General Info

File name

Discord Gift Valid.exe

Full analysis
https://app.any.run/tasks/732ded9c-3f6d-433c-a83b-9ed3a814ec25
Verdict
Malicious activity
Analysis date
7/17/2019, 18:26:23
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5

89ed55773129d263d92a79652746d307

SHA1

76ec0358029368aabe175aeadd6763d663c964d6

SHA256

ff9e38138bc6874b0f8e02848e5432662eb6b4baeb52702c7432be5796e3b9d8

SSDEEP

3072:ryQP2dr++pfl4v+IRSDQXlvRdQ0mjdrO+pfl4v+Ix:ZP2drFIv+IYDQpfQdrVIv+I

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 67.0.4 (x86 en-US) (67.0.4)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • ns8D2B.tmp (PID: 3924)
  • TeamViewer_Setup.exe (PID: 3884)
  • nsCB7E.tmp (PID: 3428)
  • nsBBED.tmp (PID: 2856)
Loads the Task Scheduler COM API
  • schtasks.exe (PID: 3184)
Changes settings of System certificates
  • TeamViewer_Service.exe (PID: 3536)
Uses Task Scheduler to autorun other applications
  • ns8D2B.tmp (PID: 3924)
Creates files in the program directory
  • TeamViewer_.exe (PID: 1864)
Application launched itself
  • TeamViewer_.exe (PID: 800)
Creates files in the user directory
  • TeamViewer_Service.exe (PID: 3536)
  • TeamViewer_.exe (PID: 1864)
Executable content was dropped or overwritten
  • TeamViewer_.exe (PID: 1864)
  • chrome.exe (PID: 860)
  • chrome.exe (PID: 3548)
Adds / modifies Windows certificates
  • TeamViewer_Service.exe (PID: 3536)
Starts application with an unusual extension
  • TeamViewer_.exe (PID: 1864)
Modifies files in Chrome extension folder
  • chrome.exe (PID: 3548)
Reads settings of System Certificates
  • chrome.exe (PID: 3548)
Reads Internet Cache Settings
  • chrome.exe (PID: 3548)
Dropped object may contain Bitcoin addresses
  • chrome.exe (PID: 3548)
Application launched itself
  • chrome.exe (PID: 3548)
Manual execution by user
  • chrome.exe (PID: 3548)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Generic CIL Executable (.NET, Mono, etc.) (45.1%)
.exe
|   Win32 Executable MS Visual C++ (generic) (19.2%)
.exe
|   Win64 Executable (generic) (17%)
.scr
|   Windows screen saver (8%)
.dll
|   Win32 Dynamic Link Library (generic) (4%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2019:07:12 16:04:11+02:00
PEType:
PE32
LinkerVersion:
11
CodeSize:
140800
InitializedDataSize:
62464
UninitializedDataSize:
null
EntryPoint:
0x245ce
OSVersion:
4
ImageVersion:
null
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
1.0.0.0
ProductVersionNumber:
1.0.0.0
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
FileDescription:
Discord Gift Valid
FileVersion:
1.0.0.0
InternalName:
Discord Gift Valid.exe
LegalCopyright:
Copyright © 2019
OriginalFileName:
Discord Gift Valid.exe
ProductName:
Discord Gift Valid by Massinez
ProductVersion:
1.0.0.0
AssemblyVersion:
1.0.0.0
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
12-Jul-2019 14:04:11
Debug artifacts
C:\Users\Massinez\documents\visual studio 2010\Projects\Discord Gift Valid\Discord Gift Valid\obj\x86\Release\Discord Gift Valid.pdb
FileDescription:
Discord Gift Valid
FileVersion:
1.0.0.0
InternalName:
Discord Gift Valid.exe
LegalCopyright:
Copyright © 2019
OriginalFilename:
Discord Gift Valid.exe
ProductName:
Discord Gift Valid by Massinez
ProductVersion:
1.0.0.0
Assembly Version:
1.0.0.0
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000080
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
4
Time date stamp:
12-Jul-2019 14:04:11
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00002000 0x000225D4 0x00022600 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.65304
.sdata 0x00026000 0x000000B9 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.60476
.rsrc 0x00028000 0x0000EE70 0x0000F000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 6.99446
.reloc 0x00038000 0x0000000C 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 0.10191
Resources
1

2

3

4

5

6

7

8

9

10

11

12

13

32512

Imports
    mscoree.dll

Exports

    No exports.

Screenshots

Processes

Total processes
81
Monitored processes
39
Malicious processes
4
Suspicious processes
3

Behavior graph

+
start drop and start drop and start drop and start drop and start discord gift valid.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs teamviewer_setup.exe no specs teamviewer_.exe no specs teamviewer_.exe ns8d2b.tmp schtasks.exe no specs chrome.exe no specs nsbbed.tmp no specs teamviewer_service.exe no specs nscb7e.tmp no specs teamviewer.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3464
CMD
"C:\Users\admin\AppData\Local\Temp\Discord Gift Valid.exe"
Path
C:\Users\admin\AppData\Local\Temp\Discord Gift Valid.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Discord Gift Valid
Version
1.0.0.0
Modules
Image
c:\users\admin\appdata\local\temp\discord gift valid.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\microsoft.v9921e851#\f971acbc25b64dfe4d70e5b25837c780\microsoft.visualbasic.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\system32\oleaut32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\61dfb69c9ad6ed96809170d54d80b8a6\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\2dc6cfd856864312d563098f9486361c\system.windows.forms.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\cd03f9386e02f56502e01a25ddd7e0a7\system.configuration.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\7c8f75f367134a030cba4a127dc62a2f\system.xml.ni.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.runt73a1fc9d#\b90f40ba78ef47ed0a9a563e242f6322\system.runtime.remoting.ni.dll
c:\windows\system32\uxtheme.dll
c:\windows\microsoft.net\assembly\gac_msil\system.windows.forms\v4.0_4.0.0.0__b77a5c561934e089\system.windows.forms.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\windowscodecs.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll

PID
3548
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe"
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\hid.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winusb.dll
c:\windows\system32\msi.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mscms.dll
c:\windows\system32\winsta.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\wpc.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\samlib.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\wship6.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\wbem\wmiperfinst.dll
c:\windows\system32\pdh.dll
c:\program files\winrar\rarext.dll
c:\program files\microsoft office\office14\olkfstub.dll
c:\progra~1\micros~1\office14\mlshext.dll
c:\program files\microsoft office\office14\onfilter.dll
c:\program files\microsoft office\office14\visshe.dll
c:\program files\common files\microsoft shared\office14\msoshext.dll
c:\program files\microsoft office\office14\msohevi.dll
c:\windows\system32\mf.dll
c:\windows\system32\shdocvw.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\syncui.dll
c:\program files\notepad++\nppshell_06.dll
c:\program files\windows sidebar\sbdrop.dll
c:\windows\system32\stobject.dll
c:\windows\system32\cryptext.dll
c:\windows\system32\colorui.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\audioses.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\rasadhlp.dll
c:\users\admin\downloads\teamviewer_setup.exe
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\mpr.dll

PID
340
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x691aa9d0,0x691aa9e0,0x691aa9ec
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
3352
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=3636 --on-initialized-event-handle=312 --parent-handle=316 /prefetch:6
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_watcher.dll

PID
3068
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=10971811207946298040 --mojo-platform-channel-handle=1040 --ignored=" --type=renderer " /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\program files\google\chrome\application\75.0.3770.100\swiftshader\libglesv2.dll
c:\program files\google\chrome\application\75.0.3770.100\swiftshader\libegl.dll

PID
860
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=2625711081695876921 --mojo-platform-channel-handle=1560 /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\credssp.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\ntmarta.dll

PID
864
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=18419694806960521348 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2240 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3584
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=6936571969286015617 --renderer-client-id=7 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2448 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
1816
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=17597468748068491422 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2452 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2500
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=1200404022308011317 --mojo-platform-channel-handle=3276 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3700
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=1583916552603333108 --mojo-platform-channel-handle=3356 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3112
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=2433587041600247975 --renderer-client-id=10 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3532 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3052
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=5979629416511115436 --mojo-platform-channel-handle=3704 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3048
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=8505381714522521428 --mojo-platform-channel-handle=3708 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3764
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=13238054752499297228 --mojo-platform-channel-handle=3420 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
1704
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=6174721953966450848 --mojo-platform-channel-handle=3264 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2380
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=8934159187617605993 --mojo-platform-channel-handle=4020 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
876
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=4703811362928332355 --mojo-platform-channel-handle=3028 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2256
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=8150527366073983036 --renderer-client-id=17 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3268 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
1812
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=2846841410745592904 --mojo-platform-channel-handle=2728 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
4056
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=6257158321342854987 --mojo-platform-channel-handle=3928 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2088
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=7661483517275808809 --mojo-platform-channel-handle=3968 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3176
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=8227384009032321970 --mojo-platform-channel-handle=4196 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
1860
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=5734941890553262820 --renderer-client-id=22 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3296 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
1200
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=4550599087197690195 --mojo-platform-channel-handle=4224 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2160
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=13894973241305997506 --renderer-client-id=24 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3388 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3712
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=11163328657558368982 --mojo-platform-channel-handle=3956 /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll

PID
2536
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=5361554978389481699 --renderer-client-id=26 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3128 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3740
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=14395707827478916158 --renderer-client-id=27 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2796 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3884
CMD
"C:\Users\admin\Downloads\TeamViewer_Setup.exe"
Path
C:\Users\admin\Downloads\TeamViewer_Setup.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
TeamViewer GmbH
Description
Version
Modules
Image
c:\users\admin\downloads\teamviewer_setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\users\admin\appdata\local\temp\nse781b.tmp\tvgetversion.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winspool.drv
c:\users\admin\appdata\local\temp\teamviewer\teamviewer_.exe

PID
800
CMD
"C:\Users\admin\AppData\Local\Temp\TeamViewer\TeamViewer_.exe"
Path
C:\Users\admin\AppData\Local\Temp\TeamViewer\TeamViewer_.exe
Indicators
No indicators
Parent process
TeamViewer_Setup.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
TeamViewer
Description
TeamViewer Remote Control Application Installer
Version
Modules
Image
c:\users\admin\appdata\local\temp\teamviewer\teamviewer_.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nsp7b67.tmp\tvgetversion.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winspool.drv
c:\users\admin\appdata\local\temp\nsp7b67.tmp\userinfo.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nsp7b67.tmp\installoptions.dll
c:\windows\system32\comdlg32.dll
c:\users\admin\appdata\local\temp\nsp7b67.tmp\system.dll
c:\users\admin\appdata\local\temp\nsp7b67.tmp\linker.dll
c:\users\admin\appdata\local\temp\nsp7b67.tmp\uac.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mpr.dll

PID
1864
CMD
"C:\Users\admin\AppData\Local\Temp\TeamViewer\TeamViewer_.exe" /UAC:501A0 /NCRC
Path
C:\Users\admin\AppData\Local\Temp\TeamViewer\TeamViewer_.exe
Indicators
Parent process
TeamViewer_.exe
User
admin
Integrity Level
HIGH
Version:
Company
TeamViewer
Description
TeamViewer Remote Control Application Installer
Version
Modules
Image
c:\users\admin\appdata\local\temp\teamviewer\teamviewer_.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nsg8b84.tmp\tvgetversion.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winspool.drv
c:\users\admin\appdata\local\temp\nsg8b84.tmp\userinfo.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nsg8b84.tmp\installoptions.dll
c:\windows\system32\comdlg32.dll
c:\users\admin\appdata\local\temp\nsg8b84.tmp\system.dll
c:\users\admin\appdata\local\temp\nsg8b84.tmp\uac.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\users\admin\appdata\local\temp\nsg8b84.tmp\nsexec.dll
c:\users\admin\appdata\local\temp\nsg8b84.tmp\ns8d2b.tmp
c:\users\admin\appdata\local\temp\nsg8b84.tmp\nsarray.dll
c:\users\admin\appdata\local\temp\nsg8b84.tmp\nsis7z.dll
c:\windows\system32\winsta.dll
c:\users\admin\appdata\local\temp\nsg8b84.tmp\findprocdll.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\teamviewer\teamviewer.exe
c:\users\admin\appdata\local\temp\nsg8b84.tmp\nsbbed.tmp
c:\users\admin\appdata\local\temp\nsg8b84.tmp\nscb7e.tmp

PID
3924
CMD
"C:\Users\admin\AppData\Local\Temp\nsg8B84.tmp\ns8D2B.tmp" C:\Windows\system32\schtasks /Create /TN TVInstallRestore /TR "C:\Users\admin\AppData\Local\Temp\TeamViewer\TeamViewer_.exe /RESTORE" /RU SYSTEM /SC ONLOGON /F
Path
C:\Users\admin\AppData\Local\Temp\nsg8B84.tmp\ns8D2B.tmp
Indicators
Parent process
TeamViewer_.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\nsg8b84.tmp\ns8d2b.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll

PID
3184
CMD
C:\Windows\system32\schtasks /Create /TN TVInstallRestore /TR "C:\Users\admin\AppData\Local\Temp\TeamViewer\TeamViewer_.exe /RESTORE" /RU SYSTEM /SC ONLOGON /F
Path
C:\Windows\system32\schtasks.exe
Indicators
No indicators
Parent process
ns8D2B.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Manages scheduled tasks
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\xmllite.dll

PID
3272
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,454193600328392502,8366990284249690116,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=3040799491103730806 --mojo-platform-channel-handle=2888 /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\twext.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\sendmail.dll
c:\windows\system32\zipfldr.dll
c:\windows\system32\fxsresm.dll
c:\program files\winrar\rarext.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\syncui.dll
c:\windows\system32\synceng.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\acppage.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\msi.dll
c:\windows\system32\wer.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\netutils.dll

PID
2856
CMD
"C:\Users\admin\AppData\Local\Temp\nsg8B84.tmp\nsBBED.tmp" "C:\Program Files\TeamViewer\TeamViewer_Service.exe" -install
Path
C:\Users\admin\AppData\Local\Temp\nsg8B84.tmp\nsBBED.tmp
Indicators
No indicators
Parent process
TeamViewer_.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\nsg8b84.tmp\nsbbed.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\program files\teamviewer\teamviewer_service.exe

PID
3536
CMD
"C:\Program Files\TeamViewer\TeamViewer_Service.exe" -install
Path
C:\Program Files\TeamViewer\TeamViewer_Service.exe
Indicators
No indicators
Parent process
nsBBED.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
TeamViewer GmbH
Description
TeamViewer 14
Version
14.4.2669.0
Modules
Image
c:\program files\teamviewer\teamviewer_service.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll

PID
3428
CMD
"C:\Users\admin\AppData\Local\Temp\nsg8B84.tmp\nsCB7E.tmp" "C:\Program Files\TeamViewer\TeamViewer.exe" api --install
Path
C:\Users\admin\AppData\Local\Temp\nsg8B84.tmp\nsCB7E.tmp
Indicators
No indicators
Parent process
TeamViewer_.exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\nsg8b84.tmp\nscb7e.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll

PID
3808
CMD
"C:\Program Files\TeamViewer\TeamViewer.exe" api --install
Path
C:\Program Files\TeamViewer\TeamViewer.exe
Indicators
No indicators
Parent process
nsCB7E.tmp
User
admin
Integrity Level
HIGH
Version:
Company
TeamViewer GmbH
Description
TeamViewer 14
Version
14.4.2669.0
Modules
Image
c:\program files\teamviewer\teamviewer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll

Registry activity

Total events
2419
Read events
1965
Write events
451
Delete events
3

Modification events

PID
Process
Operation
Key
Name
Value
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
failed_count
0
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
2
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
01000000
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
1
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
1
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome
UsageStatsInSample
0
3548
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
usagestats
0
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_installdate
0
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_enableddate
0
3548
chrome.exe
delete key
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
0
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
13207854401825000
3548
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
3548
chrome.exe
delete key
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
aapocclcgogkmnckokdopfmhonfmgoek
AD7C1D5FAC6E63C30552E14161CDBD4845278777E35E0BFAE9777BDED2A2B4E0
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ahfgeienlihckogmohjhadlkjgocpleb
15B1C3FE35F29528448F36A72A4DFBC58A8083C7190559D25865779166D220A2
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
aohghmighlieiainnegkcijnfilokake
647315E02AFCF8E459A42158EC73600239ED5D258675CD321229288FB5EFF63E
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
apdfllckaahabafndbhieahigkjlhalf
EE9DF26626BD917D2B5C18B8EB48B8130B494EDC68E651EB35899944A01DF84C
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
blpcfgokakmgnkcojhhkbfbldkacnbeo
D1A249F4831A04A4F4DCC95DA04FD48355AE0721284F472DF7277D3333EB1EBC
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
felcaaldnbdncclmgdcncolpebgiejap
3905A02FD7B8A879DF54276E16C6CE6F1F339E46C43E93BC14D726261E388280
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gfdkimpbcpahaombhbimeihdjnejgicl
D6B079666F209503A09486C70AC09307652A0F7F783166A999B27C99D0DA79E2
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ghbmnnjooekpmoecnnnilnnbdlolhkhi
0A11868E526A3043A2928D8A161F35A7C5BE8DD31ED63673EAAE8AC3FEA5AA13
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
00175B8120231631976CA8B862A3416996C9373BA3D289F0619DDA992973DDFA
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mfehgcgbbipciphmccgaenjidiccnmng
63355C14E8C7DF9A075F2EDDEA6F2807DC8166B83F96F4C975B9B6554C6324D7
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mhjfbmdgcfjbbpaeojofohoefgiehjai
0E265BFED6F1C7D5F0A9BD790C50BB30E78E959631D51EEBB8BB0DE73E65763C
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
04A45240BDA55E8777FA04357712CA6DD942253A21323E4C7D3CCF769B34BFED
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
5D58C2FED93EFDED578B006CB02BBB8DEC329128E2D098172E1316CDD15254DC
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
5563AB682CA6A0C26A556EBB7F35E0DBFC59DB6FCBE27122171B00B8CBBC8CE7
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pjkljhegncpnkpknbcohdijeoejaedia
442205BF2B9940D2F770C5BD29C6ABD54087A538474B6DDE0F786ACCD5B4A9FE
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pkedcjkdefgpdelpbcmbmeomcjbeemfm
9DB5BF57B7BBD2D9DD073B5FEB11053711E766965D75E19E21AC698BB0C41DEF
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000078000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
1C00000001000000E30707000300110010001B000B00CA0100000000
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
1C00000001000000E30707000300110010001B000B00CC0100000000
3548
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pkedcjkdefgpdelpbcmbmeomcjbeemfm
F873710E51957C12574469A2FA526E012184DD4855C924FF404FB881BCEBB222
3352
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
3548-13207854400965625
259
860
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
3808
TeamViewer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D5883D5C-5456-4BF9-844A-3F8C5E61AF9F}\1.2
TeamViewer
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D5883D5C-5456-4BF9-844A-3F8C5E61AF9F}\1.2\FLAGS
0
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D5883D5C-5456-4BF9-844A-3F8C5E61AF9F}\1.2\0\win32
C:\Program Files\TeamViewer\TeamViewer.exe
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D5883D5C-5456-4BF9-844A-3F8C5E61AF9F}\1.2\HELPDIR
C:\Program Files\TeamViewer
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A20E949F-5456-4A49-BE51-88077E13F793}
ITvMachineSettings
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A20E949F-5456-4A49-BE51-88077E13F793}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A20E949F-5456-4A49-BE51-88077E13F793}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A20E949F-5456-4A49-BE51-88077E13F793}\TypeLib
{D5883D5C-5456-4BF9-844A-3F8C5E61AF9F}
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A20E949F-5456-4A49-BE51-88077E13F793}\TypeLib
Version
1.2
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DB86189D-5456-4B7B-B5AB-419653E156DD}
ITvUserSettings
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DB86189D-5456-4B7B-B5AB-419653E156DD}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DB86189D-5456-4B7B-B5AB-419653E156DD}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DB86189D-5456-4B7B-B5AB-419653E156DD}\TypeLib
{D5883D5C-5456-4BF9-844A-3F8C5E61AF9F}
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DB86189D-5456-4B7B-B5AB-419653E156DD}\TypeLib
Version
1.2
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D399478A-5456-4112-B963-38E6C8AA1217}
ITvAddress
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D399478A-5456-4112-B963-38E6C8AA1217}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D399478A-5456-4112-B963-38E6C8AA1217}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D399478A-5456-4112-B963-38E6C8AA1217}\TypeLib
{D5883D5C-5456-4BF9-844A-3F8C5E61AF9F}
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D399478A-5456-4112-B963-38E6C8AA1217}\TypeLib
Version
1.2
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BF93CDAB-5456-4611-AE2C-6F50A41564C1}
ITvVersion
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BF93CDAB-5456-4611-AE2C-6F50A41564C1}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BF93CDAB-5456-4611-AE2C-6F50A41564C1}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BF93CDAB-5456-4611-AE2C-6F50A41564C1}\TypeLib
{D5883D5C-5456-4BF9-844A-3F8C5E61AF9F}
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BF93CDAB-5456-4611-AE2C-6F50A41564C1}\TypeLib
Version
1.2
3808
TeamViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F274CC23-5456-42B2-AC7A-5C5EA0D6EFBC}
ITvSession
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
UserSID
S-1-5-21-1302019708-1500728564-335382590-1000
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
0
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
RegEntries
0
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
InstallDir
C:\Program Files\TeamViewer
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
UserRegProfiles
1
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE0
RMVDIR:C:\Program Files\TeamViewer
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
1
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE1
DELETE:C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\TeamViewer.lnk
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
2
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE2
DELETE:C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\TeamViewer.lnk
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
3
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE3
DELETE:C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo\TeamViewer.lnk
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
4
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE4
RMVDIR:C:\Program Files\TeamViewer\x86
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
5
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE5
RMVDIR:C:\Program Files\TeamViewer\outlook
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
6
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE6
RMVDIR:C:\Program Files\TeamViewer\Printer
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
7
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE7
RMVDIR:C:\Program Files\TeamViewer\Printer\x86
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
8
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE8
RENSRC:C:\Program Files\TeamViewer\CopyRights_DE.txt
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
9
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE9
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\CopyRights_DE.txt
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
10
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE10
RENSRC:C:\Program Files\TeamViewer\CopyRights_EN.txt
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
11
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE11
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\CopyRights_EN.txt
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
12
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE12
RENSRC:C:\Program Files\TeamViewer\Lizenz_TeamViewer_DE_unicode.txt
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
13
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE13
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\Lizenz_TeamViewer_DE_unicode.txt
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
14
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE14
RENSRC:C:\Program Files\TeamViewer\Lizenz_TeamViewer_EN_unicode.txt
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
15
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE15
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\Lizenz_TeamViewer_EN_unicode.txt
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
16
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE16
RENSRC:C:\Program Files\TeamViewer\TeamViewer.exe
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
17
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE17
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer.exe
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
18
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE18
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Desktop.exe
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
19
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE19
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Desktop.exe
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
20
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE20
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Service.exe
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
21
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE21
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Service.exe
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
22
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE22
RENSRC:C:\Program Files\TeamViewer\uninstall.exe
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
23
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE23
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\uninstall.exe
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
24
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE24
RENSRC:C:\Program Files\TeamViewer\TeamViewer_StaticRes.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
25
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE25
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_StaticRes.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
26
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE26
RENSRC:C:\Program Files\TeamViewer\tv_w32.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
27
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE27
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\tv_w32.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
28
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE28
RENSRC:C:\Program Files\TeamViewer\tv_w32.exe
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
29
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE29
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\tv_w32.exe
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
30
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE30
RENSRC:C:\Program Files\TeamViewer\tv_x64.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
31
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE31
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\tv_x64.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
32
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE32
RENSRC:C:\Program Files\TeamViewer\tv_x64.exe
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
33
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE33
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\tv_x64.exe
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
34
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE34
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Note.exe
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
35
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE35
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Note.exe
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
36
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE36
RENSRC:C:\Program Files\TeamViewer\outlook\TeamViewerMeetingAddIn.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
37
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE37
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\outlook\TeamViewerMeetingAddIn.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
38
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE38
RENSRC:C:\Program Files\TeamViewer\outlook\ManagedAggregator.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
39
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE39
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\outlook\ManagedAggregator.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
40
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE40
RENSRC:C:\Program Files\TeamViewer\outlook\TeamViewerMeetingAddinShim.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
41
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE41
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\outlook\TeamViewerMeetingAddinShim.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
42
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE42
RENSRC:C:\Program Files\TeamViewer\outlook\TeamViewerMeetingAddinShim64.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
43
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE43
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\outlook\TeamViewerMeetingAddinShim64.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
44
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE44
RENSRC:C:\Program Files\TeamViewer\teamviewer14.otf
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
45
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE45
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\teamviewer14.otf
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
46
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE46
RENSRC:C:\Program Files\TeamViewer\Printer\teamviewer_xpsdriverfilter.cat
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
47
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE47
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\Printer\teamviewer_xpsdriverfilter.cat
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
48
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE48
RENSRC:C:\Program Files\TeamViewer\Printer\TeamViewer_XPSDriverFilter.gpd
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
49
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE49
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\Printer\TeamViewer_XPSDriverFilter.gpd
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
50
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE50
RENSRC:C:\Program Files\TeamViewer\Printer\TeamViewer_XPSDriverFilter.inf
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
51
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE51
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\Printer\TeamViewer_XPSDriverFilter.inf
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
52
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE52
RENSRC:C:\Program Files\TeamViewer\Printer\TeamViewer_XPSDriverFilter-manifest.ini
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
53
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE53
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\Printer\TeamViewer_XPSDriverFilter-manifest.ini
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
54
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE54
RENSRC:C:\Program Files\TeamViewer\Printer\TeamViewer_XPSDriverFilter-PipelineConfig.xml
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
55
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE55
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\Printer\TeamViewer_XPSDriverFilter-PipelineConfig.xml
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
56
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE56
RENSRC:C:\Program Files\TeamViewer\x86\TeamViewerVPN.cat
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
57
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE57
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\x86\TeamViewerVPN.cat
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
58
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE58
RENSRC:C:\Program Files\TeamViewer\x86\TeamViewerVPN.inf
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
59
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE59
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\x86\TeamViewerVPN.inf
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
60
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE60
RENSRC:C:\Program Files\TeamViewer\x86\TeamViewerVPN.sy_
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
61
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE61
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\x86\TeamViewerVPN.sy_
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
62
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE62
RENSRC:C:\Program Files\TeamViewer\x86\TVMonitor.cat
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
63
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE63
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\x86\TVMonitor.cat
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
64
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE64
RENSRC:C:\Program Files\TeamViewer\x86\TVMonitor.inf
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
65
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE65
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\x86\TVMonitor.inf
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
66
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE66
RENSRC:C:\Program Files\TeamViewer\x86\TVMonitor.sy_
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
67
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE67
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\x86\TVMonitor.sy_
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
68
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE68
RENSRC:C:\Program Files\TeamViewer\Printer\x86\TeamViewer_XPSDriverFilter.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
69
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE69
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\Printer\x86\TeamViewer_XPSDriverFilter.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
70
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE70
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_en.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
71
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE71
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_en.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
72
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE72
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_de.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
73
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE73
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_de.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
74
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE74
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_es.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
75
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE75
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_es.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
76
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE76
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_da.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
77
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE77
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_da.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
78
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE78
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_fr.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
79
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE79
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_fr.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
80
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE80
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_it.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
81
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE81
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_it.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
82
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE82
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_nl.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
83
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE83
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_nl.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
84
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE84
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_pt.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
85
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE85
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_pt.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
86
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE86
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_sv.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
87
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE87
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_sv.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
88
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE88
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_fi.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
89
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE89
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_fi.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
90
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE90
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_no.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
91
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE91
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_no.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
92
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE92
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_ja.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
93
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE93
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_ja.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
94
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE94
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_ru.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
95
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE95
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_ru.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
96
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE96
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_ko.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
97
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE97
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_ko.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
98
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE98
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_cs.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
99
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE99
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_cs.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
100
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE100
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_ar.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
101
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE101
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_ar.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
102
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE102
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_zhCN.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
103
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE103
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_zhCN.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
104
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE104
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_pl.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
105
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE105
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_pl.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
106
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE106
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_tr.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
107
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE107
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_tr.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
108
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE108
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_bg.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
109
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE109
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_bg.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
110
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE110
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_el.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
111
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE111
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_el.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
112
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE112
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_he.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
113
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE113
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_he.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
114
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE114
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_hr.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
115
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE115
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_hr.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
116
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE116
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_hu.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
117
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE117
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_hu.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
118
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE118
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_id.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
119
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE119
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_id.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
120
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE120
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_lt.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
121
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE121
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_lt.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
122
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE122
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_ro.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
123
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE123
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_ro.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
124
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE124
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_sk.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
125
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE125
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_sk.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
126
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE126
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_sr.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
127
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE127
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_sr.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
128
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE128
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_th.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
129
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE129
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_th.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
130
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE130
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_uk.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
131
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE131
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_uk.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
132
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE132
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_vi.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
133
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE133
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_vi.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
134
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE134
RENSRC:C:\Program Files\TeamViewer\TeamViewer_Resource_zhTW.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
135
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE135
RENDST:C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Resource_zhTW.dll
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
136
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE136
RENSRC:C:\Program Files\TeamViewer\License.txt
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
137
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE137
RENDST:C:\Program Files\TeamViewer\Lizenz_TeamViewer_EN_unicode.txt
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
138
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE138
RENSRC:C:\Program Files\TeamViewer\CopyRights.txt
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
139
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE139
RENDST:C:\Program Files\TeamViewer\CopyRights_EN.txt
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
140
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE140
RESFIL:C:\Program Files\TeamViewer\Lizenz_TeamViewer_DE_unicode.txt
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
141
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE141
RESFIL:C:\Program Files\TeamViewer\CopyRights_DE.txt
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
142
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE142
RENSRC:C:\Program Files\TeamViewer\x86\teamviewervpn.sys
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
143
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE143
RENDST:C:\Program Files\TeamViewer\x86\teamviewervpn.sy_
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
144
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE144
DELETE:C:\Users\Public\Desktop\TeamViewer 14.lnk
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
145
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE145
DELETE:C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 14.lnk
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
146
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE146
SRVNAM:TeamViewer
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
147
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE147
RMVSRV:C:\Program Files\TeamViewer\TeamViewer_Service.exe
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
148
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FE148
RMVAPI:C:\Program Files\TeamViewer\TeamViewer.exe
1864
TeamViewer_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\TVInstallTemp\RestoreInfo
FileEntries
149
3272
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
3272
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
@sendmail.dll,-21
Desktop (create shortcut)
3272
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
@zipfldr.dll,-10148
Compressed (zipped) folder
3272
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
@sendmail.dll,-4
Mail recipient
3272
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
@C:\Windows\system32\FXSRESM.dll,-120
Fax recipient
3536
TeamViewer_Service.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
3536
TeamViewer_Service.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A
Blob
0F00000001000000140000000F6AAD4C3FE04619CDC8B2BD655AA1A26042E6500B000000010000005400000053007400610072006600690065006C006400200043006C00610073007300200032002000430065007200740069006600690063006100740069006F006E00200041007500740068006F007200690074007900000053000000010000004800000030463021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C03021060B6086480186FD6E0107170330123010060A2B0601040182373C0101030200C009000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B060105050703036200000001000000200000001465FA205397B876FAA6F0A9958E5590E40FCC7FAA4FB7C2C8677521FB5FB658140000000100000014000000BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E71D000000010000001000000090C4F4233B006B7BFAA6ADCD8F577D77030000000100000014000000AD7E1C28B064EF8F6003402014C3D0E3370EB58A2000000001000000130400003082040F308202F7A003020102020100300D06092A864886F70D01010505003068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F72697479301E170D3034303632393137333931365A170D3334303632393137333931365A3068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F7269747930820120300D06092A864886F70D01010105000382010D00308201080282010100B732C8FEE971A60485AD0C1164DFCE4DEFC80318873FA1ABFB3CA69FF0C3A1DAD4D86E2B5390FB24A43E84F09EE85FECE52744F528A63F7BDEE02AF0C8AF532F9ECA0501931E8F661C39A74DFA5AB673042566EB777FE759C64A99251454EB26C7F37F19D530708FAFB0462AFFADEB29EDD79FAA0487A3D4F989A5345FDB43918236D9663CB1B8B982FD9C3A3E10C83BEF0665667A9B19183DFF71513C302E5FBE3D7773B25D066CC323569A2B8526921CA702B3E43F0DAF087982B8363DEA9CD335B3BC69CAF5CC9DE8FD648D1780336E5E4A5D99C91E87B49D1AC0D56E1335235EDF9B5F3DEFD6F776C2EA3EBB780D1C42676B04D8F8D6DA6F8BF244A001AB020103A381C53081C2301D0603551D0E04160414BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E73081920603551D2304818A3081878014BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E7A16CA46A3068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F72697479820100300C0603551D13040530030101FF300D06092A864886F70D01010505000382010100059D3F889DD1C91A55A1AC69F3F359DA9B01871A4F57A9A179092ADBF72FB21ECCC75E6AD88387A197EF49353E7706415862BF8E58B80A673FECB3DD21661FC954FA72CC3D4C40D881AF779E837ABBA2C7F534178ED91140F4FC2C2A4D157FA7625D2E25D3000B201A1D68F917B8F4BD8BED2859DD4D168B1783C8B265C72D7AA5AABC53866DDD57A4CAF820410B68F0F4FB74BE565D7A79F5F91D85E32D95BEF5719043CC8D1F9A000A8729E95522580023EAE31243295B4708DD8C416A6506A8E521AA41B4952195B97DD134AB13D6ADBCDCE23D39CDBD3E7570A1185903C922B48F9CD55E2AD7A5B6D40A6DF8B74011469A1F790E62BF0F97ECE02F1F1794
3536
TeamViewer_Service.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A
Blob
190000000100000010000000FD960962AC6938E0D4B0769AA1A64E26030000000100000014000000AD7E1C28B064EF8F6003402014C3D0E3370EB58A1D000000010000001000000090C4F4233B006B7BFAA6ADCD8F577D77140000000100000014000000BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E76200000001000000200000001465FA205397B876FAA6F0A9958E5590E40FCC7FAA4FB7C2C8677521FB5FB65809000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030353000000010000004800000030463021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C03021060B6086480186FD6E0107170330123010060A2B0601040182373C0101030200C00B000000010000005400000053007400610072006600690065006C006400200043006C00610073007300200032002000430065007200740069006600690063006100740069006F006E00200041007500740068006F00720069007400790000000F00000001000000140000000F6AAD4C3FE04619CDC8B2BD655AA1A26042E6502000000001000000130400003082040F308202F7A003020102020100300D06092A864886F70D01010505003068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F72697479301E170D3034303632393137333931365A170D3334303632393137333931365A3068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F7269747930820120300D06092A864886F70D01010105000382010D00308201080282010100B732C8FEE971A60485AD0C1164DFCE4DEFC80318873FA1ABFB3CA69FF0C3A1DAD4D86E2B5390FB24A43E84F09EE85FECE52744F528A63F7BDEE02AF0C8AF532F9ECA0501931E8F661C39A74DFA5AB673042566EB777FE759C64A99251454EB26C7F37F19D530708FAFB0462AFFADEB29EDD79FAA0487A3D4F989A5345FDB43918236D9663CB1B8B982FD9C3A3E10C83BEF0665667A9B19183DFF71513C302E5FBE3D7773B25D066CC323569A2B8526921CA702B3E43F0DAF087982B8363DEA9CD335B3BC69CAF5CC9DE8FD648D1780336E5E4A5D99C91E87B49D1AC0D56E1335235EDF9B5F3DEFD6F776C2EA3EBB780D1C42676B04D8F8D6DA6F8BF244A001AB020103A381C53081C2301D0603551D0E04160414BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E73081920603551D2304818A3081878014BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E7A16CA46A3068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F72697479820100300C0603551D13040530030101FF300D06092A864886F70D01010505000382010100059D3F889DD1C91A55A1AC69F3F359DA9B01871A4F57A9A179092ADBF72FB21ECCC75E6AD88387A197EF49353E7706415862BF8E58B80A673FECB3DD21661FC954FA72CC3D4C40D881AF779E837ABBA2C7F534178ED91140F4FC2C2A4D157FA7625D2E25D3000B201A1D68F917B8F4BD8BED2859DD4D168B1783C8B265C72D7AA5AABC53866DDD57A4CAF820410B68F0F4FB74BE565D7A79F5F91D85E32D95BEF5719043CC8D1F9A000A8729E95522580023EAE31243295B4708DD8C416A6506A8E521AA41B4952195B97DD134AB13D6ADBCDCE23D39CDBD3E7570A1185903C922B48F9CD55E2AD7A5B6D40A6DF8B74011469A1F790E62BF0F97ECE02F1F1794

Files activity

Executable files
13
Suspicious files
129
Text files
207
Unknown types
17

Dropped files

PID
Process
Filename
Type
1864
TeamViewer_.exe
C:\Users\admin\AppData\Local\Temp\nsg8B84.tmp\nsCB7E.tmp
executable
MD5: 483a9b183523e7e2015ddec730e59f7b
SHA256: aef58b24cc84a798101f9603c986161b93d8bc3c84de4d48050e10f50ff3fb27
1864
TeamViewer_.exe
C:\Program Files\TeamViewer\x86\teamviewervpn.sys
executable
MD5: 9101fffcfccd1a30e870a5b8a9091b10
SHA256: 58aab0f6ff78fd0ecdd8d9da1b6852e9e57e3daa39489abddba106ece0b3bca7
1864
TeamViewer_.exe
C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_StaticRes.dll
executable
MD5: 728748c9ca37bbaa47a98ac88f5a759d
SHA256: 45a7c967d5165a99e3d88be444927d0bafc5de37cbc5e3c6c8ef7e7fbc962b6b
1864
TeamViewer_.exe
C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Note.exe
executable
MD5: eb99df0c65510008a689881aaa62996d
SHA256: 2b13ba21da6313a2ee43a2dc803e25d5016cfeff604564590189f344a82f96bf
1864
TeamViewer_.exe
C:\Program Files\TeamViewer\TeamViewer_Resource_da.dll
executable
MD5: db1ed95e765d0c5a505c715dd88171e3
SHA256: e42f489c27c2fba6c86ee315a12290db217776614611c2cd84248258df12869f
3548
chrome.exe
C:\Users\admin\Downloads\TeamViewer_Setup.exe
executable
MD5: 673d583d7c195cf565bb8cb0ced65f56
SHA256: df26627cc29716b65a3ed72f78d59808244f9bc4ad2624657ddbee79d2baa422
860
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000028
executable
MD5: 673d583d7c195cf565bb8cb0ced65f56
SHA256: df26627cc29716b65a3ed72f78d59808244f9bc4ad2624657ddbee79d2baa422
1864
TeamViewer_.exe
C:\Users\admin\AppData\Local\Temp\nsg8B84.tmp\nsBBED.tmp
executable
MD5: 483a9b183523e7e2015ddec730e59f7b
SHA256: aef58b24cc84a798101f9603c986161b93d8bc3c84de4d48050e10f50ff3fb27
3548
chrome.exe
C:\Users\admin\Downloads\Unconfirmed 155483.crdownload
executable
MD5: 53de7d36563f091affb3c36a4829dc7a
SHA256: 016215287f80b67215fd3ac9542b19b95a7d456e87698171aeb8ab38a14c9c29
1864
TeamViewer_.exe
C:\Program Files\TeamViewer\tv_w32.exe
executable
MD5: c833f80e7e06d99c48d7a579edadf245
SHA256: 3bd36b9b04ba3aa658219c386be1929370e3b9c4f1abf1f5fab31373d2ae3b5e
1864
TeamViewer_.exe
C:\Program Files\TeamViewer\TeamViewer_Resource_ro.dll
executable
MD5: d289979dccf1baf82f60723b1125b5f3
SHA256: aad6bf37814de8847e9bc7207ea0e561cc758c8be58aaccdc134c9d6c18890a2
1864
TeamViewer_.exe
C:\Program Files\TeamViewer\TeamViewer_Resource_sk.dll
executable
MD5: 7152c36817abc6dcaba165bfa3178bb9
SHA256: 5f66ebf116a1fd4b5373638bbf0c349148c426893cd9ff120c114ffa0b686e3c
1864
TeamViewer_.exe
C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer_Desktop.exe
executable
MD5: d16f31ade685d443c47f789c74d4834d
SHA256: 5ff8652b1e33f8e944a0117eb5dd74ee4314b127779f12ecdc497bd1ad3689dc
1864
TeamViewer_.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 14.lnk
lnk
MD5: 555d1586ee721f12c20ef1cf013eb169
SHA256: 612f232f2e340e6a89ff125e43e0c10a715c67bbd021765101a0ec075a1a86fb
1864
TeamViewer_.exe
C:\Users\Public\Desktop\TeamViewer 14.lnk
lnk
MD5: 3c8f475068d99f2ccf058f8ecf714853
SHA256: bdb41a4706697b09571316e7efdf4495edfddbf3e8fa756629835407b6f5dd97
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\37b7463b-52e9-400b-9f58-42142d9f845e.tmp
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RFebed7.TMP
text
MD5: b68b679128d668b5b7d03c610306973b
SHA256: cf5e2a854ecdec17f120b171466f928065cb8f67f49d5356c4a59530b4838f50
1864
TeamViewer_.exe
C:\Program Files\TeamViewer\TVExtractTemp\TeamViewer.exe
––
MD5:  ––
SHA256:  ––
1864
TeamViewer_.exe
C:\Program Files\TeamViewer\TVExtractTemp\tvfiles.7z
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\337ab716-ad25-4e18-8f78-c8033fe458a4.tmp
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\df06e209-bb35-4b2f-9ba2-8d1ca6829079.tmp
––
MD5:  ––
SHA256:  ––
800
TeamViewer_.exe
C:\Users\admin\AppData\Local\Temp\nsp7B67.tmp\start_unicode.ini
text
MD5: 5f658c02413d43e7e5303ef258a8575a
SHA256: a4abad61d36ad2f88bbf7d91c797cc5c7b693a7876e19661f7a2653133cbc999
3884
TeamViewer_Setup.exe
C:\Users\admin\AppData\Local\Temp\nse781B.tmp\TvGetVersion.dll
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\DownloadMetadata
binary
MD5: 5c31d05f3305a1adedbbbc2e49677ac2
SHA256: 3ac77f4ced5fd162899e54386bb5b3ae6b962bfea1a51a1c95e5a92461d4ba01
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\a1cf4e57-d36c-4207-85a4-65cd859ef228.tmp
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\Downloads\TeamViewer_Setup.exe:Zone.Identifier
text
MD5: fbccf14d504b7b2dbcb5a5bda75bd93b
SHA256: eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\6d8cedfc-d754-4eab-92b2-c5cc7a9edeaa.tmp
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\Downloads\Unconfirmed 155483.crdownload
––
MD5:  ––
SHA256:  ––
340
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma
binary
MD5: 9543068b6751e1f3e11f91d72ee78d95
SHA256: d060ad21ae6e04cb58668caa52adfca573e018102cc07554d2ed3eae11ab7785
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7519.422.0.3_0\_metadata\computed_hashes.json
text
MD5: 60b11a4c514e82b763fda6c8bca188b8
SHA256: cf23c3ec4b986391e7ada2d4940832a27ec6336a434f75ddf818b5d00e35604d
860
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RFe50cb.TMP
text
MD5: ae8231f9641a54db9f46766a03302ec8
SHA256: 3dc28733405407328e15daead89acf9818d1d62fe069d6f2a8eacbf1c3f8c5c5
860
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity
text
MD5: ae8231f9641a54db9f46766a03302ec8
SHA256: 3dc28733405407328e15daead89acf9818d1d62fe069d6f2a8eacbf1c3f8c5c5
860
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\21e46ecd-4004-43c1-9a0a-5ce1201f24c6.tmp
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RFe50ac.TMP
text
MD5: 59e3eb97c53fabe5817a77a2595d4ecd
SHA256: 217ebb0ed07c4a8543b142c8ab12b5d01bcf9fba342a4de3ace4cac11021bd50
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 59e3eb97c53fabe5817a77a2595d4ecd
SHA256: 217ebb0ed07c4a8543b142c8ab12b5d01bcf9fba342a4de3ace4cac11021bd50
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\3ed7c05e-f435-40e4-a3d9-539f06b84a15.tmp
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000005.ldb
binary
MD5: f9c535b95b3823de1fcee726e5748257
SHA256: c21ca87e66d09bd798e2686409e26064252b17ca3af9904352d27f996b20d8a8
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: 0e67af1e444a95905534a29d40d60614
SHA256: 0d5003cc4dc795686dc1134a1d97320f2f61d1e83fe6c932f1b24f36b5926aac
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RFe4b3d.TMP
text
MD5: 0e67af1e444a95905534a29d40d60614
SHA256: 0d5003cc4dc795686dc1134a1d97320f2f61d1e83fe6c932f1b24f36b5926aac
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\0faea880-5a9b-4c40-9c0a-22f5597138e6.tmp
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
text
MD5: 217f919db8022821f00c1cd30a1259b1
SHA256: 81f67f3ec0ea3c6430d66fb017772098de8b385a979df70c271df2068ecaa2ab
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences~RFe41c7.TMP
text
MD5: 217f919db8022821f00c1cd30a1259b1
SHA256: 81f67f3ec0ea3c6430d66fb017772098de8b385a979df70c271df2068ecaa2ab
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\bc30b63a-d377-418a-a0ad-ae6339dc5449.tmp
––
MD5:  ––
SHA256:  ––
1864
TeamViewer_.exe
C:\Program Files\TeamViewer\Printer\TeamViewer_XPSDriverFilter.inf
binary
MD5: 4eb1623eba2343ef10c4d1d72e74c61b
SHA256: 517f468834395d0c4ea0240a2a0571cf763b378d0cf8546908c5a538399f8395
3548
chrome.exe
C:\Users\admin\Downloads\acb82fee-9794-44e6-8096-8078629fbd20.tmp
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\8c7c41d638974bcc_0
binary
MD5: 94695900964effeda8b354d23dcab0a3
SHA256: 1cd8741ddb772a75c179deed225bc749e25e50c5e061db81e1bbcbd99a7ba63e
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\CURRENT
text
MD5: 206702161f94c5cd39fadd03f4014d98
SHA256: 1005a525006f148c86efcbfb36c6eac091b311532448010f70f7de9a68007167
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\CURRENT~RFe3b8e.TMP
text
MD5: 206702161f94c5cd39fadd03f4014d98
SHA256: 1005a525006f148c86efcbfb36c6eac091b311532448010f70f7de9a68007167
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\000002.dbtmp
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\000001.dbtmp
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\MANIFEST-000001
binary
MD5: 5af87dfd673ba2115e2fcf5cfdb727ab
SHA256: f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\fe046203ae1650c7_0
binary
MD5: 1c5afbefb232a4a49239bbc5eac16b32
SHA256: 9fc16a19dd8000db893a77e721ce695dbc0a5c15b6d217fe70a93411eddf97a1
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\854fe90140c6269e_0
binary
MD5: 0bc07f70e2c4b7f42268691b437c8a9f
SHA256: 8c9678b1d731dde3331114807eb349caf643dc1c9184a9aeb6c6d0a8c4f697d2
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\916359fcd6391b9c_0
binary
MD5: fc5dfcbb251823db46442ef4dbf45833
SHA256: ddf9f4b625ddd72d0d3f36ad8bc466d7a5bae4a3ac5864a00004c5a79b7af4ce
860
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000027
image
MD5: 2f8b7a36daa83c87feda52be336f3e5e
SHA256: 6b702e0285c351556200c52f83b838a8821f0dbe7a01a6cba79fb8a796ccb6a4
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7519.422.0.3_0
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\Temp\scoped_dir3548_24917\CRX_INSTALL
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\zh_TW\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\zh\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\tr\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\uk\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\vi\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\sw\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\th\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\ta\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\te\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\sv\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\sr\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\sl\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\sk\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\ru\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\ro\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\pt\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\nb\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\nl\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\pl\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\ms\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\ml\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\mr\messages.json
––
MD5:  ––
SHA256:  ––
3548
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir3548_12085\CRX_INSTALL\_locales\ko\messages.json
––
MD5:  ––
SHA256:  ––