792DD2CEA8BE965B5547 --mojo-platform-channel-handle=1232 /prefetch:2
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Exit code
4
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\ole32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\dxva2.dll
c:\users\admin\appdata\local\microsoft\teams\current\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll

PID
2360
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=renderer --autoplay-policy=no-user-gesture-required --no-sandbox --enable-features=FixAltGraph --service-pipe-token=72444AA24B6FC3535E7CED90A7125E23 --lang=en-US --app-user-model-id=com.squirrel.Teams.Teams --app-path="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar" --node-integration=false --webview-tag=false --no-sandbox --preload="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar\lib\renderer\preload_default.js" --background-color=#FFFFFFFF --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=72444AA24B6FC3535E7CED90A7125E23 --renderer-client-id=5 --mojo-platform-channel-handle=1484 /prefetch:1 --msteams-process-type=loadingWindow
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll

PID
3148
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=gpu-process --enable-features=FixAltGraph --no-sandbox --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --use-gl=swiftshader-webgl --service-request-channel-token=DFDEEE571E6025032F84ADB81473391F --mojo-platform-channel-handle=1716 /prefetch:2
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Exit code
4
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\dxva2.dll
c:\users\admin\appdata\local\microsoft\teams\current\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll

PID
2588
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=renderer --autoplay-policy=no-user-gesture-required --no-sandbox --enable-features=FixAltGraph --service-pipe-token=F0127559C10569C18E78A2E71B2F4A36 --lang=en-US --app-user-model-id=com.squirrel.Teams.Teams --app-path="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar" --node-integration=false --webview-tag=false --no-sandbox --preload="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar\lib\renderer\notifications\preload_notifications.js" --background-color=#fff --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=F0127559C10569C18E78A2E71B2F4A36 --renderer-client-id=9 --mojo-platform-channel-handle=1920 /prefetch:1 --msteams-process-type=notificationsManager
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll

PID
3568
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=renderer --autoplay-policy=no-user-gesture-required --no-sandbox --enable-features=FixAltGraph --service-pipe-token=3171DC7419E791B1F9A91559FBA37E60 --lang=en-US --app-user-model-id=com.squirrel.Teams.Teams --app-path="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar" --node-integration=false --webview-tag=true --no-sandbox --preload="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar\lib\renderer\preload.js" --background-color=#fff --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=3171DC7419E791B1F9A91559FBA37E60 --renderer-client-id=10 --mojo-platform-channel-handle=1664 /prefetch:1 --msteams-process-type=mainWindow
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\native-utils\build\release\native-utils.node
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll

PID
3644
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=relauncher --- "C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe"
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\apphelp.dll

PID
2244
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe"
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\native-utils\build\release\native-utils.node
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\bcryptprimitives.dll
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\keytar3\build\release\keytar.node
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\@msteams\node-locale-info-provider\build\release\addon.node
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\@msteams\electron-modules-package-utils\build\release\package-utils.node
c:\windows\system32\wintrust.dll
c:\windows\system32\winsta.dll
c:\windows\system32\mscms.dll
c:\windows\system32\audioses.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\adal-win\build\release\adal-win.node
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\adal-win\build\release\adal.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mlang.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\jscript.dll
c:\windows\system32\dxtrans.dll
c:\windows\system32\atl.dll
c:\windows\system32\ddrawex.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\dxtmsft.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\msxml3.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\d3dim700.dll

PID
1360
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=gpu-process --enable-features=FixAltGraph --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --service-request-channel-token=B2E5091204B079F0D6283C90FE9D023C --mojo-platform-channel-handle=1240 --ignored=" --type=renderer " /prefetch:2
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
LOW
Exit code
4
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\dxva2.dll
c:\users\admin\appdata\local\microsoft\teams\current\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll

PID
3564
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=renderer --autoplay-policy=no-user-gesture-required --enable-features=FixAltGraph --service-pipe-token=D834EDC04E3307549784E0BAB726F410 --lang=en-US --app-user-model-id=com.squirrel.Teams.Teams --app-path="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar" --node-integration=false --webview-tag=false --no-sandbox --preload="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar\lib\renderer\preload_default.js" --background-color=#FFFFFFFF --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=D834EDC04E3307549784E0BAB726F410 --renderer-client-id=5 --mojo-platform-channel-handle=1632 /prefetch:1 --msteams-process-type=loadingWindow
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll

PID
4068
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=gpu-process --enable-features=FixAltGraph --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --use-gl=swiftshader-webgl --service-request-channel-token=EA0071857A9D931CBB1E7A0061A62498 --mojo-platform-channel-handle=1820 --ignored=" --type=renderer " /prefetch:2
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
LOW
Exit code
4
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\dxva2.dll
c:\users\admin\appdata\local\microsoft\teams\current\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll

PID
552
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=renderer --autoplay-policy=no-user-gesture-required --enable-features=FixAltGraph --service-pipe-token=0F017A53887CE7CF58B37DA1B11DF677 --lang=en-US --app-user-model-id=com.squirrel.Teams.Teams --app-path="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar" --node-integration=false --webview-tag=false --no-sandbox --preload="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar\lib\renderer\notifications\preload_notifications.js" --background-color=#fff --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=0F017A53887CE7CF58B37DA1B11DF677 --renderer-client-id=9 --mojo-platform-channel-handle=2008 /prefetch:1 --msteams-process-type=notificationsManager
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\cryptbase.dll

PID
3192
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=renderer --autoplay-policy=no-user-gesture-required --enable-features=FixAltGraph --service-pipe-token=E6E1A70D199A2FEC063069ECBFA0C7E8 --lang=en-US --app-user-model-id=com.squirrel.Teams.Teams --app-path="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar" --node-integration=false --webview-tag=false --enable-sandbox --preload="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar\lib\renderer\preload_default_sandbox.js" --background-color=#fff --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=E6E1A70D199A2FEC063069ECBFA0C7E8 --renderer-client-id=11 --mojo-platform-channel-handle=1488 /prefetch:1 --msteams-process-type=upnWindow
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\windows\system32\wshqos.dll
c:\windows\system32\wship6.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll

PID
2824
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=renderer --autoplay-policy=no-user-gesture-required --enable-features=FixAltGraph --disable-gpu-compositing --service-pipe-token=8CE49356C7B5505444DA2CC26921F6D8 --lang=en-US --app-user-model-id=com.squirrel.Teams.Teams --app-path="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar" --node-integration=false --webview-tag=true --no-sandbox --preload="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar\lib\renderer\preload.js" --background-color=#fff --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=8CE49356C7B5505444DA2CC26921F6D8 --renderer-client-id=12 --mojo-platform-channel-handle=3372 /prefetch:1 --msteams-process-type=mainWindow
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\systemroot\system32\ntdll.dll
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\native-utils\build\release\native-utils.node
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll

PID
2572
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=relauncher --- "C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe"
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\apphelp.dll

PID
3632
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe"
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\native-utils\build\release\native-utils.node
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\bcryptprimitives.dll
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\keytar3\build\release\keytar.node
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\@msteams\node-locale-info-provider\build\release\addon.node
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\@msteams\electron-modules-package-utils\build\release\package-utils.node
c:\windows\system32\wintrust.dll
c:\windows\system32\winsta.dll
c:\windows\system32\mscms.dll
c:\windows\system32\audioses.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\adal-win\build\release\adal-win.node
c:\users\admin\appdata\local\microsoft\teams\current\resources\app.asar.unpacked\node_modules\adal-win\build\release\adal.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll

PID
1816
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=gpu-process --enable-features=FixAltGraph --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --service-request-channel-token=88FEF2478BBB18802E2504BAE57AB471 --mojo-platform-channel-handle=1240 --ignored=" --type=renderer " /prefetch:2
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
LOW
Exit code
4
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\dxva2.dll
c:\users\admin\appdata\local\microsoft\teams\current\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll

PID
3052
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=renderer --autoplay-policy=no-user-gesture-required --enable-features=FixAltGraph --service-pipe-token=C65D6DAD1B3B1A167DB5558696D40FAF --lang=en-US --app-user-model-id=com.squirrel.Teams.Teams --app-path="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar" --node-integration=false --webview-tag=false --no-sandbox --preload="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar\lib\renderer\preload_default.js" --background-color=#FFFFFFFF --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=C65D6DAD1B3B1A167DB5558696D40FAF --renderer-client-id=5 --mojo-platform-channel-handle=1620 /prefetch:1 --msteams-process-type=loadingWindow
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll

PID
3224
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=gpu-process --enable-features=FixAltGraph --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --use-gl=swiftshader-webgl --service-request-channel-token=53DEC905B9F674124E32A3E5DF6DA06E --mojo-platform-channel-handle=1804 --ignored=" --type=renderer " /prefetch:2
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
LOW
Exit code
4
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\dxva2.dll
c:\users\admin\appdata\local\microsoft\teams\current\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll

PID
3680
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=renderer --autoplay-policy=no-user-gesture-required --enable-features=FixAltGraph --service-pipe-token=83FCA71D0B0536298B5C593500257B6E --lang=en-US --app-user-model-id=com.squirrel.Teams.Teams --app-path="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar" --node-integration=false --webview-tag=false --no-sandbox --preload="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar\lib\renderer\notifications\preload_notifications.js" --background-color=#fff --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=83FCA71D0B0536298B5C593500257B6E --renderer-client-id=9 --mojo-platform-channel-handle=2016 /prefetch:1 --msteams-process-type=notificationsManager
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No indicators
Parent process
Teams.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Microsoft Teams
Version
1.2.00.22654
Modules
Image
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\node.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\users\admin\appdata\local\microsoft\teams\current\msvcp140.dll
c:\users\admin\appdata\local\microsoft\teams\current\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-localization-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-processthreads-l1-1-1.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-timezone-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-file-l2-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-string-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-heap-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-stdio-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-convert-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-locale-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-math-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-multibyte-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-time-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-filesystem-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-environment-l1-1-0.dll
c:\users\admin\appdata\local\microsoft\teams\current\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll

PID
1016
CMD
"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=renderer --autoplay-policy=no-user-gesture-required --enable-features=FixAltGraph --service-pipe-token=D656954A742913B59728A16078E6CB86 --lang=en-US --app-user-model-id=com.squirrel.Teams.Teams --app-path="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar" --node-integration=false --webview-tag=false --enable-sandbox --preload="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar\lib\renderer\preload_default_sandbox.js" --background-color=#fff --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=D656954A742913B59728A16078E6CB86 --renderer-client-id=11 --mojo-platform-channel-handle=1452 /prefetch:1 --msteams-process-type=upnWindow
Path
C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Indicators
No