rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,AcquireCredentialsHandleA
1096rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,AcquireCredentialsHandleA
2504rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,AcceptSecurityContext
2004rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,AcceptSecurityContext
2356rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,AcquireCredentialsHandleW
2108rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,AcquireCredentialsHandleW
2404rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,AddCredentialsA
2196rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,AddCredentialsA
2552rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,AddCredentialsW
2292rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,AddCredentialsW
2652rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,AddSecurityPackageA
2436rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,AddSecurityPackageA
2748rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,AddSecurityPackageW
2640rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,AddSecurityPackageW
2912rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,ApplyControlToken
2852rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,ApplyControlToken
3000rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,ChangeAccountPasswordA
524rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,ChangeAccountPasswordA
2288rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,ChangeAccountPasswordW
2324rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,ChangeAccountPasswordW
2476rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,CompleteAuthToken
2576rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,CompleteAuthToken
2792rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,CredMarshalTargetInfo
1940rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,CredMarshalTargetInfo
2712rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,CredUnmarshalTargetInfo
2084rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,CredUnmarshalTargetInfo
2472rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,DecryptMessage
3048rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,DecryptMessage
2136rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,DeleteSecurityContext
2884rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,DeleteSecurityContext
2392rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,DeleteSecurityPackageA
2212rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,DeleteSecurityPackageA
2776rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,DeleteSecurityPackageW
2600rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,DeleteSecurityPackageW
2864rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,EncryptMessage
2168rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,EncryptMessage
3240rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,EnumerateSecurityPackagesA
3152rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,EnumerateSecurityPackagesA
3316rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,EnumerateSecurityPackagesW
3308rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,EnumerateSecurityPackagesW
3448rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,ExportSecurityContext
3492rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,ExportSecurityContext
3624rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,FreeContextBuffer
3612rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,FreeContextBuffer
3820rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,FreeCredentialsHandle
3800rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,FreeCredentialsHandle
4012rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,GetSecurityUserInfo
4000rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,GetSecurityUserInfo
3348rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,GetUserNameExA
3148rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,GetUserNameExA
948rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,GetUserNameExW
3332rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,GetUserNameExW
3660rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,ImpersonateSecurityContext
3572rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,ImpersonateSecurityContext
3904rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,ImportSecurityContextA
3840rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,ImportSecurityContextA
3892rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,ImportSecurityContextW
3172rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,ImportSecurityContextW
3724rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,InitSecurityInterfaceA
3424rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,InitSecurityInterfaceA
3372rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,InitSecurityInterfaceW
3220rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,InitSecurityInterfaceW
3216rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,InitializeSecurityContextA
3024rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,InitializeSecurityContextA
4136rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,InitializeSecurityContextW
3872rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,InitializeSecurityContextW
4200rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LogonUserExExW
4048rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LogonUserExExW
4284rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaCallAuthenticationPackage
4272rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaCallAuthenticationPackage
4408rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaConnectUntrusted
4492rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaConnectUntrusted
4744rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaDeregisterLogonProcess
4592rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaDeregisterLogonProcess
4796rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaEnumerateLogonSessions
4732rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaEnumerateLogonSessions
4988rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaFreeReturnBuffer
4920rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaFreeReturnBuffer
4112rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaGetLogonSessionData
5084rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaGetLogonSessionData
3636rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaLogonUser
4300rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaLogonUser
4456rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaLookupAuthenticationPackage
4344rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaLookupAuthenticationPackage
4876rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaRegisterLogonProcess
4792rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaRegisterLogonProcess
3208rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaRegisterPolicyChangeNotification
5048rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaRegisterPolicyChangeNotification
4504rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaUnregisterPolicyChangeNotification
4232rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,LsaUnregisterPolicyChangeNotification
4772rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,MakeSignature
4660rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,MakeSignature
4320rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QueryContextAttributesA
5000rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QueryContextAttributesA
1044rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QueryContextAttributesExW
4956rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QueryContextAttributesExW
4608rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QueryContextAttributesExA
4468rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QueryContextAttributesExA
4964rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QueryContextAttributesW
4560rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QueryContextAttributesW
1228rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QueryCredentialsAttributesA
4700rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QueryCredentialsAttributesA
5160rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QueryCredentialsAttributesExA
5136rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QueryCredentialsAttributesExA
5224rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QueryCredentialsAttributesExW
5344rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QueryCredentialsAttributesExW
5536rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QueryCredentialsAttributesW
5448rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QueryCredentialsAttributesW
5628rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QuerySecurityContextToken
5608rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QuerySecurityContextToken
5832rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QuerySecurityPackageInfoA
5780rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QuerySecurityPackageInfoA
5988rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QuerySecurityPackageInfoW
5920rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,QuerySecurityPackageInfoW
5200rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,RevertSecurityContext
6072rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,RevertSecurityContext
5324rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslAcceptSecurityContext
4176rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslAcceptSecurityContext
5432rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslEnumerateProfilesA
5376rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslEnumerateProfilesA
5816rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslEnumerateProfilesW
5668rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslEnumerateProfilesW
6012rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslGetContextOption
5848rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslGetContextOption
6096rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslGetProfilePackageA
5128rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslGetProfilePackageA
5472rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslGetProfilePackageW
5368rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslGetProfilePackageW
5980rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslIdentifyPackageA
5696rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslIdentifyPackageA
5568rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslIdentifyPackageW
6120rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslIdentifyPackageW
5776rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslInitializeSecurityContextA
5676rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslInitializeSecurityContextA
5640rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslInitializeSecurityContextW
5240rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslInitializeSecurityContextW
5552rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslSetContextOption
2124rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SaslSetContextOption
5380rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sspicli.dll,SealMessage
6368