

Process created: C:\Windows \SysWOW64\ rundll32.e xe rundll3 2.exe C:\U sers\user\ Desktop\jv m.dll,?_7 ?$CppVtabl ConstantPo C:\Windows \System32\ loaddll32. Process created: C:\Windows \SysWOW64\ WerFault.e xe C:\Wind ows\SysWOW 64\WerFaul t.exe -u - p 4548 -s 724 Process created: C:\Windows \SysWOW64\ WerFault.e xe C:\Wind ows\SysWOW 64\WerFaul t.exe -u - p 6632 -s 724 Process created: C:\Windows \SysWOW64\ WerFault.e xe C:\Wind ows\SysWOW 64\WerFaul t.exe -u - p 6676 -s 724 Process created: C:\Windows \SysWOW64\ WerFault.e xe C:\Wind ows\SysWOW 64\WerFaul t.exe -u - p 6356 -s 724 Process created: C:\Windows \SysWOW64\ WerFault.e xe C:\Wind ows\SysWOW 64\WerFaul t.exe -u - p 6340 -s 728 Process created: C:\Windows \SysWOW64\ WerFault.e xe C:\Wind ows\SysWOW 64\WerFaul t.exe -u - p 7088 -s 724 Process created: C:\Windows \SysWOW64\ WerFault.e xe C:\Wind ows\SysWOW 64\WerFaul t.exe -u - p 7072 -s 724 Process created: C:\Windows \SysWOW64\ rundll32.e xe rundll3 2.exe "C:\ Users\user \Desktop\j vm.dll",? _7?$CppVta bleTesterA C:\Windows \SysWOW64\ rundll32.e xe Process created: C:\Windows \SysWOW64\ rundll32.e xe rundll3 2.exe "C:\ Users\user \Desktop\j vm.dll",? _7?$CppVta bleTesterA MirrorKlas C:\Windows \System32\ loaddll32. Process created: C:\Windows \SysWOW64\ rundll32.e xe rundll3 2.exe "C:\ Users\user \Desktop\j vm.dll",? _7?$CppVta bleTesterA ClassLoade C:\Windows \System32\ loaddll32.

Process created: C:\Windows \SysWOW64\ rundll32.e xe rundll3 2.exe "C:\ Users\user \Desktop\j vm.dll",? _7?$CppVta bleTesterA C:\Windows \System32\ loaddll32.

Process created: C:\Windows \SysWOW64\ WerFault.e xe C:\Wind ows\SysWOW 64\WerFaul t.exe -u - p 7008 -s 724 Source: C:\Windows \SysWOW64\ rundll32.e xe Process created: C:\Windows \SysWOW64\ WerFault.e xe C:\Wind ows\SysWOW 64\WerFaul t.exe -u - p 7020 -s 732 Process created: C:\Windows \SysWOW64\ rundll32.e xe rundll3 2.exe C:\U sers\user\ Desktop\jv m.dll,?_7 ?$CppVtabl InstanceKl C:\Windows \SysWOW64\ rundll32.e xe Process created: C:\Windows \SysWOW64\ rundll32.e xe rundll3 2.exe C:\U sers\user\ Desktop\jv m.dll,?_7 ?$CppVtabl InstanceCl assLoaderK C:\Windows \System32\ loaddll32. Process created: C:\Windows \SysWOW64\ rundll32.e xe rundll3 2.exe "C: \Users\use r\Desktop\ jvm.dll",# 1 Process created: C:\Windows \SysWOW64\ rundll32.e xe rundll3 2.exe C:\U sers\user\ Desktop\jv m.dll,?_7 ?$CppVtabl ConstantPo C:\Windows \SysWOW64\ cmd.exe Process created: C:\Windows \SysWOW64\ cmd.exe cm d.exe /C r undll32.ex e "C:\User s\user\Des ktop\jvm.d ll",#1 exe loaddl l32.exe "C :\Users\us er\Desktop \jvm.dll"

Process created: C:\Windows \System32\ loaddll32. Detected potential crypto function Source: C:\Windows \System32\ loaddll32.
