Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_00401355 NtAllocateVirtualMemory,NtMapViewOfSection,NtMapViewOfSection,NtMapViewOfSection,NtMapViewOfSection,Sleep,Sleep,NtTerminateProcess, | 0_2_00401355 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_004013DD NtAllocateVirtualMemory,NtMapViewOfSection,NtMapViewOfSection,NtMapViewOfSection,NtMapViewOfSection,Sleep,Sleep,NtTerminateProcess, | 0_2_004013DD |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_0040135C NtAllocateVirtualMemory, | 0_2_0040135C |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_00401367 NtAllocateVirtualMemory, | 0_2_00401367 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_0040186D Sleep,Sleep,NtTerminateProcess, | 0_2_0040186D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_00401878 Sleep,Sleep,NtTerminateProcess, | 0_2_00401878 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_00401E02 NtQuerySystemInformation,NtOpenKey,NtEnumerateKey, | 0_2_00401E02 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_00401408 NtAllocateVirtualMemory, | 0_2_00401408 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_004013E8 NtAllocateVirtualMemory, | 0_2_004013E8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_004013F3 NtAllocateVirtualMemory, | 0_2_004013F3 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_00401883 Sleep,Sleep,NtTerminateProcess, | 0_2_00401883 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_00401386 NtAllocateVirtualMemory, | 0_2_00401386 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22C0A NtQueryInformationProcess,LdrInitializeThunk, | 0_2_6CD22C0A |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22DF0 ZwQuerySystemInformation,LdrInitializeThunk, | 0_2_6CD22DF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22DB0 ZwEnumerateKey,LdrInitializeThunk, | 0_2_6CD22DB0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22D10 ZwMapViewOfSection,LdrInitializeThunk, | 0_2_6CD22D10 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22E50 ZwDuplicateObject,LdrInitializeThunk, | 0_2_6CD22E50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22F30 ZwCreateSection,LdrInitializeThunk, | 0_2_6CD22F30 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22BF0 ZwAllocateVirtualMemory,LdrInitializeThunk, | 0_2_6CD22BF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22B90 ZwOpenKey,LdrInitializeThunk, | 0_2_6CD22B90 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22CD0 ZwOpenThreadToken, | 0_2_6CD22CD0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD38CD0 RtlRaiseException,RtlCaptureContext,ZwRaiseException,RtlRaiseStatus, | 0_2_6CD38CD0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDCCC8 memset,RtlInitUnicodeString,ZwOpenKey,RtlInitUnicodeString,ZwClose,RtlFreeHeap,RtlInitUnicodeString,RtlCultureNameToLCID,RtlInitUnicodeString,RtlCultureNameToLCID, | 0_2_6CCDCCC8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD7ACD0 RtlQueryCriticalSectionOwner,ZwReadVirtualMemory,RtlQueryCriticalSectionOwner, | 0_2_6CD7ACD0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22CC0 ZwQueryVirtualMemory, | 0_2_6CD22CC0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB0CC0 EtwRegisterSecurityProvider,ZwTraceControl,RtlNtStatusToDosError,RtlSetLastWin32Error, | 0_2_6CDB0CC0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6ACC8 ZwClose,ZwUnmapViewOfSection,ZwClose,ZwClose,ZwClose,ZwClose, | 0_2_6CD6ACC8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD12CF0 memcpy,RtlGetNtSystemRoot,RtlInitUnicodeString,memcpy,ZwOpenKey,ZwClose,ZwEnumerateKey,DbgPrintEx,DbgPrintEx,DbgPrintEx, | 0_2_6CD12CF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22CF0 ZwOpenProcess, | 0_2_6CD22CF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22CE0 ZwQueryInformationThread, | 0_2_6CD22CE0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD8C8D RtlFreeHeap,ZwSetEvent,ZwAlertThreadByThreadId, | 0_2_6CCD8C8D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22C90 ZwReleaseMutant, | 0_2_6CD22C90 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22C80 ZwImpersonateClientOfPort, | 0_2_6CD22C80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD08CB1 RtlInitUnicodeString,ZwQueryLicenseValue,RtlAllocateHeap,ZwQueryLicenseValue,RtlFreeHeap, | 0_2_6CD08CB1 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22CB0 ZwRequestWaitReplyPort, | 0_2_6CD22CB0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD90CB5 ZwAllocateVirtualMemory,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint, | 0_2_6CD90CB5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22CA0 ZwQueryInformationToken, | 0_2_6CD22CA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5CCA0 RtlAppxIsFileOwnedByTrustedInstaller,ZwQuerySecurityObject,RtlAllocateHeap,ZwQuerySecurityObject,RtlGetOwnerSecurityDescriptor,RtlCreateServiceSid,RtlAllocateHeap,RtlCreateServiceSid,RtlEqualSid,RtlFreeHeap,RtlFreeHeap, | 0_2_6CD5CCA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD66CA0 RtlCreateQueryDebugBuffer,ZwCreateSection,ZwMapViewOfSection,ZwAllocateVirtualMemory,ZwAllocateVirtualMemory,ZwFreeVirtualMemory,ZwFreeVirtualMemory,ZwUnmapViewOfSection,ZwClose, | 0_2_6CD66CA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22C50 ZwSetInformationProcess, | 0_2_6CD22C50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22C40 ZwWriteFileGather, | 0_2_6CD22C40 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24C40 RtlUnhandledExceptionFilter,ZwTerminateProcess, | 0_2_6CD24C40 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEAC50 LdrpResGetMappingSize,RtlImageNtHeaderEx,ZwQueryVirtualMemory,LdrpResGetMappingSize,RtlGetCurrentServiceSessionId,LdrpResGetMappingSize,RtlGetCurrentServiceSessionId, | 0_2_6CCEAC50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22C70 ZwFreeVirtualMemory, | 0_2_6CD22C70 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22C60 ZwCreateKey, | 0_2_6CD22C60 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6EC65 ZwWow64CsrCaptureMessageString, | 0_2_6CD6EC65 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1AC00 RtlpCheckDynamicTimeZoneInformation,memcmp,ZwClose, | 0_2_6CD1AC00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22C00 ZwQueryInformationProcess, | 0_2_6CD22C00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22C30 ZwWaitForMultipleObjects32, | 0_2_6CD22C30 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24C30 RtlUnhandledExceptionFilter,ZwTerminateProcess, | 0_2_6CD24C30 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD84C34 RtlDosPathNameToRelativeNtPathName_U,ZwOpenFile,ZwClose,RtlFreeHeap,RtlFreeHeap,RtlAllocateHeap,RtlCultureNameToLCID,RtlAllocateHeap,RtlReAllocateHeap,memcpy,memset,ZwQueryDirectoryFile,ZwClose,RtlFreeHeap,RtlFreeHeap, | 0_2_6CD84C34 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDEC20 TpSetPoolWorkerThreadIdleTimeout,ZwSetInformationWorkerFactory, | 0_2_6CCDEC20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD64DD7 DbgPrint,DbgPrompt,ZwTerminateThread,ZwTerminateProcess,DbgPrint, | 0_2_6CD64DD7 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22DD0 ZwDelayExecution, | 0_2_6CD22DD0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0EDD3 RtlAcquireSRWLockShared,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockShared,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockShared,RtlReleaseSRWLockExclusive,RtlFreeHeap,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockExclusive,ZwGetCompleteWnfStateSubscription,RtlFreeHeap, | 0_2_6CD0EDD3 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22DC0 ZwOpenFile, | 0_2_6CD22DC0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4DC4 ZwQueryInformationProcess,RtlRaiseStatus,RtlDebugPrintTimes,RtlUnhandledExceptionFilter2, | 0_2_6CDB4DC4 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD80DF0 RtlCheckBootStatusIntegrity,ZwReadFile,RtlAllocateHeap,ZwReadFile,RtlFreeHeap, | 0_2_6CD80DF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD8ADF0 RtlConnectToSm,RtlInitUnicodeString,memset,memcpy,ZwAlpcConnectPort, | 0_2_6CD8ADF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD00DE1 RtlAcquireSRWLockExclusive,RtlAllocateHeap,memcpy,ZwSetInformationProcess,RtlReleaseSRWLockExclusive,RtlFreeHeap,RtlAllocateHeap,RtlFreeHeap,RtlReleaseSRWLockExclusive,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap, | 0_2_6CD00DE1 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22DE0 ZwQueryDirectoryFile, | 0_2_6CD22DE0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD96DE0 RtlIsPartialPlaceholderFileHandle,ZwQueryInformationFile, | 0_2_6CD96DE0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22D90 ZwOpenProcessTokenEx, | 0_2_6CD22D90 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD68D87 RtlAppendUnicodeStringToString,ZwOpenKey, | 0_2_6CD68D87 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22D80 ZwOpenThreadTokenEx, | 0_2_6CD22D80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1CDB1 RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlDebugPrintTimes,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,ZwQueryInformationProcess,RtlRaiseStatus,RtlFreeHeap,LdrControlFlowGuardEnforced,RtlFreeHeap, | 0_2_6CD1CDB1 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD70DB0 RtlSetImageMitigationPolicy,RtlInitUnicodeStringEx,RtlInitUnicodeStringEx,RtlInitUnicodeStringEx,ZwOpenKey,ZwDeleteValueKey,ZwDeleteValueKey,ZwQueryValueKey,memcpy,ZwSetValueKey,RtlSetImageMitigationPolicy,ZwClose, | 0_2_6CD70DB0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE8DA4 RtlInitializeCriticalSectionEx,ZwDelayExecution, | 0_2_6CCE8DA4 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22DA0 ZwQueryPerformanceCounter, | 0_2_6CD22DA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22D50 ZwTerminateProcess, | 0_2_6CD22D50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22D40 ZwReplyWaitReceivePortEx, | 0_2_6CD22D40 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1CD47 ZwCancelWaitCompletionPacket,RtlDebugPrintTimes, | 0_2_6CD1CD47 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE0D59 memset,RtlRunOnceExecuteOnce,ZwTraceControl,memcmp,RtlNtStatusToDosError,RtlFreeHeap,RtlAllocateHeap,RtlNtStatusToDosError,RtlFreeHeap, | 0_2_6CCE0D59 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22D70 ZwReadFileScatter, | 0_2_6CD22D70 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD00D77 ZwProtectVirtualMemory, | 0_2_6CD00D77 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22D60 ZwSetEventBoostPriority, | 0_2_6CD22D60 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD38D10 RtlRaiseStatus,RtlCaptureContext,ZwRaiseException,RtlRaiseStatus, | 0_2_6CD38D10 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22D00 ZwSetInformationFile, | 0_2_6CD22D00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB0D00 EtwWriteUMSecurityEvent,ZwTraceEvent,RtlNtStatusToDosError, | 0_2_6CDB0D00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD6D10 LdrQueryImageFileKeyOption,RtlInitUnicodeStringEx,ZwQueryValueKey,LdrQueryImageFileKeyOption,RtlFreeHeap,RtlAllocateHeap,ZwQueryValueKey,RtlFreeHeap,RtlUnicodeStringToInteger,memcpy,LdrQueryImageFileKeyOption, | 0_2_6CCD6D10 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22D30 ZwUnmapViewOfSection, | 0_2_6CD22D30 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD88D31 RtlInitUnicodeString,memset,RtlAppendUnicodeStringToString,RtlAppendUnicodeStringToString,ZwOpenKey,ZwQueryValueKey,_allmul,ZwClose, | 0_2_6CD88D31 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD64D39 RtlReportSilentProcessExit,ZwQueryInformationProcess,RtlRaiseStatus,RtlDebugPrintTimes,RtlUnhandledExceptionFilter2,ZwTerminateProcess, | 0_2_6CD64D39 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22D20 ZwAccessCheckAndAuditAlarm, | 0_2_6CD22D20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6AD20 ZwDuplicateObject,ZwDuplicateObject, | 0_2_6CD6AD20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD96D21 ZwQueryInformationProcess,RtlRaiseStatus,RtlDebugPrintTimes,RtlUnhandledExceptionFilter2, | 0_2_6CD96D21 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22ED0 ZwQueryDefaultUILanguage, | 0_2_6CD22ED0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22EC0 ZwContinue, | 0_2_6CD22EC0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22EF0 ZwYieldExecution, | 0_2_6CD22EF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB0EF0 ZwTraceControl,RtlNtStatusToDosError,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlSetLastWin32Error, | 0_2_6CDB0EF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22EE0 ZwQueueApcThread, | 0_2_6CD22EE0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22E90 ZwOpenEvent, | 0_2_6CD22E90 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD88E90 memcpy,ZwUnmapViewOfSection,ZwMapViewOfSection,memcpy, | 0_2_6CD88E90 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22E80 ZwReadVirtualMemory, | 0_2_6CD22E80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDAE90 TpReleasePool,RtlAcquireSRWLockExclusive,ZwShutdownWorkerFactory,RtlGetCurrentServiceSessionId,TpReleasePool,TpReleasePool,RtlDebugPrintTimes,TpReleasePool,TpReleasePool, | 0_2_6CCDAE90 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22EB0 ZwDuplicateToken, | 0_2_6CD22EB0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD7AEB0 RtlpNotOwnerCriticalSection,DbgPrintEx,ZwQueryInformationProcess,RtlRaiseStatus,RtlRaiseStatus,RtlDebugPrintTimes,RtlpNotOwnerCriticalSection, | 0_2_6CD7AEB0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22EA0 ZwAdjustPrivilegesToken, | 0_2_6CD22EA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6CEA0 LdrAddDllDirectory,RtlDetermineDosPathNameType_U,ZwQueryAttributesFile,RtlFreeHeap,RtlAllocateHeap,memcpy,RtlAcquireSRWLockExclusive,@_EH4_CallFilterFunc@8,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlFreeHeap,LdrAddDllDirectory, | 0_2_6CD6CEA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD14E50 RtlDecodePointer,RtlDecodePointer,ZwQueryInformationProcess,RtlRaiseStatus, | 0_2_6CD14E50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD16E50 RtlAdjustPrivilege,ZwOpenProcessToken,ZwAdjustPrivilegesToken,ZwClose,ZwOpenThreadToken,RtlAdjustPrivilege, | 0_2_6CD16E50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD66E50 RtlDestroyQueryDebugBuffer,ZwClose,ZwUnmapViewOfSection, | 0_2_6CD66E50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4E52 ZwAlertThreadByThreadId, | 0_2_6CDB4E52 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22E40 ZwCloseObjectAuditAlarm, | 0_2_6CD22E40 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD94E4D ZwQueryPerformanceCounter,RtlRandomEx, | 0_2_6CD94E4D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9CE4E memset,memset,memset,ZwQueryInstallUILanguage,ZwIsUILanguageComitted,RtlLCIDToCultureName,ZwQueryValueKey,RtlInitUnicodeString,RtlCompareUnicodeStrings,RtlInitUnicodeString,ZwQueryValueKey,ZwEnumerateValueKey,RtlCompareUnicodeStrings,RtlCompareUnicodeStrings, | 0_2_6CD9CE4E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22E70 ZwClearEvent, | 0_2_6CD22E70 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD60E7F RtlAllocateHeap,memcpy,RtlGetCurrentServiceSessionId,ZwTraceEvent,RtlFreeHeap, | 0_2_6CD60E7F |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDAAE75 ZwFreeVirtualMemory,RtlAcquireSRWLockExclusive,RtlRbRemoveNode,RtlReleaseSRWLockExclusive,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive, | 0_2_6CDAAE75 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22E60 ZwQueryAttributesFile, | 0_2_6CD22E60 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9EE6D memset,ZwCreateSection,ZwClose,ZwMapViewOfSection,RtlDebugPrintTimes,ZwUnmapViewOfSection,ZwUnmapViewOfSection,ZwClose, | 0_2_6CD9EE6D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB8E6C memset,ZwQueryInformationThread,ZwQueryInformationThread,ZwQueryInformationThread,ZwQueryInformationThread,ZwQueryInformationThread,ZwQueryInformationThread,memset,ZwGetContextThread, | 0_2_6CDB8E6C |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6E71 RtlGetCurrentServiceSessionId,ZwSetInformationThread,ZwSetInformationThread, | 0_2_6CCE6E71 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD68E16 ZwOpenProcessTokenEx,ZwQueryInformationToken,ZwClose,RtlConvertSidToUnicodeString, | 0_2_6CD68E16 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22E10 ZwQueryTimer, | 0_2_6CD22E10 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5CE16 wcschr,RtlInitUnicodeString,wcstoul,RtlAnsiStringToUnicodeString,RtlCompareUnicodeString,ZwProtectVirtualMemory,DbgPrintEx,RtlFreeUnicodeString, | 0_2_6CD5CE16 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6EE10 AlpcAdjustCompletionListConcurrencyCount,ZwAlpcSetInformation, | 0_2_6CD6EE10 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD18E1A RtlReleaseActivationContext,LdrUnloadDll,ZwClose,RtlFreeHeap, | 0_2_6CD18E1A |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD8E1D RtlFreeHeap,ZwSetEvent,ZwClose, | 0_2_6CCD8E1D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22E00 ZwOpenSection, | 0_2_6CD22E00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22E30 ZwWriteVirtualMemory, | 0_2_6CD22E30 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDA0E3D ZwQuerySystemInformation, | 0_2_6CDA0E3D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22E20 ZwFsControlFile, | 0_2_6CD22E20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24E20 KiUserApcDispatcher,RtlDebugPrintTimes,RtlDebugPrintTimes,ZwContinue,RtlRaiseStatus, | 0_2_6CD24E20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22FD0 ZwReadRequestData, | 0_2_6CD22FD0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9AFD0 RtlpGetUserOrMachineUILanguage4NLS,RtlInitUnicodeString,RtlInitUnicodeString,ZwOpenKey,RtlInitUnicodeString,ZwClose,RtlInitUnicodeString,ZwOpenKey,RtlInitUnicodeString,ZwClose,ZwClose, | 0_2_6CD9AFD0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22FC0 ZwTerminateThread, | 0_2_6CD22FC0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDEFD8 RtlRunOnceExecuteOnce,ZwAllocateVirtualMemory,ZwAllocateVirtualMemory,RtlGetCurrentServiceSessionId,RtlGetCurrentServiceSessionId, | 0_2_6CCDEFD8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD7AFCE ZwQueryInformationProcess,RtlRaiseStatus,RtlCaptureContext,ZwQueryInformationProcess,RtlRaiseException, | 0_2_6CD7AFCE |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD14FF1 ZwQuerySecurityAttributesToken,ZwQuerySecurityAttributesToken,ZwQuerySecurityAttributesToken,ZwQuerySecurityAttributesToken, | 0_2_6CD14FF1 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22FF0 ZwQueryEvent, | 0_2_6CD22FF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD20FF6 RtlAllocateHeap,RtlInitUnicodeString,ZwOpenKey,RtlAllocateHeap,RtlInitUnicodeString,ZwQueryValueKey,RtlFreeHeap,ZwClose,RtlFreeHeap, | 0_2_6CD20FF6 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22FE0 ZwCreateFile, | 0_2_6CD22FE0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD66FE0 RtlQueryProcessDebugInformation,memset,ZwOpenProcess,ZwOpenProcess,RtlWow64GetProcessMachines,ZwClose,ZwClose,ZwWow64CallFunction64,RtlpQueryProcessDebugInformationRemote,ZwWaitForSingleObject,ZwQueryInformationThread,ZwTerminateThread,ZwClose,ZwClose,RtlQueryProcessBackTraceInformation,RtlQueryProcessLockInformation,RtlQueryProcessHeapInformation,ZwClose, | 0_2_6CD66FE0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4FE7 RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CDB4FE7 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22F90 ZwProtectVirtualMemory, | 0_2_6CD22F90 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD12F98 memcpy,memcpy,RtlDosPathNameToRelativeNtPathName_U,ZwOpenFile,memcpy,RtlFreeHeap,RtlDeleteBoundaryDescriptor,DbgPrintEx,DbgPrintEx,DbgPrintEx,ZwClose,RtlFreeHeap,DbgPrintEx,memcpy,DbgPrintEx,ZwClose, | 0_2_6CD12F98 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22F80 ZwIsProcessInJob, | 0_2_6CD22F80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24F80 KiUserExceptionDispatcher,RtlDebugPrintTimes,ZwContinue,ZwRaiseException,RtlRaiseException, | 0_2_6CD24F80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB0F88 ZwTraceControl,RtlNtStatusToDosError,RtlSetLastWin32Error, | 0_2_6CDB0F88 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB6F80 PssNtFreeRemoteSnapshot,ZwReadVirtualMemory,ZwFreeVirtualMemory,ZwDuplicateObject,ZwDuplicateObject,ZwDuplicateObject,ZwDuplicateObject,ZwDuplicateObject,ZwDuplicateObject,ZwFreeVirtualMemory, | 0_2_6CDB6F80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22FB0 ZwResumeThread, | 0_2_6CD22FB0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1AFB8 RtlInitUnicodeString,RtlInitUnicodeString,ZwQueryValueKey,ZwClose,ZwClose,ZwClose,RtlInitUnicodeString,ZwOpenKey,ZwEnumerateValueKey,DbgPrint,ZwDeleteValueKey,RtlDebugPrintTimes,ZwDeleteValueKey,DbgPrint,ZwClose, | 0_2_6CD1AFB8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22FA0 ZwQuerySection, | 0_2_6CD22FA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22F50 ZwApphelpCacheControl, | 0_2_6CD22F50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4F5C ZwTerminateProcess, | 0_2_6CDB4F5C |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD80F50 RtlCreateBootStatusDataFile,RtlInitUnicodeString,RtlInitUnicodeString,ZwCreateFile,ZwWriteFile,RtlRestoreBootStatusDefaults,ZwClose,RtlFreeHeap, | 0_2_6CD80F50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD96F50 RtlIsCurrentThread,ZwCompareObjects, | 0_2_6CD96F50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD18F40 RtlUnwind,ZwContinue,RtlUnwind,RtlRaiseException,RtlRaiseException,RtlRaiseException,ZwContinue,ZwRaiseException, | 0_2_6CD18F40 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22F40 ZwFlushBuffersFile, | 0_2_6CD22F40 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22F70 ZwCreateThread, | 0_2_6CD22F70 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6AF7A ZwUnmapViewOfSection,ZwClose,ZwClose,ZwClose,ZwClose,ZwClose, | 0_2_6CD6AF7A |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22F60 ZwCreateProcessEx, | 0_2_6CD22F60 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4F68 RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CDB4F68 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD8AF60 RtlSendMsgToSm,ZwAlpcSendWaitReceivePort, | 0_2_6CD8AF60 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22F10 ZwCreateEvent, | 0_2_6CD22F10 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24F10 KiUserCallbackDispatcher,RtlDebugPrintTimes,RtlDebugPrintTimes,ZwCallbackReturn,RtlRaiseStatus, | 0_2_6CD24F10 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22F00 ZwAddAtom, | 0_2_6CD22F00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD20F04 RtlInitUnicodeString,ZwOpenKey,RtlInitUnicodeString,ZwQueryValueKey,ZwClose, | 0_2_6CD20F04 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD80F00 RtlCheckSystemBootStatusIntegrity,ZwPowerInformation, | 0_2_6CD80F00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD94F00 __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,ZwQueryPerformanceCounter,ZwQueryPerformanceCounter, | 0_2_6CD94F00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22F20 ZwQueryVolumeInformationFile, | 0_2_6CD22F20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD96F20 RtlIsCurrentProcess,ZwCompareObjects, | 0_2_6CD96F20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD248D0 ZwWow64QueryInformationProcess64, | 0_2_6CD248D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD248C0 ZwWow64GetNativeSystemInformation, | 0_2_6CD248C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD248F0 ZwWow64ReadVirtualMemory64, | 0_2_6CD248F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDE8E0 RtlQueryWnfStateData,_alloca_probe_16,ZwQueryWnfStateData,RtlDebugPrintTimes, | 0_2_6CCDE8E0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD248E0 ZwWow64AllocateVirtualMemory64, | 0_2_6CD248E0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE28F0 RtlDetermineDosPathNameType_U,RtlDetermineDosPathNameType_U,ZwTerminateProcess,ZwWaitForAlertByThreadId,RtlReleaseSRWLockExclusive,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlFreeHeap,RtlGetCurrentServiceSessionId,RtlCreateUnicodeString,RtlCreateUnicodeString,RtlFreeUnicodeString,RtlFreeUnicodeString, | 0_2_6CCE28F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD168EF ZwUnmapViewOfSection, | 0_2_6CD168EF |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24890 ZwWow64CsrVerifyRegion, | 0_2_6CD24890 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE0887 RtlAcquireSRWLockExclusive,RtlAcquireSRWLockExclusive,ZwSubscribeWnfStateChange,RtlGetCurrentServiceSessionId,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockExclusive, | 0_2_6CCE0887 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6C89D RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CD6C89D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24880 ZwWow64CsrGetProcessId, | 0_2_6CD24880 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4887 ZwSetInformationWorkerFactory, | 0_2_6CDB4887 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD248B0 ZwWow64GetCurrentProcessorNumberEx, | 0_2_6CD248B0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1C8B7 ZwTraceControl, | 0_2_6CD1C8B7 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD248A0 ZwWow64DebuggerCall, | 0_2_6CD248A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24850 ZwWow64CsrAllocateMessagePointer, | 0_2_6CD24850 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDA685D ZwGetCurrentProcessorNumber,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockExclusive, | 0_2_6CDA685D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD7A85E RtlInitializeSid,ZwQueryInformationToken,RtlSidDominates,RtlSidDominates,ZwPrivilegeCheck, | 0_2_6CD7A85E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24840 ZwWow64CsrFreeCaptureBuffer, | 0_2_6CD24840 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDA0840 ZwCreateSection,ZwMapViewOfSection,memset,memcpy,ZwUnmapViewOfSection,ZwClose, | 0_2_6CDA0840 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24870 ZwWow64CsrCaptureMessageString, | 0_2_6CD24870 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24860 ZwWow64CsrCaptureMessageBuffer, | 0_2_6CD24860 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24810 ZwWow64CsrIdentifyAlertableThread, | 0_2_6CD24810 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6C810 RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CD6C810 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24800 ZwWow64CsrClientConnectToServer, | 0_2_6CD24800 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD20800 ZwAllocateVirtualMemory,memset,RtlEnterCriticalSection,RtlLeaveCriticalSection, | 0_2_6CD20800 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6A800 RtlEncodeRemotePointer,ZwQueryInformationProcess, | 0_2_6CD6A800 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24830 ZwWow64CsrAllocateCaptureBuffer, | 0_2_6CD24830 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEE820 RtlLeaveCriticalSection,RtlpNotOwnerCriticalSection,RtlLeaveCriticalSection,ZwSetEvent,RtlRaiseStatus,LdrRscIsTypeExist, | 0_2_6CCEE820 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD16820 RtlClearThreadWorkOnBehalfTicket,memcmp,RtlClearThreadWorkOnBehalfTicket,ZwSetInformationThread, | 0_2_6CD16820 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24820 ZwWow64CsrClientCallServer, | 0_2_6CD24820 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD769C0 RtlGetSessionProperties,RtlGetCurrentServiceSessionId,ZwQueryInformationJobObject, | 0_2_6CD769C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD129F9 DbgPrintEx,wcsrchr,memcpy,DbgPrintEx,ZwClose,DbgPrintEx,DbgPrintEx,RtlDosPathNameToRelativeNtPathName_U,DbgPrintEx,ZwOpenFile,ZwClose,RtlFreeHeap,DbgPrintEx,DbgPrintEx,DbgPrintEx,RtlDeleteBoundaryDescriptor,ZwClose,RtlFreeHeap, | 0_2_6CD129F9 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDA29F3 ZwAllocateVirtualMemoryEx, | 0_2_6CDA29F3 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE49FF ZwSetInformationWorkerFactory, | 0_2_6CCE49FF |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6A9E0 RtlReportExceptionEx,RtlReportException,ZwDuplicateObject,ZwDuplicateObject,memset,ZwTerminateProcess, | 0_2_6CD6A9E0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6E9E0 RtlComputeImportTableHash,ZwCreateSection,ZwMapViewOfSection,ZwClose,RtlImageNtHeader,RtlAddressInSectionTable,RtlAllocateHeap,ZwUnmapViewOfSection,RtlFlushSecureMemoryCache,ZwUnmapViewOfSection, | 0_2_6CD6E9E0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDAA987 ZwQueryVirtualMemory,ZwProtectVirtualMemory, | 0_2_6CDAA987 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD229B3 ZwWaitForAlertByThreadId, | 0_2_6CD229B3 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD889B4 ZwOpenKey,ZwQueryValueKey,ZwClose, | 0_2_6CD889B4 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD649B8 ZwQueryInformationProcess,ZwMapViewOfSection,ZwClose, | 0_2_6CD649B8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1A9A0 RtlReleaseResource,ZwReleaseSemaphore,RtlRaiseStatus,ZwQueryValueKey,ZwReleaseSemaphore,RtlRaiseStatus,ZwClose, | 0_2_6CD1A9A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB6940 PssNtCaptureSnapshot,ZwAllocateVirtualMemory,memset,PssNtFreeSnapshot,_allmul,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,_allmul,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,ZwCreateProcessEx,_allmul,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,PssNtFreeSnapshot,_allmul,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,_allmul,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,_allmul,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z, | 0_2_6CDB6940 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD96970 RtlInitializeContext,ZwWriteVirtualMemory, | 0_2_6CD96970 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6C97C RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CD6C97C |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD06962 ZwQueryInformationToken,RtlFindAceByType,RtlFindAceByType,RtlFindAceByType,RtlAllocateHeap,memcpy,memcpy,memcpy,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlCreateSecurityDescriptor,RtlFreeHeap,RtlCreateAcl,RtlAddMandatoryAce,RtlFreeHeap,memcpy,RtlFreeHeap,RtlSidDominates,RtlFreeHeap,RtlFreeHeap,RtlFindAceByType,ZwDuplicateToken,ZwAccessCheck,ZwClose,ZwPrivilegeCheck,ZwPrivilegeCheck,RtlFreeHeap,memset,memset,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap, | 0_2_6CD06962 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD2096E memset,memset,ZwQuerySystemInformation,ZwQueryInformationThread,ZwQueryInformationThread,ZwQuerySystemInformation,RtlAllocateHeap,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,memcpy,memcpy,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,memset,ZwWriteFile,RtlFreeHeap,ZwClose,ZwReadFile,ZwWriteFile,RtlQueryPerformanceCounter,RtlQueryPerformanceCounter,memcpy,ZwQueryVolumeInformationFile,ZwSetInformationFile, | 0_2_6CD2096E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0096D ZwWow64IsProcessorFeaturePresent, | 0_2_6CD0096D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24910 ZwWow64CallFunction64, | 0_2_6CD24910 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6C912 RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CD6C912 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24900 ZwWow64WriteVirtualMemory64, | 0_2_6CD24900 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD64908 RtlAllocateHeap,ZwQueryVirtualMemory,RtlFreeHeap, | 0_2_6CD64908 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24930 DbgPrintEx,ZwTerminateProcess, | 0_2_6CD24930 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCFE920 RtlWow64EnableFsRedirectionEx,RtlEnterCriticalSection,RtlLeaveCriticalSection,ZwSetEvent, | 0_2_6CCFE920 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24920 ZwWow64IsProcessorFeaturePresent, | 0_2_6CD24920 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB8927 ZwDuplicateObject,ZwQueryObject,ZwClose,memset,_wcsicmp,ZwQueryObject,ZwQueryObject,_wcsicmp,ZwClose,RtlDebugPrintTimes,RtlDebugPrintTimes, | 0_2_6CDB8927 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22AD0 ZwReadFile, | 0_2_6CD22AD0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22AC0 ZwCallbackReturn, | 0_2_6CD22AC0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9AACD ZwFreeVirtualMemory, | 0_2_6CD9AACD |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD36ACC memset,ZwQueryWnfStateData,RtlFreeHeap,RtlAllocateHeap,ZwQueryWnfStateData,ZwQueryWnfStateData,RtlFreeHeap, | 0_2_6CD36ACC |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22AF0 ZwWriteFile, | 0_2_6CD22AF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD8EAF0 RtlFlushSecureMemoryCache,ZwQueryVirtualMemory, | 0_2_6CD8EAF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22AE0 ZwDeviceIoControlFile, | 0_2_6CD22AE0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD7AAE0 RtlConvertExclusiveToShared,ZwReleaseSemaphore,RtlRaiseStatus, | 0_2_6CD7AAE0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9AA98 ZwAllocateVirtualMemory, | 0_2_6CD9AA98 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22A90 ZwAcceptConnectPort, | 0_2_6CD22A90 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22A80 ZwWorkerFactoryWorkerReady, | 0_2_6CD22A80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22AB0 ZwWaitForSingleObject, | 0_2_6CD22AB0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22AA0 ZwMapUserPhysicalPagesScatter, | 0_2_6CD22AA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDA2AAC ZwQuerySystemInformation, | 0_2_6CDA2AAC |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD72AA9 ZwEnumerateValueKey,RtlInitUnicodeStringEx,RtlInitUnicodeStringEx,RtlCompareUnicodeString,RtlCompareUnicodeString,ZwEnumerateKey,ZwOpenKey,ZwClose, | 0_2_6CD72AA9 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB0A50 EtwEventWriteString,ZwTraceEvent,RtlNtStatusToDosError, | 0_2_6CDB0A50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1AA45 ZwOpenKey,ZwQueryValueKey,ZwClose, | 0_2_6CD1AA45 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6A50 RtlAcquireSRWLockExclusive,RtlDebugPrintTimes,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlGetCurrentServiceSessionId,ZwSetInformationThread,ZwSetInformationThread,RtlGetCurrentServiceSessionId,ZwSetInformationThread,ZwSetInformationThread, | 0_2_6CCE6A50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22A70 ZwAccessCheck, | 0_2_6CD22A70 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5CA72 ZwQueryValueKey,RtlAllocateHeap,ZwQueryValueKey,RtlFreeHeap, | 0_2_6CD5CA72 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB2A70 EtwSendNotification,ZwTraceControl,RtlNtStatusToDosError,ZwClose, | 0_2_6CDB2A70 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD94A63 ZwQuerySystemInformation,RtlAllocateHeap,RtlFreeHeap,RtlAllocateHeap, | 0_2_6CD94A63 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDEA0C ZwCreateEvent,TpAllocWait,ZwSetWnfProcessNotificationEvent,TpSetWaitEx,TpReleaseWait,ZwClose, | 0_2_6CCDEA0C |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6CA11 RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CD6CA11 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD72A03 ZwDeleteKey,ZwClose, | 0_2_6CD72A03 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD60A0E RtlRunOnceExecuteOnce,ZwQuerySystemInformation,RtlCaptureContext,memset,RtlReportException, | 0_2_6CD60A0E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD96A30 RtlRemoteCall,LdrControlFlowGuardEnforced,ZwSuspendThread,ZwGetContextThread,ZwResumeThread,ZwWriteVirtualMemory,ZwResumeThread,memcpy,memcpy,ZwWriteVirtualMemory,ZwSetContextThread,ZwResumeThread, | 0_2_6CD96A30 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB2A30 EtwReplyNotification,ZwTraceControl,RtlNtStatusToDosError, | 0_2_6CDB2A30 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22BD0 ZwQueryKey, | 0_2_6CD22BD0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE0BCD RtlAcquireSRWLockExclusive,memset,ZwTraceControl,RtlReleaseSRWLockExclusive,RtlSetLastWin32Error,RtlFreeHeap,RtlAllocateHeap,RtlNtStatusToDosError,RtlFreeHeap, | 0_2_6CCE0BCD |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6EBD0 CsrCaptureMessageMultiUnicodeStringsInPlace,ZwWow64CsrAllocateCaptureBuffer, | 0_2_6CD6EBD0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22BC0 ZwQueryDefaultLocale, | 0_2_6CD22BC0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD96BFC ZwQueryInformationProcess,RtlRaiseStatus,RtlDebugPrintTimes, | 0_2_6CD96BFC |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6CBF0 RtlAcquireSRWLockShared,RtlReleaseSRWLockShared,RtlAcquireSRWLockShared,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockShared,ZwGetCompleteWnfStateSubscription,RtlFreeHeap, | 0_2_6CD6CBF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0EBFC RtlAcquireSRWLockExclusive,RtlAcquireSRWLockExclusive,RtlGetCurrentServiceSessionId,ZwSubscribeWnfStateChange,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlDebugPrintTimes, | 0_2_6CD0EBFC |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22BE0 ZwQueryValueKey, | 0_2_6CD22BE0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB8B98 ZwGetNextThread,ZwAllocateVirtualMemory,ZwGetNextThread,RtlGetExtendedContextLength,ZwCreateSection,ZwMapViewOfSection,ZwClose,ZwUnmapViewOfSection,ZwUnmapViewOfSection, | 0_2_6CDB8B98 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22B80 ZwQueryInformationFile, | 0_2_6CD22B80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDAEB89 ZwFreeVirtualMemory, | 0_2_6CDAEB89 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22BB0 ZwFindAtom, | 0_2_6CD22BB0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6CBB0 ZwSetEvent, | 0_2_6CD6CBB0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDEBA6 ZwOpenFile,memcmp,ZwQueryInformationThread,TpWaitForWork,TpReleaseWork, | 0_2_6CCDEBA6 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22BA0 ZwEnumerateValueKey, | 0_2_6CD22BA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22B50 ZwSetEvent, | 0_2_6CD22B50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5CB5D RtlGetPersistedStateLocation,ZwOpenKeyEx, | 0_2_6CD5CB5D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD8EB50 RtlRegisterSecureMemoryCacheCallback,ZwQuerySystemInformation,RtlAllocateHeap,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive, | 0_2_6CD8EB50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB2B57 RtlAllocateHeap,RtlAllocateHeap,ZwTraceControl,RtlNtStatusToDosError,ZwTraceControl,RtlFreeHeap,RtlFreeHeap, | 0_2_6CDB2B57 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22B40 ZwSetInformationThread, | 0_2_6CD22B40 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD76B40 RtlIsUntrustedObject,ZwQuerySecurityObject,RtlAllocateHeap,ZwQuerySecurityObject,RtlFindAceByType,RtlFreeHeap, | 0_2_6CD76B40 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD7AB40 RtlConvertSharedToExclusive,ZwReleaseSemaphore,RtlRaiseStatus,ZwReleaseSemaphore,RtlRaiseStatus,RtlAcquireResourceExclusive, | 0_2_6CD7AB40 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD8B50 RtlDeleteTimerQueueEx,RtlAcquireSRWLockExclusive,TpTimerOutstandingCallbackCount,TpReleaseTimer,RtlDeleteTimerQueueEx,RtlDeleteTimerQueueEx,RtlDeleteTimerQueueEx,ZwWaitForAlertByThreadId, | 0_2_6CCD8B50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22B70 ZwQueryObject, | 0_2_6CD22B70 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22B60 ZwClose, | 0_2_6CD22B60 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9CB64 memset,RtlInitUnicodeString,RtlInitUnicodeString,ZwEnumerateValueKey,RtlInitUnicodeString,RtlCompareUnicodeStrings, | 0_2_6CD9CB64 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22B10 ZwReleaseSemaphore, | 0_2_6CD22B10 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22B00 ZwRemoveIoCompletion, | 0_2_6CD22B00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDACB09 ZwQueryVirtualMemory, | 0_2_6CDACB09 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22B30 ZwReplyPort, | 0_2_6CD22B30 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0EB20 TpSetWaitEx,RtlAllocateHeap,ZwGetCompleteWnfStateSubscription,RtlFreeHeap,TpSetWaitEx, | 0_2_6CD0EB20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22B20 ZwReplyWaitReceivePort, | 0_2_6CD22B20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDAB30 RtlCreateMemoryZone,ZwAllocateVirtualMemory, | 0_2_6CCDAB30 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD244D0 ZwSetLowEventPair, | 0_2_6CD244D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD244C0 ZwSetLdtEntries, | 0_2_6CD244C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD244F0 ZwSetQuotaInformationFile, | 0_2_6CD244F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD8E4FD ZwOpenProcessTokenEx,ZwAdjustPrivilegesToken,ZwOpenFile,RtlCreateSecurityDescriptor,RtlSetOwnerSecurityDescriptor,ZwSetSecurityObject,ZwClose,ZwClose, | 0_2_6CD8E4FD |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE04E5 SbSelectProcedure,RtlDebugPrintTimes,RtlGetSuiteMask,RtlGetSuiteMask,RtlGetNtProductType,RtlInitUnicodeString,ZwQueryLicenseValue, | 0_2_6CCE04E5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD244E0 ZwSetLowWaitHighEventPair, | 0_2_6CD244E0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24490 ZwSetIntervalProfile, | 0_2_6CD24490 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9A49A RtlAllocateHeap,ZwCreateEvent,TpAllocWork, | 0_2_6CD9A49A |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24480 ZwSetInformationWorkerFactory, | 0_2_6CD24480 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4480 TpSetPoolThreadCpuSets,RtlAcquireSRWLockExclusive,ZwSetInformationWorkerFactory,RtlReleaseSRWLockExclusive,RtlNumberOfSetBits, | 0_2_6CDB4480 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD244B0 ZwSetIoCompletionEx, | 0_2_6CD244B0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE64AB memcmp,ZwSetInformationThread,RtlDeactivateActivationContextUnsafeFast,RtlSetThreadSubProcessTag,memset,RtlRaiseException,ZwSetInformationThread,DbgPrintEx,memset,RtlRaiseException,DbgPrintEx,memset,RtlRaiseException,DbgPrintEx,memset,RtlRaiseException,DbgPrintEx,memset,RtlRaiseException, | 0_2_6CCE64AB |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD244A0 ZwSetIoCompletion, | 0_2_6CD244A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24450 ZwSetInformationTransaction, | 0_2_6CD24450 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDBA457 ZwDeviceIoControlFile, | 0_2_6CDBA457 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9A456 RtlUnsubscribeWnfNotificationWaitForCompletion,ZwClose,TpReleaseWork,RtlFreeHeap, | 0_2_6CD9A456 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1E443 ZwDelayExecution,ZwFreeVirtualMemory,ZwClose,ZwClose,RtlDeleteCriticalSection,RtlFreeUnicodeString,RtlFreeUnicodeString,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlFreeUnicodeString,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap, | 0_2_6CD1E443 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24440 ZwSetInformationToken, | 0_2_6CD24440 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0A470 LdrUnloadAlternateResourceModuleEx,RtlAcquireSRWLockExclusive,ZwUnmapViewOfSection,ZwClose,RtlFreeHeap,LdrUnloadAlternateResourceModuleEx,RtlFreeHeap,RtlReAllocateHeap, | 0_2_6CD0A470 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24470 ZwSetInformationVirtualMemory, | 0_2_6CD24470 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24460 ZwSetInformationTransactionManager, | 0_2_6CD24460 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6C460 RtlTestAndPublishWnfStateData,ZwUpdateWnfStateData,RtlGetCurrentServiceSessionId, | 0_2_6CD6C460 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24410 ZwSetInformationKey, | 0_2_6CD24410 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDBA414 ZwClose, | 0_2_6CDBA414 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24400 ZwSetInformationJobObject, | 0_2_6CD24400 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD18402 RtlImageNtHeaderEx,ZwOpenKey,ZwOpenKey,ZwOpenKey,ZwQueryValueKey,ZwClose,RtlFormatCurrentUserKeyPath,RtlAllocateHeap,RtlAppendUnicodeStringToString,RtlAppendUnicodeToString,ZwOpenKey,RtlFreeHeap,RtlFreeUnicodeString,ZwQueryValueKey,ZwClose,ZwQueryKey,ZwClose,LdrLoadDll,ZwQueryValueKey,ZwQueryValueKey,ZwClose,LdrGetProcedureAddressForCaller,LdrUnloadDll, | 0_2_6CD18402 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE2410 RtlRandomEx,ZwQueryInformationProcess, | 0_2_6CCE2410 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF2410 RtlAcquireSRWLockExclusive,ZwWaitForAlertByThreadId,RtlAcquireSRWLockExclusive,ZwTerminateProcess, | 0_2_6CCF2410 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24430 ZwSetInformationSymbolicLink, | 0_2_6CD24430 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDC427 memset,ZwIsUILanguageComitted,RtlpGetNameFromLangInfoNode,ZwQueryInstallUILanguage,RtlLCIDToCultureName,RtlFreeHeap, | 0_2_6CCDC427 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDE420 ZwTraceControl,EtwDeliverDataBlock,TpSetWaitEx,RtlAllocateHeap,RtlFreeHeap,RtlFreeHeap, | 0_2_6CCDE420 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24420 ZwSetInformationResourceManager, | 0_2_6CD24420 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD66420 RtlDefaultNpAcl,RtlAllocateHeap,ZwQueryInformationToken,ZwQueryInformationToken,RtlAllocateHeap,ZwQueryInformationToken,RtlGetAppContainerSidType,RtlGetAppContainerParent,RtlAllocateHeap,RtlCreateAcl,RtlInitializeSid,RtlInitializeSid,RtlInitializeSid,RtlInitializeSid,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap, | 0_2_6CD66420 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1A5D0 RtlCreateTagHeap,ZwQuerySystemInformation, | 0_2_6CD1A5D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD245D0 ZwShutdownSystem, | 0_2_6CD245D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD245C0 ZwSetWnfProcessNotificationEvent, | 0_2_6CD245C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9A5C0 ZwWaitForSingleObject, | 0_2_6CD9A5C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE65D0 ZwReleaseWorkerFactoryWorker,memmove,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,_allshl,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlDebugPrintTimes,RtlFreeHeap,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive, | 0_2_6CCE65D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD245F0 ZwSignalAndWaitForSingleObject, | 0_2_6CD245F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB85F0 ZwQueryInformationProcess, | 0_2_6CDB85F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE25E0 ZwClose,RtlFreeHeap, | 0_2_6CCE25E0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD245E0 ZwShutdownWorkerFactory, | 0_2_6CD245E0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD725E4 ZwClose,RtlStringFromGUIDEx,ZwCreateKey,RtlFreeUnicodeString, | 0_2_6CD725E4 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24590 ZwSetTimerResolution, | 0_2_6CD24590 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB8590 ZwQueryMutant,ZwQueryMutant, | 0_2_6CDB8590 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24580 ZwSetTimerEx, | 0_2_6CD24580 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD205B0 EtwpCreateEtwThread,ZwResumeThread,EtwpCreateEtwThread,ZwTerminateThread,ZwClose, | 0_2_6CD205B0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD245B0 ZwSetVolumeInformationFile, | 0_2_6CD245B0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD245A0 ZwSetUuidSeed, | 0_2_6CD245A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6E5A2 ZwOpenKey,DbgPrintEx,ZwQueryValueKey,DbgPrintEx,DbgPrintEx,memcpy,ZwClose, | 0_2_6CD6E5A2 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD65B5 RtlInitUnicodeString,RtlDebugPrintTimes,RtlDebugPrintTimes,RtlEnterCriticalSection,RtlLeaveCriticalSection,RtlReleasePath,ZwTerminateProcess, | 0_2_6CCD65B5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9A5A0 ZwSetEvent, | 0_2_6CD9A5A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24550 ZwSetSystemTime, | 0_2_6CD24550 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24540 ZwSetSystemPowerState, | 0_2_6CD24540 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6C540 RtlWaitForWnfMetaNotification,ZwQueryWnfStateNameInformation,ZwQueryWnfStateNameInformation,ZwCreateEvent,RtlRegisterForWnfMetaNotification,_allmul,ZwWaitForSingleObject,RtlUnsubscribeWnfNotificationWaitForCompletion,ZwClose, | 0_2_6CD6C540 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1A570 RtlWakeAllConditionVariable,ZwAlertThreadByThreadId,RtlWakeAllConditionVariable, | 0_2_6CD1A570 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1C570 RtlSetUserCallbackExceptionFilter,RtlSetUserCallbackExceptionFilter,ZwQueryInformationProcess,RtlRaiseStatus, | 0_2_6CD1C570 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24570 ZwSetTimer2, | 0_2_6CD24570 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24560 ZwSetThreadExecutionState, | 0_2_6CD24560 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB8560 ZwQueryEvent, | 0_2_6CDB8560 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24510 ZwSetSystemEnvironmentValue, | 0_2_6CD24510 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24500 ZwSetSecurityObject, | 0_2_6CD24500 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4500 TpTrimPools,RtlAcquireSRWLockExclusive,RtlAcquireSRWLockShared,RtlAcquireSRWLockExclusive,ZwSetInformationWorkerFactory,RtlSleepConditionVariableSRW,RtlAllocateHeap,ZwClose,RtlFreeHeap,RtlAllocateHeap,ZwClose,RtlFreeHeap,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockShared,ZwWaitForMultipleObjects,ZwClose,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockShared,RtlReleaseSRWLockExclusive, | 0_2_6CDB4500 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24530 ZwSetSystemInformation, | 0_2_6CD24530 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24520 ZwSetSystemEnvironmentValueEx, | 0_2_6CD24520 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD246D0 ZwTranslateFilePath, | 0_2_6CD246D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD246C0 ZwTraceControl, | 0_2_6CD246C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1A6C7 RtlAllocateHeap,memcpy,ZwFreeVirtualMemory, | 0_2_6CD1A6C7 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD246F0 ZwUnloadDriver, | 0_2_6CD246F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5E6F2 ZwQuerySystemInformation,ZwQuerySystemInformationEx,RtlAllocateHeap,ZwQuerySystemInformationEx,RtlFindCharInUnicodeString,RtlEnterCriticalSection,memcpy, | 0_2_6CD5E6F2 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD246E0 ZwUmsThreadYield, | 0_2_6CD246E0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6A6E0 RtlWow64IsWowGuestMachineSupported,ZwQuerySystemInformationEx,_alloca_probe_16,ZwQuerySystemInformationEx, | 0_2_6CD6A6E0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24690 ZwTestAlert, | 0_2_6CD24690 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6A690 RtlWow64GetSharedInfoProcess,ZwQueryInformationProcess,ZwReadVirtualMemory, | 0_2_6CD6A690 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD72699 memset,memset,ZwCreateUserProcess, | 0_2_6CD72699 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24680 ZwTerminateJobObject, | 0_2_6CD24680 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB8680 ZwQueryInformationThread,ZwQueryInformationThread, | 0_2_6CDB8680 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD246B0 ZwThawTransactions, | 0_2_6CD246B0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD246A0 ZwThawRegistry, | 0_2_6CD246A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24650 ZwSuspendThread, | 0_2_6CD24650 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD86650 RtlpVerifyAndCommitUILanguageSettings,memset,ZwQueryInstallUILanguage,RtlLCIDToCultureName,RtlpCreateProcessRegistryInfo,ZwFlushInstallUILanguage,ZwGetMUIRegistryInfo,ZwShutdownSystem, | 0_2_6CD86650 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9A650 ZwQueryInformationProcess,RtlRaiseStatus, | 0_2_6CD9A650 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB8650 ZwQuerySemaphore, | 0_2_6CDB8650 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24640 ZwSuspendProcess, | 0_2_6CD24640 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD96640 RtlSleepConditionVariableCS,RtlLeaveCriticalSection,ZwWaitForAlertByThreadId,ZwWaitForAlertByThreadId,RtlEnterCriticalSection, | 0_2_6CD96640 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24670 ZwTerminateEnclave, | 0_2_6CD24670 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24660 ZwSystemDebugControl, | 0_2_6CD24660 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24610 ZwStartProfile, | 0_2_6CD24610 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24600 ZwSinglePhaseReject, | 0_2_6CD24600 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24630 ZwSubscribeWnfStateChange, | 0_2_6CD24630 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD20634 ZwCreateThreadEx,ZwClose, | 0_2_6CD20634 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDC62A RtlInitUnicodeString,ZwOpenKey,ZwEnumerateKey,ZwClose, | 0_2_6CCDC62A |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD18620 ZwQueryInformationThread,ZwQueryInformationThread,RtlAcquireSRWLockShared,RtlApplicationVerifierStop, | 0_2_6CD18620 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24620 ZwStopProfile, | 0_2_6CD24620 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9C620 RtlpRefreshCachedUILanguage,ZwQueryInstallUILanguage,RtlInitUnicodeString,RtlCultureNameToLCID,ZwFlushInstallUILanguage,RtlpCreateProcessRegistryInfo,ZwFlushInstallUILanguage,ZwFlushInstallUILanguage,ZwGetMUIRegistryInfo, | 0_2_6CD9C620 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB8620 ZwQuerySection, | 0_2_6CDB8620 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD247D0 ZwWaitHighEventPair, | 0_2_6CD247D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD247C0 ZwWaitForWorkViaWorkerFactory, | 0_2_6CD247C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD607C3 ZwQueryInformationProcess,RtlRaiseStatus,RtlDebugPrintTimes,RtlUnhandledExceptionFilter2,EtwEventRegister,EtwEventWrite,EtwNotificationUnregister,ZwRaiseException, | 0_2_6CD607C3 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD667C0 RtlNewSecurityGrantedAccess,ZwQueryInformationToken,RtlMapGenericMask,ZwPrivilegeCheck, | 0_2_6CD667C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD247F0 ZwLoadKey3, | 0_2_6CD247F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD247E0 ZwWaitLowEventPair, | 0_2_6CD247E0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24790 ZwWaitForAlertByThreadId, | 0_2_6CD24790 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24780 ZwVdmControl, | 0_2_6CD24780 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD88785 ZwAllocateVirtualMemory,ZwDuplicateObject,ZwWriteVirtualMemory,ZwTerminateThread,ZwClose,ZwFreeVirtualMemory,ZwResumeThread,ZwWaitForSingleObject,ZwClose,ZwReadVirtualMemory, | 0_2_6CD88785 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD247B0 ZwWaitForKeyedEvent, | 0_2_6CD247B0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6A7B0 RtlDecodeRemotePointer,ZwQueryInformationProcess, | 0_2_6CD6A7B0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD247A0 ZwWaitForDebugEvent, | 0_2_6CD247A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD67BF memset,ZwTerminateProcess, | 0_2_6CCD67BF |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD947A0 RtlHeapTrkInitialize,ZwMapViewOfSection,ZwQueryPerformanceCounter,RtlCreateHeap,RtlSetHeapInformation,RtlAllocateHeap,RtlAllocateHeap,ZwUnmapViewOfSection,RtlDestroyHeap,ZwUnmapViewOfSection,ZwClose, | 0_2_6CD947A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24750 ZwUnmapViewOfSectionEx, | 0_2_6CD24750 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDA740 ZwClose,RtlFreeHeap, | 0_2_6CCDA740 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24740 ZwUnlockVirtualMemory, | 0_2_6CD24740 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24770 ZwUpdateWnfStateData, | 0_2_6CD24770 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDA760 EtwSetMark,ZwTraceEvent,RtlNtStatusToDosError, | 0_2_6CCDA760 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24760 ZwUnsubscribeWnfStateChange, | 0_2_6CD24760 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD10710 RtlAllocateHandle,RtlReAllocateHeap,RtlAllocateHandle,ZwAllocateVirtualMemory,ZwAllocateVirtualMemory,RtlAllocateHeap, | 0_2_6CD10710 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24710 ZwUnloadKey2, | 0_2_6CD24710 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24700 ZwUnloadKey, | 0_2_6CD24700 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD66700 RtlNewInstanceSecurityObject,ZwQueryInformationToken, | 0_2_6CD66700 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24730 ZwUnlockFile, | 0_2_6CD24730 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5C730 LdrAppxHandleIntegrityFailure,RtlQueryPackageIdentityEx,memset,ZwQueryValueKey,RtlFreeHeap,ZwClose,memset,memset,RtlCaptureContext,RtlReportException,ZwTerminateProcess, | 0_2_6CD5C730 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD20735 ZwAllocateVirtualMemory,ZwFreeVirtualMemory, | 0_2_6CD20735 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24720 ZwUnloadKeyEx, | 0_2_6CD24720 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD240D0 ZwQueryWnfStateNameInformation, | 0_2_6CD240D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD620DE ZwRaiseHardError, | 0_2_6CD620DE |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDBA0D1 ZwDeviceIoControlFile, | 0_2_6CDBA0D1 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD740DA ZwQueryVirtualMemory, | 0_2_6CD740DA |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1E0DF ZwDelayExecution, | 0_2_6CD1E0DF |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDC0C2 ZwAlertThreadByThreadId, | 0_2_6CCDC0C2 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD240C0 ZwQueryWnfStateData, | 0_2_6CD240C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE20DA ZwOpenThreadToken,ZwSetInformationThread,ZwClose, | 0_2_6CCE20DA |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6C0C0 RtlInitUnicodeString,ZwQueryValueKey, | 0_2_6CD6C0C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD640C9 ZwTerminateProcess,RtlLeaveCriticalSection, | 0_2_6CD640C9 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD220F0 RtlPublishWnfStateData,ZwUpdateWnfStateData,RtlGetCurrentServiceSessionId,RtlPublishWnfStateData, | 0_2_6CD220F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD240F0 ZwRaiseException, | 0_2_6CD240F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD240E0 ZwQueueApcThreadEx, | 0_2_6CD240E0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5E0E0 LdrCreateEnclave,ZwCreateEnclave,LdrCreateEnclave, | 0_2_6CD5E0E0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24090 ZwQuerySystemEnvironmentValueEx, | 0_2_6CD24090 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1C080 RtlImpersonateSelfEx,ZwOpenProcessTokenEx,ZwDuplicateToken,ZwSetInformationThread,ZwClose,ZwClose,RtlImpersonateSelfEx, | 0_2_6CD1C080 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24080 ZwQuerySystemEnvironmentValue, | 0_2_6CD24080 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD68080 ZwReadVirtualMemory, | 0_2_6CD68080 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1608F ZwOpenKey,ZwCreateKey, | 0_2_6CD1608F |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDA60B8 RtlAcquireSRWLockExclusive,ZwGetNlsSectionPtr,RtlAllocateHeap,RtlFreeHeap,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockExclusive, | 0_2_6CDA60B8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD240B0 ZwQueryTimerResolution, | 0_2_6CD240B0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD740A7 ZwSetInformationFile, | 0_2_6CD740A7 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD240A0 ZwQuerySystemInformationEx, | 0_2_6CD240A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5E0A0 DbgUiWaitStateChange,ZwWaitForDebugEvent, | 0_2_6CD5E0A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24050 ZwQuerySecurityPolicy, | 0_2_6CD24050 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24040 ZwQuerySecurityObject, | 0_2_6CD24040 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD16045 ZwClose, | 0_2_6CD16045 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD64043 ZwOpenFile,ZwQueryVirtualMemory,ZwOpenFile, | 0_2_6CD64043 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1A073 RtlInitUnicodeString,RtlInitAnsiString,RtlAnsiStringToUnicodeString,RtlInitUnicodeString,RtlInitUnicodeString,RtlInitUnicodeString,ZwRaiseHardError,RtlRaiseStatus,EtwTraceMessageVa,RtlNtStatusToDosError, | 0_2_6CD1A073 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24070 ZwQuerySymbolicLinkObject, | 0_2_6CD24070 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5E070 DbgUiStopDebugging,ZwRemoveProcessDebug, | 0_2_6CD5E070 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD06060 RtlCheckTokenMembershipEx,RtlCreateSecurityDescriptor,RtlSetOwnerSecurityDescriptor,RtlSetGroupSecurityDescriptor,RtlCreateAcl,RtlInitializeSidEx,RtlSetDaclSecurityDescriptor,ZwAccessCheck,RtlInitializeSidEx,ZwOpenThreadTokenEx,ZwOpenProcessTokenEx,ZwDuplicateToken,ZwClose,ZwClose,RtlCheckTokenMembershipEx, | 0_2_6CD06060 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24060 ZwQuerySemaphore, | 0_2_6CD24060 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9A060 RtlOsDeploymentState,RtlInitUnicodeString,ZwOpenKey,RtlInitUnicodeString,ZwQueryValueKey, | 0_2_6CD9A060 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24010 ZwQueryPortInformationProcess, | 0_2_6CD24010 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24000 ZwQueryOpenSubKeysEx, | 0_2_6CD24000 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4003 RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,ZwSetInformationJobObject,ZwQueryInformationJobObject,RtlReleaseSRWLockExclusive,RtlDebugPrintTimes, | 0_2_6CDB4003 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24030 ZwQuerySecurityAttributesToken, | 0_2_6CD24030 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6C03E RtlInitUnicodeString,ZwOpenKey,ZwClose, | 0_2_6CD6C03E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24020 ZwQueryQuotaInformationFile, | 0_2_6CD24020 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD241D0 ZwReplaceKey, | 0_2_6CD241D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD801D0 RtlAssert,RtlCaptureContext,DbgPrintEx,DbgPrompt,ZwTerminateThread,DbgPrintEx,RtlAssert,ZwTerminateProcess, | 0_2_6CD801D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD941CB ZwQueryVirtualMemory,bsearch_s, | 0_2_6CD941CB |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD241C0 ZwRenameTransactionManager, | 0_2_6CD241C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDA61C3 RtlAllocateHeap,ZwQueryWnfStateData,ZwUpdateWnfStateData,RtlFreeHeap, | 0_2_6CDA61C3 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9A1C0 RtlQueryValidationRunlevel,ZwOpenKey,ZwQueryValueKey,ZwClose, | 0_2_6CD9A1C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB41C0 TpQueryPoolStackInformation,ZwQueryInformationWorkerFactory, | 0_2_6CDB41C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1C1F0 RtlSetUnhandledExceptionFilter,RtlSetUnhandledExceptionFilter,ZwQueryInformationProcess,RtlRaiseStatus, | 0_2_6CD1C1F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD241F0 ZwReplyWaitReplyPort, | 0_2_6CD241F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB81F0 ZwQueryVirtualMemory,ZwPssCaptureVaSpaceBulk,ZwQueryVirtualMemory, | 0_2_6CDB81F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD241E0 ZwReplacePartitionUnit, | 0_2_6CD241E0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD641E2 ZwGetCachedSigningLevel,ZwCompareSigningLevels,ZwSetCachedSigningLevel, | 0_2_6CD641E2 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB61E5 RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CDB61E5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24190 ZwRemoveIoCompletionEx, | 0_2_6CD24190 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5E190 RtlFreeUserStack,ZwFreeVirtualMemory, | 0_2_6CD5E190 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6019F RtlGetCurrentServiceSessionId,RtlAllocateHeap,memcpy,RtlGetCurrentServiceSessionId,ZwTraceEvent,RtlFreeHeap, | 0_2_6CD6019F |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE819E ZwOpenProcessTokenEx,ZwDuplicateToken,ZwSetInformationObject,ZwSetInformationThread,ZwAdjustPrivilegesToken,ZwSetInformationThread, | 0_2_6CCE819E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE419F ZwCreateTimer2,ZwCreateWaitCompletionPacket,ZwAssociateWaitCompletionPacket,ZwClose, | 0_2_6CCE419F |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24180 ZwReleaseWorkerFactoryWorker, | 0_2_6CD24180 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD20185 ZwQuerySystemInformation,EtwpCreateEtwThread,RtlNtStatusToDosError,RtlNtStatusToDosError,ZwClose,RtlNtStatusToDosError, | 0_2_6CD20185 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDA197 RtlInitUnicodeStringEx,ZwQueryValueKey,RtlInitUnicodeStringEx,RtlPrefixUnicodeString,ZwEnumerateKey,ZwOpenKey,RtlInitUnicodeStringEx,ZwQueryValueKey,RtlFreeHeap,ZwClose,RtlAllocateHeap,RtlCompareUnicodeString,ZwClose,RtlFreeHeap,ZwClose, | 0_2_6CCDA197 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB6187 ZwSetInformationThread,memset,RtlRaiseException, | 0_2_6CDB6187 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD241B0 ZwRenameKey, | 0_2_6CD241B0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDBA1B6 ZwCreateFile, | 0_2_6CDBA1B6 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD241A0 ZwRemoveProcessDebug, | 0_2_6CD241A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD141A2 ZwAlertThreadByThreadId, | 0_2_6CD141A2 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24150 ZwRegisterProtocolAddressInformation, | 0_2_6CD24150 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0215F ZwQueryAttributesFile,RtlDeleteBoundaryDescriptor, | 0_2_6CD0215F |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24140 ZwRecoverTransactionManager, | 0_2_6CD24140 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD74144 RtlGetCurrentServiceSessionId,RtlGetCurrentServiceSessionId,RtlDetermineDosPathNameType_U,RtlDosPathNameToNtPathName_U,ZwQueryAttributesFile,RtlFreeHeap,RtlGetCurrentServiceSessionId,RtlGetCurrentServiceSessionId, | 0_2_6CD74144 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9A140 RtlQueryTokenHostIdAsUlong64,ZwQuerySecurityAttributesToken, | 0_2_6CD9A140 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB8142 ZwAllocateVirtualMemory,ZwFreeVirtualMemory,ZwQueryVirtualMemory, | 0_2_6CDB8142 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6154 RtlAcquireSRWLockExclusive,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlAllocateHeap,ZwDuplicateObject,RtlFreeHeap,RtlReleaseSRWLockExclusive,RtlWakeConditionVariable, | 0_2_6CCE6154 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24170 ZwReleaseKeyedEvent, | 0_2_6CD24170 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6417C ZwRaiseHardError, | 0_2_6CD6417C |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24160 ZwRegisterThreadTerminatePort, | 0_2_6CD24160 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22160 RtlCreateUserStack,RtlImageNtHeader,ZwSetInformationProcess,ZwAllocateVirtualMemory,ZwAllocateVirtualMemory,RtlFreeUserStack,RtlCreateUserStack,RtlCreateUserStack,RtlCreateUserStack, | 0_2_6CD22160 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDBA160 RtlGetNtSystemRoot,ZwClose, | 0_2_6CDBA160 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24110 ZwReadOnlyEnlistment, | 0_2_6CD24110 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9A11F ZwClose, | 0_2_6CD9A11F |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE2102 TpSetDefaultPoolMaxThreads,ZwDuplicateToken, | 0_2_6CCE2102 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24100 ZwRaiseHardError, | 0_2_6CD24100 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD74104 ZwQueryInformationFile, | 0_2_6CD74104 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD8E10E ZwQuerySecurityObject,RtlAllocateHeap,ZwQuerySecurityObject,RtlFreeHeap,RtlGetDaclSecurityDescriptor,RtlGetOwnerSecurityDescriptor,RtlEqualSid,RtlGetAce,RtlEqualSid,ZwSetSecurityObject,RtlSelfRelativeToAbsoluteSD2,RtlAllocateHeap,memcpy,RtlFreeHeap,RtlSelfRelativeToAbsoluteSD2,RtlFreeHeap,RtlSetOwnerSecurityDescriptor,RtlSetDaclSecurityDescriptor,RtlMakeSelfRelativeSD,RtlAllocateHeap,RtlMakeSelfRelativeSD,RtlFreeHeap,ZwSetSecurityObject,RtlFreeHeap, | 0_2_6CD8E10E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD68100 RtlSetProcessDebugInformation,ZwUnmapViewOfSection,RtlExitUserThread, | 0_2_6CD68100 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6C137 ZwQueryVirtualMemory,ZwQuerySystemInformation,ZwAllocateVirtualMemory,ZwProtectVirtualMemory, | 0_2_6CD6C137 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24130 ZwRecoverResourceManager, | 0_2_6CD24130 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6013A ZwOpenKeyEx,ZwClose, | 0_2_6CD6013A |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24120 ZwRecoverEnlistment, | 0_2_6CD24120 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD242D0 ZwSaveMergedKeys, | 0_2_6CD242D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB62D6 RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CDB62D6 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD242C0 ZwSaveKeyEx, | 0_2_6CD242C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD622C5 ZwOpenKey,ZwQueryValueKey,ZwClose, | 0_2_6CD622C5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD702C0 RtlQueryImageMitigationPolicy,RtlInitUnicodeStringEx,RtlInitUnicodeStringEx,ZwOpenKey,ZwQueryValueKey,ZwClose,memcpy,RtlQueryImageMitigationPolicy, | 0_2_6CD702C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD942F9 ZwQueryVirtualMemory,ZwQueryVirtualMemory,RtlImageDirectoryEntryToData, | 0_2_6CD942F9 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD242F0 ZwSerializeBoot, | 0_2_6CD242F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDCCC8 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDCCC8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD8CD0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCD8CD0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD12CF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD12CF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD12CF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD12CF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD12CF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD12CF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD12CF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD12CF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD8C8D mov eax, dword ptr fs:[00000030h] | 0_2_6CCD8C8D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD08CB1 mov eax, dword ptr fs:[00000030h] | 0_2_6CD08CB1 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD08CB1 mov eax, dword ptr fs:[00000030h] | 0_2_6CD08CB1 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CD90CB5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CD90CB5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CD90CB5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CD90CB5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CD90CB5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CD90CB5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CD90CB5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CD90CB5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CD90CB5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CD90CB5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CD90CB5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CD90CB5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CD90CB5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5CCA0 mov ecx, dword ptr fs:[00000030h] | 0_2_6CD5CCA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5CCA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD5CCA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5CCA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD5CCA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5CCA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD5CCA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD14C59 mov eax, dword ptr fs:[00000030h] | 0_2_6CD14C59 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEAC50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEAC50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEAC50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEAC50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEAC50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEAC50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEAC50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEAC50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEAC50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEAC50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEAC50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEAC50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6C50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE6C50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6C50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE6C50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6C50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE6C50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD7AC60 mov eax, dword ptr fs:[00000030h] | 0_2_6CD7AC60 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD7AC60 mov eax, dword ptr fs:[00000030h] | 0_2_6CD7AC60 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF0C00 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF0C00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF0C00 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF0C00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF0C00 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF0C00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF0C00 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF0C00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1CC00 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1CC00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD64C0F mov eax, dword ptr fs:[00000030h] | 0_2_6CD64C0F |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD84C34 mov eax, dword ptr fs:[00000030h] | 0_2_6CD84C34 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD84C34 mov eax, dword ptr fs:[00000030h] | 0_2_6CD84C34 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD84C34 mov eax, dword ptr fs:[00000030h] | 0_2_6CD84C34 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD84C34 mov eax, dword ptr fs:[00000030h] | 0_2_6CD84C34 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD84C34 mov eax, dword ptr fs:[00000030h] | 0_2_6CD84C34 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD84C34 mov eax, dword ptr fs:[00000030h] | 0_2_6CD84C34 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD84C34 mov ecx, dword ptr fs:[00000030h] | 0_2_6CD84C34 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDEC20 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDEC20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD7CC20 mov eax, dword ptr fs:[00000030h] | 0_2_6CD7CC20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD7CC20 mov eax, dword ptr fs:[00000030h] | 0_2_6CD7CC20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD64DD7 mov eax, dword ptr fs:[00000030h] | 0_2_6CD64DD7 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD64DD7 mov eax, dword ptr fs:[00000030h] | 0_2_6CD64DD7 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0EDD3 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0EDD3 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0EDD3 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0EDD3 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0CDF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0CDF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0CDF0 mov ecx, dword ptr fs:[00000030h] | 0_2_6CD0CDF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDCDEA mov eax, dword ptr fs:[00000030h] | 0_2_6CCDCDEA |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDCDEA mov eax, dword ptr fs:[00000030h] | 0_2_6CCDCDEA |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD80DF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD80DF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD80DF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD80DF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD00DE1 mov eax, dword ptr fs:[00000030h] | 0_2_6CD00DE1 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD6DF6 mov eax, dword ptr fs:[00000030h] | 0_2_6CCD6DF6 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1CDB1 mov ecx, dword ptr fs:[00000030h] | 0_2_6CD1CDB1 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1CDB1 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1CDB1 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1CDB1 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1CDB1 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD08DBF mov eax, dword ptr fs:[00000030h] | 0_2_6CD08DBF |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD08DBF mov eax, dword ptr fs:[00000030h] | 0_2_6CD08DBF |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD16DA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD16DA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDA8DAE mov eax, dword ptr fs:[00000030h] | 0_2_6CDA8DAE |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDA8DAE mov eax, dword ptr fs:[00000030h] | 0_2_6CDA8DAE |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4DAD mov eax, dword ptr fs:[00000030h] | 0_2_6CDB4DAD |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE0D59 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE0D59 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE0D59 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE0D59 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE0D59 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE0D59 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE8D59 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE8D59 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE8D59 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE8D59 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE8D59 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE8D59 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE8D59 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE8D59 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE8D59 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE8D59 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD78D6B mov eax, dword ptr fs:[00000030h] | 0_2_6CD78D6B |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD98D10 mov eax, dword ptr fs:[00000030h] | 0_2_6CD98D10 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD98D10 mov eax, dword ptr fs:[00000030h] | 0_2_6CD98D10 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD14D1D mov eax, dword ptr fs:[00000030h] | 0_2_6CD14D1D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCFAD00 mov eax, dword ptr fs:[00000030h] | 0_2_6CCFAD00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCFAD00 mov eax, dword ptr fs:[00000030h] | 0_2_6CCFAD00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCFAD00 mov eax, dword ptr fs:[00000030h] | 0_2_6CCFAD00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD6D10 mov eax, dword ptr fs:[00000030h] | 0_2_6CCD6D10 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD6D10 mov eax, dword ptr fs:[00000030h] | 0_2_6CCD6D10 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD6D10 mov eax, dword ptr fs:[00000030h] | 0_2_6CCD6D10 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4D30 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB4D30 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD68D20 mov eax, dword ptr fs:[00000030h] | 0_2_6CD68D20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD96ED0 mov ecx, dword ptr fs:[00000030h] | 0_2_6CD96ED0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD18EF5 mov eax, dword ptr fs:[00000030h] | 0_2_6CD18EF5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6EE0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE6EE0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6EE0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE6EE0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6EE0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE6EE0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6EE0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE6EE0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD12E9C mov eax, dword ptr fs:[00000030h] | 0_2_6CD12E9C |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD12E9C mov ecx, dword ptr fs:[00000030h] | 0_2_6CD12E9C |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDAE90 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDAE90 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDAE90 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDAE90 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDAE90 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDAE90 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD7AEB0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD7AEB0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD7AEB0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD7AEB0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD96EB0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD96EB0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6CEA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD6CEA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6CEA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD6CEA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6CEA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD6CEA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB2E4F mov eax, dword ptr fs:[00000030h] | 0_2_6CDB2E4F |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB2E4F mov eax, dword ptr fs:[00000030h] | 0_2_6CDB2E4F |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDEE5A mov eax, dword ptr fs:[00000030h] | 0_2_6CCDEE5A |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD60E7F mov eax, dword ptr fs:[00000030h] | 0_2_6CD60E7F |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD60E7F mov eax, dword ptr fs:[00000030h] | 0_2_6CD60E7F |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD60E7F mov eax, dword ptr fs:[00000030h] | 0_2_6CD60E7F |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6E71 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE6E71 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD18E1A mov eax, dword ptr fs:[00000030h] | 0_2_6CD18E1A |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD8E1D mov eax, dword ptr fs:[00000030h] | 0_2_6CCD8E1D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0AE00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0AE00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0AE00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0AE00 mov ecx, dword ptr fs:[00000030h] | 0_2_6CD0AE00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0AE00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0AE00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0AE00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0AE00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0AE00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0AE00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD14E30 mov eax, dword ptr fs:[00000030h] | 0_2_6CD14E30 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD76E20 mov eax, dword ptr fs:[00000030h] | 0_2_6CD76E20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD76E20 mov eax, dword ptr fs:[00000030h] | 0_2_6CD76E20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD76E20 mov ecx, dword ptr fs:[00000030h] | 0_2_6CD76E20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE2FC8 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE2FC8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE2FC8 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE2FC8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE2FC8 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE2FC8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE2FC8 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE2FC8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDEFD8 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDEFD8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDEFD8 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDEFD8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDEFD8 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDEFD8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD20FF6 mov eax, dword ptr fs:[00000030h] | 0_2_6CD20FF6 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD20FF6 mov eax, dword ptr fs:[00000030h] | 0_2_6CD20FF6 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD20FF6 mov eax, dword ptr fs:[00000030h] | 0_2_6CD20FF6 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD20FF6 mov eax, dword ptr fs:[00000030h] | 0_2_6CD20FF6 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD96FF7 mov eax, dword ptr fs:[00000030h] | 0_2_6CD96FF7 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCFCFE0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCFCFE0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4FE7 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB4FE7 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD8FF0 mov ecx, dword ptr fs:[00000030h] | 0_2_6CCD8FF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD8FF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCD8FF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD12F98 mov eax, dword ptr fs:[00000030h] | 0_2_6CD12F98 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD12F98 mov eax, dword ptr fs:[00000030h] | 0_2_6CD12F98 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1CF80 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1CF80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1CF50 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1CF50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD80F50 mov eax, dword ptr fs:[00000030h] | 0_2_6CD80F50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD64F40 mov eax, dword ptr fs:[00000030h] | 0_2_6CD64F40 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD64F40 mov eax, dword ptr fs:[00000030h] | 0_2_6CD64F40 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD64F40 mov eax, dword ptr fs:[00000030h] | 0_2_6CD64F40 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD64F40 mov eax, dword ptr fs:[00000030h] | 0_2_6CD64F40 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD84F42 mov eax, dword ptr fs:[00000030h] | 0_2_6CD84F42 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDCF50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDCF50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDCF50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDCF50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDCF50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDCF50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDCF50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDCF50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDCF50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDCF50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDCF50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDCF50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD16F60 mov eax, dword ptr fs:[00000030h] | 0_2_6CD16F60 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD16F60 mov eax, dword ptr fs:[00000030h] | 0_2_6CD16F60 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4F68 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB4F68 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD82F60 mov eax, dword ptr fs:[00000030h] | 0_2_6CD82F60 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD82F60 mov eax, dword ptr fs:[00000030h] | 0_2_6CD82F60 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0AF69 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0AF69 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0AF69 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0AF69 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD24F10 mov eax, dword ptr fs:[00000030h] | 0_2_6CD24F10 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1CF1F mov eax, dword ptr fs:[00000030h] | 0_2_6CD1CF1F |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD96F00 mov eax, dword ptr fs:[00000030h] | 0_2_6CD96F00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE2F12 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE2F12 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0EF28 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0EF28 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0E8C0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0E8C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB08C0 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB08C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1C8F9 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1C8F9 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1C8F9 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1C8F9 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE28F0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE28F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE28F0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE28F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE28F0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE28F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE28F0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE28F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE28F0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE28F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE28F0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE28F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDAA8E4 mov eax, dword ptr fs:[00000030h] | 0_2_6CDAA8E4 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE0887 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE0887 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6C89D mov eax, dword ptr fs:[00000030h] | 0_2_6CD6C89D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD10854 mov eax, dword ptr fs:[00000030h] | 0_2_6CD10854 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE4859 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE4859 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE4859 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE4859 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6E872 mov eax, dword ptr fs:[00000030h] | 0_2_6CD6E872 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6E872 mov eax, dword ptr fs:[00000030h] | 0_2_6CD6E872 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD76870 mov eax, dword ptr fs:[00000030h] | 0_2_6CD76870 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD76870 mov eax, dword ptr fs:[00000030h] | 0_2_6CD76870 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6C810 mov eax, dword ptr fs:[00000030h] | 0_2_6CD6C810 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1A830 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1A830 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD8483A mov eax, dword ptr fs:[00000030h] | 0_2_6CD8483A |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD8483A mov eax, dword ptr fs:[00000030h] | 0_2_6CD8483A |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD02835 mov eax, dword ptr fs:[00000030h] | 0_2_6CD02835 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD02835 mov eax, dword ptr fs:[00000030h] | 0_2_6CD02835 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD02835 mov eax, dword ptr fs:[00000030h] | 0_2_6CD02835 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD02835 mov ecx, dword ptr fs:[00000030h] | 0_2_6CD02835 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD02835 mov eax, dword ptr fs:[00000030h] | 0_2_6CD02835 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD02835 mov eax, dword ptr fs:[00000030h] | 0_2_6CD02835 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD149D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD149D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDAA9D3 mov eax, dword ptr fs:[00000030h] | 0_2_6CDAA9D3 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD769C0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD769C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEA9D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEA9D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEA9D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEA9D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEA9D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEA9D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEA9D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEA9D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEA9D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEA9D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEA9D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEA9D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD129F9 mov eax, dword ptr fs:[00000030h] | 0_2_6CD129F9 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD129F9 mov eax, dword ptr fs:[00000030h] | 0_2_6CD129F9 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6E9E0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD6E9E0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE09AD mov eax, dword ptr fs:[00000030h] | 0_2_6CCE09AD |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE09AD mov eax, dword ptr fs:[00000030h] | 0_2_6CCE09AD |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD689B3 mov esi, dword ptr fs:[00000030h] | 0_2_6CD689B3 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD689B3 mov eax, dword ptr fs:[00000030h] | 0_2_6CD689B3 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD689B3 mov eax, dword ptr fs:[00000030h] | 0_2_6CD689B3 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF29A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF29A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF29A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF29A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF29A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF29A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF29A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF29A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF29A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF29A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF29A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF29A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCF29A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1A950 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1A950 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD60946 mov eax, dword ptr fs:[00000030h] | 0_2_6CD60946 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4940 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB4940 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD84978 mov eax, dword ptr fs:[00000030h] | 0_2_6CD84978 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD84978 mov eax, dword ptr fs:[00000030h] | 0_2_6CD84978 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1C970 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1C970 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1C970 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1C970 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6C97C mov eax, dword ptr fs:[00000030h] | 0_2_6CD6C97C |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD06962 mov eax, dword ptr fs:[00000030h] | 0_2_6CD06962 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD06962 mov eax, dword ptr fs:[00000030h] | 0_2_6CD06962 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD06962 mov eax, dword ptr fs:[00000030h] | 0_2_6CD06962 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD2096E mov eax, dword ptr fs:[00000030h] | 0_2_6CD2096E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD2096E mov edx, dword ptr fs:[00000030h] | 0_2_6CD2096E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD2096E mov eax, dword ptr fs:[00000030h] | 0_2_6CD2096E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6C912 mov eax, dword ptr fs:[00000030h] | 0_2_6CD6C912 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD8918 mov eax, dword ptr fs:[00000030h] | 0_2_6CCD8918 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD8918 mov eax, dword ptr fs:[00000030h] | 0_2_6CCD8918 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5E908 mov eax, dword ptr fs:[00000030h] | 0_2_6CD5E908 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5E908 mov eax, dword ptr fs:[00000030h] | 0_2_6CD5E908 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6892A mov eax, dword ptr fs:[00000030h] | 0_2_6CD6892A |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD7892B mov eax, dword ptr fs:[00000030h] | 0_2_6CD7892B |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD14AD0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD14AD0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD14AD0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD14AD0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE0AD0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE0AD0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD36ACC mov eax, dword ptr fs:[00000030h] | 0_2_6CD36ACC |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD36ACC mov eax, dword ptr fs:[00000030h] | 0_2_6CD36ACC |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD36ACC mov eax, dword ptr fs:[00000030h] | 0_2_6CD36ACC |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1AAEE mov eax, dword ptr fs:[00000030h] | 0_2_6CD1AAEE |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1AAEE mov eax, dword ptr fs:[00000030h] | 0_2_6CD1AAEE |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD18A90 mov edx, dword ptr fs:[00000030h] | 0_2_6CD18A90 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDEA80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDEA80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEEA80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEEA80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEEA80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEEA80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEEA80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEEA80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEEA80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEEA80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CCEEA80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4A80 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB4A80 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE8AA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE8AA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE8AA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE8AA0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD36AA4 mov eax, dword ptr fs:[00000030h] | 0_2_6CD36AA4 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD10A50 mov eax, dword ptr fs:[00000030h] | 0_2_6CD10A50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF0A5B mov eax, dword ptr fs:[00000030h] | 0_2_6CCF0A5B |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF0A5B mov eax, dword ptr fs:[00000030h] | 0_2_6CCF0A5B |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6A50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE6A50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6A50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE6A50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6A50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE6A50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6A50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE6A50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6A50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE6A50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6A50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE6A50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE6A50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE6A50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5CA72 mov eax, dword ptr fs:[00000030h] | 0_2_6CD5CA72 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5CA72 mov eax, dword ptr fs:[00000030h] | 0_2_6CD5CA72 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD8EA60 mov eax, dword ptr fs:[00000030h] | 0_2_6CD8EA60 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1CA6F mov eax, dword ptr fs:[00000030h] | 0_2_6CD1CA6F |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1CA6F mov eax, dword ptr fs:[00000030h] | 0_2_6CD1CA6F |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1CA6F mov eax, dword ptr fs:[00000030h] | 0_2_6CD1CA6F |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6CA11 mov eax, dword ptr fs:[00000030h] | 0_2_6CD6CA11 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD04A35 mov eax, dword ptr fs:[00000030h] | 0_2_6CD04A35 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD04A35 mov eax, dword ptr fs:[00000030h] | 0_2_6CD04A35 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1CA38 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1CA38 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1CA24 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1CA24 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0EA2E mov eax, dword ptr fs:[00000030h] | 0_2_6CD0EA2E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE0BCD mov eax, dword ptr fs:[00000030h] | 0_2_6CCE0BCD |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE0BCD mov eax, dword ptr fs:[00000030h] | 0_2_6CCE0BCD |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE0BCD mov eax, dword ptr fs:[00000030h] | 0_2_6CCE0BCD |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD8EBD0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD8EBD0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD00BCB mov eax, dword ptr fs:[00000030h] | 0_2_6CD00BCB |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD00BCB mov eax, dword ptr fs:[00000030h] | 0_2_6CD00BCB |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD00BCB mov eax, dword ptr fs:[00000030h] | 0_2_6CD00BCB |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD18BF0 mov ecx, dword ptr fs:[00000030h] | 0_2_6CD18BF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD18BF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD18BF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD18BF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD18BF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6CBF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD6CBF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0EBFC mov eax, dword ptr fs:[00000030h] | 0_2_6CD0EBFC |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE8BF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE8BF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE8BF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE8BF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE8BF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE8BF0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD94BB0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD94BB0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD94BB0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD94BB0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF0BBE mov eax, dword ptr fs:[00000030h] | 0_2_6CCF0BBE |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF0BBE mov eax, dword ptr fs:[00000030h] | 0_2_6CCF0BBE |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD8EB50 mov eax, dword ptr fs:[00000030h] | 0_2_6CD8EB50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB2B57 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB2B57 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB2B57 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB2B57 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB2B57 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB2B57 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB2B57 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB2B57 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD94B4B mov eax, dword ptr fs:[00000030h] | 0_2_6CD94B4B |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD94B4B mov eax, dword ptr fs:[00000030h] | 0_2_6CD94B4B |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD76B40 mov eax, dword ptr fs:[00000030h] | 0_2_6CD76B40 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD76B40 mov eax, dword ptr fs:[00000030h] | 0_2_6CD76B40 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD88B42 mov eax, dword ptr fs:[00000030h] | 0_2_6CD88B42 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDAAB40 mov eax, dword ptr fs:[00000030h] | 0_2_6CDAAB40 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD8B50 mov eax, dword ptr fs:[00000030h] | 0_2_6CCD8B50 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDCB7E mov eax, dword ptr fs:[00000030h] | 0_2_6CCDCB7E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CD5EB1D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CD5EB1D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CD5EB1D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CD5EB1D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CD5EB1D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CD5EB1D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CD5EB1D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CD5EB1D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CD5EB1D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4B00 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB4B00 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0EB20 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0EB20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0EB20 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0EB20 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE04E5 mov ecx, dword ptr fs:[00000030h] | 0_2_6CCE04E5 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9A49A mov eax, dword ptr fs:[00000030h] | 0_2_6CD9A49A |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD144B0 mov ecx, dword ptr fs:[00000030h] | 0_2_6CD144B0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE64AB mov eax, dword ptr fs:[00000030h] | 0_2_6CCE64AB |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6A4B0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD6A4B0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0245A mov eax, dword ptr fs:[00000030h] | 0_2_6CD0245A |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD9A456 mov eax, dword ptr fs:[00000030h] | 0_2_6CD9A456 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD645D mov eax, dword ptr fs:[00000030h] | 0_2_6CCD645D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1E443 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1E443 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1E443 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1E443 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1E443 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1E443 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1E443 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1E443 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1E443 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1E443 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1E443 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1E443 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1E443 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1E443 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1E443 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1E443 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0A470 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0A470 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0A470 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0A470 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0A470 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0A470 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6C460 mov ecx, dword ptr fs:[00000030h] | 0_2_6CD6C460 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD18402 mov eax, dword ptr fs:[00000030h] | 0_2_6CD18402 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD18402 mov eax, dword ptr fs:[00000030h] | 0_2_6CD18402 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD18402 mov eax, dword ptr fs:[00000030h] | 0_2_6CD18402 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1A430 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1A430 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDC427 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDC427 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDE420 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDE420 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDE420 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDE420 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDE420 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDE420 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD66420 mov eax, dword ptr fs:[00000030h] | 0_2_6CD66420 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD66420 mov eax, dword ptr fs:[00000030h] | 0_2_6CD66420 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD66420 mov eax, dword ptr fs:[00000030h] | 0_2_6CD66420 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD66420 mov eax, dword ptr fs:[00000030h] | 0_2_6CD66420 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD66420 mov eax, dword ptr fs:[00000030h] | 0_2_6CD66420 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD66420 mov eax, dword ptr fs:[00000030h] | 0_2_6CD66420 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD66420 mov eax, dword ptr fs:[00000030h] | 0_2_6CD66420 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1A5D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1A5D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1A5D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1A5D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1E5CF mov eax, dword ptr fs:[00000030h] | 0_2_6CD1E5CF |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1E5CF mov eax, dword ptr fs:[00000030h] | 0_2_6CD1E5CF |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE65D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE65D0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE25E0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE25E0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1C5ED mov eax, dword ptr fs:[00000030h] | 0_2_6CD1C5ED |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1C5ED mov eax, dword ptr fs:[00000030h] | 0_2_6CD1C5ED |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE2582 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE2582 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE2582 mov ecx, dword ptr fs:[00000030h] | 0_2_6CCE2582 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDA580 mov ecx, dword ptr fs:[00000030h] | 0_2_6CCDA580 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDA580 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDA580 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1E59C mov eax, dword ptr fs:[00000030h] | 0_2_6CD1E59C |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD14588 mov eax, dword ptr fs:[00000030h] | 0_2_6CD14588 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD045B1 mov eax, dword ptr fs:[00000030h] | 0_2_6CD045B1 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD045B1 mov eax, dword ptr fs:[00000030h] | 0_2_6CD045B1 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE8550 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE8550 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE8550 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE8550 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD76500 mov eax, dword ptr fs:[00000030h] | 0_2_6CD76500 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4500 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB4500 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4500 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB4500 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4500 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB4500 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4500 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB4500 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4500 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB4500 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4500 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB4500 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDB4500 mov eax, dword ptr fs:[00000030h] | 0_2_6CDB4500 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0E53E mov eax, dword ptr fs:[00000030h] | 0_2_6CD0E53E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0E53E mov eax, dword ptr fs:[00000030h] | 0_2_6CD0E53E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0E53E mov eax, dword ptr fs:[00000030h] | 0_2_6CD0E53E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0E53E mov eax, dword ptr fs:[00000030h] | 0_2_6CD0E53E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0E53E mov eax, dword ptr fs:[00000030h] | 0_2_6CD0E53E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1A6C7 mov ebx, dword ptr fs:[00000030h] | 0_2_6CD1A6C7 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1A6C7 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1A6C7 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5E6F2 mov eax, dword ptr fs:[00000030h] | 0_2_6CD5E6F2 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5E6F2 mov eax, dword ptr fs:[00000030h] | 0_2_6CD5E6F2 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5E6F2 mov eax, dword ptr fs:[00000030h] | 0_2_6CD5E6F2 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5E6F2 mov eax, dword ptr fs:[00000030h] | 0_2_6CD5E6F2 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD606F1 mov eax, dword ptr fs:[00000030h] | 0_2_6CD606F1 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD606F1 mov eax, dword ptr fs:[00000030h] | 0_2_6CD606F1 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE4690 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE4690 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE4690 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE4690 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD166B0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD166B0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1C6A6 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1C6A6 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCFC640 mov eax, dword ptr fs:[00000030h] | 0_2_6CCFC640 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD12674 mov eax, dword ptr fs:[00000030h] | 0_2_6CD12674 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1A660 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1A660 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1A660 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1A660 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF260B mov eax, dword ptr fs:[00000030h] | 0_2_6CCF260B |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF260B mov eax, dword ptr fs:[00000030h] | 0_2_6CCF260B |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF260B mov eax, dword ptr fs:[00000030h] | 0_2_6CCF260B |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF260B mov eax, dword ptr fs:[00000030h] | 0_2_6CCF260B |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF260B mov eax, dword ptr fs:[00000030h] | 0_2_6CCF260B |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF260B mov eax, dword ptr fs:[00000030h] | 0_2_6CCF260B |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCF260B mov eax, dword ptr fs:[00000030h] | 0_2_6CCF260B |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22619 mov eax, dword ptr fs:[00000030h] | 0_2_6CD22619 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5E609 mov eax, dword ptr fs:[00000030h] | 0_2_6CD5E609 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE262C mov eax, dword ptr fs:[00000030h] | 0_2_6CCE262C |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCFE627 mov eax, dword ptr fs:[00000030h] | 0_2_6CCFE627 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD16620 mov eax, dword ptr fs:[00000030h] | 0_2_6CD16620 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD18620 mov eax, dword ptr fs:[00000030h] | 0_2_6CD18620 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD067C0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD067C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD067C0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD067C0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD607C3 mov eax, dword ptr fs:[00000030h] | 0_2_6CD607C3 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1C7F0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1C7F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE47FB mov eax, dword ptr fs:[00000030h] | 0_2_6CCE47FB |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE47FB mov eax, dword ptr fs:[00000030h] | 0_2_6CCE47FB |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6E7E1 mov eax, dword ptr fs:[00000030h] | 0_2_6CD6E7E1 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD027ED mov eax, dword ptr fs:[00000030h] | 0_2_6CD027ED |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD027ED mov eax, dword ptr fs:[00000030h] | 0_2_6CD027ED |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD027ED mov eax, dword ptr fs:[00000030h] | 0_2_6CD027ED |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD8678E mov eax, dword ptr fs:[00000030h] | 0_2_6CD8678E |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE07AF mov eax, dword ptr fs:[00000030h] | 0_2_6CCE07AF |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD947A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD947A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22750 mov eax, dword ptr fs:[00000030h] | 0_2_6CD22750 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD22750 mov eax, dword ptr fs:[00000030h] | 0_2_6CD22750 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD64755 mov eax, dword ptr fs:[00000030h] | 0_2_6CD64755 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD6E75D mov eax, dword ptr fs:[00000030h] | 0_2_6CD6E75D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDA740 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDA740 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1674D mov esi, dword ptr fs:[00000030h] | 0_2_6CD1674D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1674D mov eax, dword ptr fs:[00000030h] | 0_2_6CD1674D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1674D mov eax, dword ptr fs:[00000030h] | 0_2_6CD1674D |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE0750 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE0750 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE8770 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE8770 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD10710 mov eax, dword ptr fs:[00000030h] | 0_2_6CD10710 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1C700 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1C700 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE0710 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE0710 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD5C730 mov eax, dword ptr fs:[00000030h] | 0_2_6CD5C730 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1273C mov eax, dword ptr fs:[00000030h] | 0_2_6CD1273C |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1273C mov ecx, dword ptr fs:[00000030h] | 0_2_6CD1273C |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1273C mov eax, dword ptr fs:[00000030h] | 0_2_6CD1273C |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1C720 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1C720 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1C720 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1C720 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD620DE mov eax, dword ptr fs:[00000030h] | 0_2_6CD620DE |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD220F0 mov ecx, dword ptr fs:[00000030h] | 0_2_6CD220F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE80E9 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE80E9 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDA0E3 mov ecx, dword ptr fs:[00000030h] | 0_2_6CCDA0E3 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD660E0 mov eax, dword ptr fs:[00000030h] | 0_2_6CD660E0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCDC0F0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCDC0F0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE208A mov eax, dword ptr fs:[00000030h] | 0_2_6CCE208A |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDA60B8 mov eax, dword ptr fs:[00000030h] | 0_2_6CDA60B8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CDA60B8 mov ecx, dword ptr fs:[00000030h] | 0_2_6CDA60B8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCD80A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CCD80A0 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD780A8 mov eax, dword ptr fs:[00000030h] | 0_2_6CD780A8 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD66050 mov eax, dword ptr fs:[00000030h] | 0_2_6CD66050 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CCE2050 mov eax, dword ptr fs:[00000030h] | 0_2_6CCE2050 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD0C073 mov eax, dword ptr fs:[00000030h] | 0_2_6CD0C073 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD1A060 mov eax, dword ptr fs:[00000030h] | 0_2_6CD1A060 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD64000 mov ecx, dword ptr fs:[00000030h] | 0_2_6CD64000 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD82000 mov eax, dword ptr fs:[00000030h] | 0_2_6CD82000 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD82000 mov eax, dword ptr fs:[00000030h] | 0_2_6CD82000 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD82000 mov eax, dword ptr fs:[00000030h] | 0_2_6CD82000 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD82000 mov eax, dword ptr fs:[00000030h] | 0_2_6CD82000 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD82000 mov eax, dword ptr fs:[00000030h] | 0_2_6CD82000 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD82000 mov eax, dword ptr fs:[00000030h] | 0_2_6CD82000 |
Source: C:\Users\user\Desktop\0di3x.exe | Code function: 0_2_6CD82000 mov eax, dword ptr fs:[00000030h] | 0_2_6CD82000 |