| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1620930641.266876 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
|
1620930646.736124 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
| section | .ndata |
| request | GET http://cdnrep.reimage.com/downloader_version.xml |
| request | GET http://cdnrep.reimageplus.com/rqz/ReimageRepair.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsj6723.tmp\inetc.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsj6723.tmp\nsExec.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\ReimageRepair.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsj6723.tmp\System.dll |
| file | C:\Program Files\Reimage\Reimage Repair\ReimageReminder.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsj6723.tmp\LogEx.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsj6723.tmp\stack.dll |
| file | C:\Program Files\Reimage\Reimage Repair\REI_SupportInfoTool.exe |
| file | C:\Program Files\Reimage\Reimage Repair\LZMA.EXE |
| file | C:\Program Files\Reimage\Reimage Repair\Reimage.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsj6723.tmp\xml.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsj6723.tmp\xml.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsj6723.tmp\System.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsj6723.tmp\nsExec.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsj6723.tmp\stack.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsj6723.tmp\LogEx.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\ReimageRepair.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsj6723.tmp\inetc.dll |
| wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process WHERE Caption = 'AVUPDATE.EXE' |
| wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process WHERE Caption = 'REIMAGE.EXE' |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1620930661.063876 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |