Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_00401B4B NtQuerySystemInformation, | 0_2_00401B4B |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_00401B2F NtQueryInformationProcess, | 0_2_00401B2F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF12CF0 memcpy,RtlGetNtSystemRoot,RtlInitUnicodeString,memcpy,ZwOpenKey,ZwClose,ZwEnumerateKey,DbgPrintEx,DbgPrintEx,DbgPrintEx, | 0_2_6CF12CF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22CF0 ZwOpenProcess, | 0_2_6CF22CF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22CE0 ZwQueryInformationThread, | 0_2_6CF22CE0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22CD0 ZwOpenThreadToken, | 0_2_6CF22CD0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF38CD0 RtlRaiseException,RtlCaptureContext,ZwRaiseException,RtlRaiseStatus, | 0_2_6CF38CD0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDCCC8 memset,RtlInitUnicodeString,ZwOpenKey,RtlInitUnicodeString,ZwClose,RtlFreeHeap,RtlInitUnicodeString,RtlCultureNameToLCID,RtlInitUnicodeString,RtlCultureNameToLCID, | 0_2_6CEDCCC8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF7ACD0 RtlQueryCriticalSectionOwner,ZwReadVirtualMemory,RtlQueryCriticalSectionOwner, | 0_2_6CF7ACD0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22CC0 ZwQueryVirtualMemory, | 0_2_6CF22CC0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB0CC0 EtwRegisterSecurityProvider,ZwTraceControl,RtlNtStatusToDosError,RtlSetLastWin32Error, | 0_2_6CFB0CC0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6ACC8 ZwClose,ZwUnmapViewOfSection,ZwClose,ZwClose,ZwClose,ZwClose, | 0_2_6CF6ACC8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF08CB1 RtlInitUnicodeString,ZwQueryLicenseValue,RtlAllocateHeap,ZwQueryLicenseValue,RtlFreeHeap, | 0_2_6CF08CB1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22CB0 ZwRequestWaitReplyPort, | 0_2_6CF22CB0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF90CB5 ZwAllocateVirtualMemory,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint,DbgPrint, | 0_2_6CF90CB5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22CA0 ZwQueryInformationToken, | 0_2_6CF22CA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5CCA0 RtlAppxIsFileOwnedByTrustedInstaller,ZwQuerySecurityObject,RtlAllocateHeap,ZwQuerySecurityObject,RtlGetOwnerSecurityDescriptor,RtlCreateServiceSid,RtlAllocateHeap,RtlCreateServiceSid,RtlEqualSid,RtlFreeHeap,RtlFreeHeap, | 0_2_6CF5CCA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF66CA0 RtlCreateQueryDebugBuffer,ZwCreateSection,ZwMapViewOfSection,ZwAllocateVirtualMemory,ZwAllocateVirtualMemory,ZwFreeVirtualMemory,ZwFreeVirtualMemory,ZwUnmapViewOfSection,ZwClose, | 0_2_6CF66CA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED8C8D RtlFreeHeap,ZwSetEvent,ZwAlertThreadByThreadId, | 0_2_6CED8C8D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22C90 ZwReleaseMutant, | 0_2_6CF22C90 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22C80 ZwImpersonateClientOfPort, | 0_2_6CF22C80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22C70 ZwFreeVirtualMemory, | 0_2_6CF22C70 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDEC6B RtlGetSuiteMask,TpSetPoolWorkerThreadIdleTimeout,TpSetPoolMaxThreads,NtLockProductActivationKeys,TpAllocWork, | 0_2_6CEDEC6B |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22C60 ZwCreateKey, | 0_2_6CF22C60 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6EC65 ZwWow64CsrCaptureMessageString, | 0_2_6CF6EC65 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22C50 ZwSetInformationProcess, | 0_2_6CF22C50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22C40 ZwWriteFileGather, | 0_2_6CF22C40 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24C40 RtlUnhandledExceptionFilter,ZwTerminateProcess, | 0_2_6CF24C40 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEAC50 LdrpResGetMappingSize,RtlImageNtHeaderEx,ZwQueryVirtualMemory,LdrpResGetMappingSize,RtlGetCurrentServiceSessionId,LdrpResGetMappingSize,RtlGetCurrentServiceSessionId, | 0_2_6CEEAC50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22C30 ZwWaitForMultipleObjects32, | 0_2_6CF22C30 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24C30 RtlUnhandledExceptionFilter,ZwTerminateProcess, | 0_2_6CF24C30 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF84C34 RtlDosPathNameToRelativeNtPathName_U,ZwOpenFile,ZwClose,RtlFreeHeap,RtlFreeHeap,RtlAllocateHeap,RtlCultureNameToLCID,RtlAllocateHeap,RtlReAllocateHeap,memcpy,memset,ZwQueryDirectoryFile,ZwClose,RtlFreeHeap,RtlFreeHeap, | 0_2_6CF84C34 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDEC20 TpSetPoolWorkerThreadIdleTimeout,ZwSetInformationWorkerFactory, | 0_2_6CEDEC20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1AC00 RtlpCheckDynamicTimeZoneInformation,memcmp,ZwClose, | 0_2_6CF1AC00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22C00 ZwQueryInformationProcess, | 0_2_6CF22C00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22C0A NtQueryInformationProcess, | 0_2_6CF22C0A |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22DF0 ZwQuerySystemInformation, | 0_2_6CF22DF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF80DF0 RtlCheckBootStatusIntegrity,ZwReadFile,RtlAllocateHeap,ZwReadFile,RtlFreeHeap, | 0_2_6CF80DF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF8ADF0 RtlConnectToSm,RtlInitUnicodeString,memset,memcpy,ZwAlpcConnectPort, | 0_2_6CF8ADF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF00DE1 RtlAcquireSRWLockExclusive,RtlAllocateHeap,memcpy,ZwSetInformationProcess,RtlReleaseSRWLockExclusive,RtlFreeHeap,RtlAllocateHeap,RtlFreeHeap,RtlReleaseSRWLockExclusive,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap, | 0_2_6CF00DE1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22DE0 ZwQueryDirectoryFile, | 0_2_6CF22DE0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF96DE0 RtlIsPartialPlaceholderFileHandle,ZwQueryInformationFile, | 0_2_6CF96DE0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF64DD7 DbgPrint,DbgPrompt,ZwTerminateThread,ZwTerminateProcess,DbgPrint, | 0_2_6CF64DD7 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22DD0 ZwDelayExecution, | 0_2_6CF22DD0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0EDD3 RtlAcquireSRWLockShared,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockShared,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockShared,RtlReleaseSRWLockExclusive,RtlFreeHeap,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockExclusive,ZwGetCompleteWnfStateSubscription,RtlFreeHeap, | 0_2_6CF0EDD3 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22DC0 ZwOpenFile, | 0_2_6CF22DC0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4DC4 ZwQueryInformationProcess,RtlRaiseStatus,RtlDebugPrintTimes,RtlUnhandledExceptionFilter2, | 0_2_6CFB4DC4 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1CDB1 RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlDebugPrintTimes,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,ZwQueryInformationProcess,RtlRaiseStatus,RtlFreeHeap,LdrControlFlowGuardEnforced,RtlFreeHeap, | 0_2_6CF1CDB1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22DB0 ZwEnumerateKey, | 0_2_6CF22DB0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF70DB0 RtlSetImageMitigationPolicy,RtlInitUnicodeStringEx,RtlInitUnicodeStringEx,RtlInitUnicodeStringEx,ZwOpenKey,ZwDeleteValueKey,ZwDeleteValueKey,ZwQueryValueKey,memcpy,ZwSetValueKey,RtlSetImageMitigationPolicy,ZwClose, | 0_2_6CF70DB0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE8DA4 RtlInitializeCriticalSectionEx,ZwDelayExecution, | 0_2_6CEE8DA4 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22DA0 ZwQueryPerformanceCounter, | 0_2_6CF22DA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22D90 ZwOpenProcessTokenEx, | 0_2_6CF22D90 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF68D87 RtlAppendUnicodeStringToString,ZwOpenKey, | 0_2_6CF68D87 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22D80 ZwOpenThreadTokenEx, | 0_2_6CF22D80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22D70 ZwReadFileScatter, | 0_2_6CF22D70 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF00D77 ZwProtectVirtualMemory, | 0_2_6CF00D77 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22D60 ZwSetEventBoostPriority, | 0_2_6CF22D60 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22D50 ZwTerminateProcess, | 0_2_6CF22D50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22D40 ZwReplyWaitReceivePortEx, | 0_2_6CF22D40 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1CD47 ZwCancelWaitCompletionPacket,RtlDebugPrintTimes, | 0_2_6CF1CD47 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE0D59 memset,RtlRunOnceExecuteOnce,ZwTraceControl,LdrInitializeThunk,memcmp,RtlNtStatusToDosError,RtlFreeHeap,RtlAllocateHeap,RtlNtStatusToDosError,RtlFreeHeap, | 0_2_6CEE0D59 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22D30 ZwUnmapViewOfSection, | 0_2_6CF22D30 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF88D31 RtlInitUnicodeString,memset,RtlAppendUnicodeStringToString,RtlAppendUnicodeStringToString,ZwOpenKey,ZwQueryValueKey,_allmul,ZwClose, | 0_2_6CF88D31 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF64D39 RtlReportSilentProcessExit,ZwQueryInformationProcess,RtlRaiseStatus,RtlDebugPrintTimes,RtlUnhandledExceptionFilter2,ZwTerminateProcess, | 0_2_6CF64D39 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22D20 ZwAccessCheckAndAuditAlarm, | 0_2_6CF22D20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6AD20 ZwDuplicateObject,ZwDuplicateObject, | 0_2_6CF6AD20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF96D21 ZwQueryInformationProcess,RtlRaiseStatus,RtlDebugPrintTimes,RtlUnhandledExceptionFilter2, | 0_2_6CF96D21 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22D10 ZwMapViewOfSection, | 0_2_6CF22D10 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF38D10 RtlRaiseStatus,RtlCaptureContext,ZwRaiseException,RtlRaiseStatus, | 0_2_6CF38D10 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22D00 ZwSetInformationFile, | 0_2_6CF22D00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB0D00 EtwWriteUMSecurityEvent,ZwTraceEvent,RtlNtStatusToDosError, | 0_2_6CFB0D00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED6D10 LdrQueryImageFileKeyOption,RtlInitUnicodeStringEx,ZwQueryValueKey,LdrQueryImageFileKeyOption,RtlFreeHeap,RtlAllocateHeap,ZwQueryValueKey,RtlFreeHeap,RtlUnicodeStringToInteger,memcpy,LdrQueryImageFileKeyOption, | 0_2_6CED6D10 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22EF0 ZwYieldExecution, | 0_2_6CF22EF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB0EF0 ZwTraceControl,RtlNtStatusToDosError,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlSetLastWin32Error, | 0_2_6CFB0EF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22EE0 ZwQueueApcThread, | 0_2_6CF22EE0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22ED0 ZwQueryDefaultUILanguage, | 0_2_6CF22ED0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22EC0 ZwContinue, | 0_2_6CF22EC0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22EB0 ZwDuplicateToken, | 0_2_6CF22EB0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF7AEB0 RtlpNotOwnerCriticalSection,DbgPrintEx,ZwQueryInformationProcess,RtlRaiseStatus,RtlRaiseStatus,RtlDebugPrintTimes,RtlpNotOwnerCriticalSection, | 0_2_6CF7AEB0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22EA0 ZwAdjustPrivilegesToken, | 0_2_6CF22EA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6CEA0 LdrAddDllDirectory,RtlDetermineDosPathNameType_U,ZwQueryAttributesFile,RtlFreeHeap,RtlAllocateHeap,LdrInitializeThunk,LdrInitializeThunk,memcpy,RtlAcquireSRWLockExclusive,@_EH4_CallFilterFunc@8,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlFreeHeap,LdrAddDllDirectory, | 0_2_6CF6CEA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22E90 ZwOpenEvent, | 0_2_6CF22E90 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF88E90 memcpy,ZwUnmapViewOfSection,ZwMapViewOfSection,memcpy, | 0_2_6CF88E90 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22E80 ZwReadVirtualMemory, | 0_2_6CF22E80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDAE90 TpReleasePool,RtlAcquireSRWLockExclusive,ZwShutdownWorkerFactory,RtlGetCurrentServiceSessionId,TpReleasePool,TpReleasePool,RtlDebugPrintTimes,TpReleasePool,TpReleasePool, | 0_2_6CEDAE90 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22E70 ZwClearEvent, | 0_2_6CF22E70 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF60E7F RtlAllocateHeap,memcpy,RtlGetCurrentServiceSessionId,ZwTraceEvent,RtlFreeHeap, | 0_2_6CF60E7F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFAAE75 ZwFreeVirtualMemory,RtlAcquireSRWLockExclusive,RtlRbRemoveNode,RtlReleaseSRWLockExclusive,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive, | 0_2_6CFAAE75 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22E60 ZwQueryAttributesFile, | 0_2_6CF22E60 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9EE6D memset,ZwCreateSection,ZwClose,ZwMapViewOfSection,RtlDebugPrintTimes,ZwUnmapViewOfSection,ZwUnmapViewOfSection,ZwClose, | 0_2_6CF9EE6D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB8E6C memset,ZwQueryInformationThread,ZwQueryInformationThread,ZwQueryInformationThread,ZwQueryInformationThread,ZwQueryInformationThread,ZwQueryInformationThread,memset,ZwGetContextThread, | 0_2_6CFB8E6C |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6E71 RtlGetCurrentServiceSessionId,ZwSetInformationThread,ZwSetInformationThread, | 0_2_6CEE6E71 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF14E50 RtlDecodePointer,RtlDecodePointer,ZwQueryInformationProcess,RtlRaiseStatus, | 0_2_6CF14E50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF16E50 RtlAdjustPrivilege,ZwOpenProcessToken,ZwAdjustPrivilegesToken,ZwClose,ZwOpenThreadToken,RtlAdjustPrivilege, | 0_2_6CF16E50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22E50 ZwDuplicateObject, | 0_2_6CF22E50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF66E50 RtlDestroyQueryDebugBuffer,ZwClose,ZwUnmapViewOfSection, | 0_2_6CF66E50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4E52 ZwAlertThreadByThreadId, | 0_2_6CFB4E52 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22E40 ZwCloseObjectAuditAlarm, | 0_2_6CF22E40 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF94E4D ZwQueryPerformanceCounter,RtlRandomEx, | 0_2_6CF94E4D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9CE4E memset,memset,memset,ZwQueryInstallUILanguage,ZwIsUILanguageComitted,RtlLCIDToCultureName,ZwQueryValueKey,RtlInitUnicodeString,RtlCompareUnicodeStrings,RtlInitUnicodeString,ZwQueryValueKey,ZwEnumerateValueKey,RtlCompareUnicodeStrings,RtlCompareUnicodeStrings, | 0_2_6CF9CE4E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22E30 ZwWriteVirtualMemory, | 0_2_6CF22E30 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFA0E3D ZwQuerySystemInformation, | 0_2_6CFA0E3D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22E20 ZwFsControlFile, | 0_2_6CF22E20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24E20 KiUserApcDispatcher,RtlDebugPrintTimes,RtlDebugPrintTimes,ZwContinue,RtlRaiseStatus, | 0_2_6CF24E20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF68E16 ZwOpenProcessTokenEx,ZwQueryInformationToken,ZwClose,RtlConvertSidToUnicodeString, | 0_2_6CF68E16 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22E10 ZwQueryTimer, | 0_2_6CF22E10 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5CE16 wcschr,RtlInitUnicodeString,wcstoul,RtlAnsiStringToUnicodeString,RtlCompareUnicodeString,ZwProtectVirtualMemory,DbgPrintEx,RtlFreeUnicodeString, | 0_2_6CF5CE16 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6EE10 AlpcAdjustCompletionListConcurrencyCount,ZwAlpcSetInformation, | 0_2_6CF6EE10 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF18E1A RtlReleaseActivationContext,LdrUnloadDll,ZwClose,RtlFreeHeap, | 0_2_6CF18E1A |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED8E1D RtlFreeHeap,ZwSetEvent,ZwClose, | 0_2_6CED8E1D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22E00 ZwOpenSection, | 0_2_6CF22E00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF14FF1 ZwQuerySecurityAttributesToken,ZwQuerySecurityAttributesToken,ZwQuerySecurityAttributesToken,ZwQuerySecurityAttributesToken, | 0_2_6CF14FF1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22FF0 ZwQueryEvent, | 0_2_6CF22FF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF20FF6 RtlAllocateHeap,RtlInitUnicodeString,ZwOpenKey,RtlAllocateHeap,RtlInitUnicodeString,ZwQueryValueKey,RtlFreeHeap,ZwClose,RtlFreeHeap, | 0_2_6CF20FF6 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22FE0 ZwCreateFile, | 0_2_6CF22FE0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF66FE0 RtlQueryProcessDebugInformation,memset,ZwOpenProcess,ZwOpenProcess,RtlWow64GetProcessMachines,ZwClose,ZwClose,ZwWow64CallFunction64,RtlpQueryProcessDebugInformationRemote,ZwWaitForSingleObject,ZwQueryInformationThread,ZwTerminateThread,ZwClose,ZwClose,RtlQueryProcessBackTraceInformation,RtlQueryProcessLockInformation,RtlQueryProcessHeapInformation,ZwClose, | 0_2_6CF66FE0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4FE7 RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CFB4FE7 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22FD0 ZwReadRequestData, | 0_2_6CF22FD0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9AFD0 RtlpGetUserOrMachineUILanguage4NLS,RtlInitUnicodeString,RtlInitUnicodeString,ZwOpenKey,RtlInitUnicodeString,ZwClose,RtlInitUnicodeString,ZwOpenKey,RtlInitUnicodeString,ZwClose,ZwClose, | 0_2_6CF9AFD0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22FC0 ZwTerminateThread, | 0_2_6CF22FC0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDEFD8 RtlRunOnceExecuteOnce,LdrInitializeThunk,LdrInitializeThunk,ZwAllocateVirtualMemory,LdrInitializeThunk,ZwAllocateVirtualMemory,RtlGetCurrentServiceSessionId,RtlGetCurrentServiceSessionId, | 0_2_6CEDEFD8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF7AFCE ZwQueryInformationProcess,RtlRaiseStatus,RtlCaptureContext,ZwQueryInformationProcess,RtlRaiseException, | 0_2_6CF7AFCE |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22FB0 ZwResumeThread, | 0_2_6CF22FB0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1AFB8 RtlInitUnicodeString,RtlInitUnicodeString,ZwQueryValueKey,ZwClose,ZwClose,ZwClose,RtlInitUnicodeString,ZwOpenKey,ZwEnumerateValueKey,DbgPrint,ZwDeleteValueKey,RtlDebugPrintTimes,ZwDeleteValueKey,DbgPrint,ZwClose, | 0_2_6CF1AFB8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22FA0 ZwQuerySection, | 0_2_6CF22FA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22F90 ZwProtectVirtualMemory, | 0_2_6CF22F90 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF12F98 memcpy,memcpy,RtlDosPathNameToRelativeNtPathName_U,ZwOpenFile,memcpy,RtlFreeHeap,RtlDeleteBoundaryDescriptor,DbgPrintEx,DbgPrintEx,DbgPrintEx,ZwClose,RtlFreeHeap,DbgPrintEx,memcpy,DbgPrintEx,ZwClose, | 0_2_6CF12F98 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22F80 ZwIsProcessInJob, | 0_2_6CF22F80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24F80 KiUserExceptionDispatcher,RtlDebugPrintTimes,ZwContinue,ZwRaiseException,RtlRaiseException, | 0_2_6CF24F80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB0F88 ZwTraceControl,RtlNtStatusToDosError,RtlSetLastWin32Error, | 0_2_6CFB0F88 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB6F80 PssNtFreeRemoteSnapshot,ZwReadVirtualMemory,ZwFreeVirtualMemory,ZwDuplicateObject,ZwDuplicateObject,ZwDuplicateObject,ZwDuplicateObject,ZwDuplicateObject,ZwDuplicateObject,ZwFreeVirtualMemory, | 0_2_6CFB6F80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22F70 ZwCreateThread, | 0_2_6CF22F70 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6AF7A ZwUnmapViewOfSection,ZwClose,ZwClose,ZwClose,ZwClose,ZwClose, | 0_2_6CF6AF7A |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22F60 ZwCreateProcessEx, | 0_2_6CF22F60 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4F68 RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CFB4F68 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF8AF60 RtlSendMsgToSm,ZwAlpcSendWaitReceivePort, | 0_2_6CF8AF60 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22F50 ZwApphelpCacheControl, | 0_2_6CF22F50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4F5C ZwTerminateProcess, | 0_2_6CFB4F5C |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF80F50 RtlCreateBootStatusDataFile,RtlInitUnicodeString,RtlInitUnicodeString,ZwCreateFile,ZwWriteFile,RtlRestoreBootStatusDefaults,ZwClose,RtlFreeHeap, | 0_2_6CF80F50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF96F50 RtlIsCurrentThread,ZwCompareObjects, | 0_2_6CF96F50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF18F40 RtlUnwind,ZwContinue,RtlUnwind,RtlRaiseException,RtlRaiseException,RtlRaiseException,ZwContinue,ZwRaiseException, | 0_2_6CF18F40 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22F40 ZwFlushBuffersFile, | 0_2_6CF22F40 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22F30 ZwCreateSection, | 0_2_6CF22F30 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22F20 ZwQueryVolumeInformationFile, | 0_2_6CF22F20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF96F20 RtlIsCurrentProcess,ZwCompareObjects, | 0_2_6CF96F20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22F10 ZwCreateEvent, | 0_2_6CF22F10 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24F10 KiUserCallbackDispatcher,RtlDebugPrintTimes,RtlDebugPrintTimes,ZwCallbackReturn,RtlRaiseStatus, | 0_2_6CF24F10 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22F00 ZwAddAtom, | 0_2_6CF22F00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF20F04 RtlInitUnicodeString,ZwOpenKey,RtlInitUnicodeString,ZwQueryValueKey,ZwClose, | 0_2_6CF20F04 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF80F00 RtlCheckSystemBootStatusIntegrity,ZwPowerInformation, | 0_2_6CF80F00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF94F00 __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,ZwQueryPerformanceCounter,ZwQueryPerformanceCounter, | 0_2_6CF94F00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF248F0 ZwWow64ReadVirtualMemory64, | 0_2_6CF248F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDE8E0 RtlQueryWnfStateData,_alloca_probe_16,ZwQueryWnfStateData,RtlDebugPrintTimes, | 0_2_6CEDE8E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF248E0 ZwWow64AllocateVirtualMemory64, | 0_2_6CF248E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE28F0 RtlDetermineDosPathNameType_U,RtlDetermineDosPathNameType_U,ZwTerminateProcess,ZwWaitForAlertByThreadId,RtlReleaseSRWLockExclusive,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlFreeHeap,RtlGetCurrentServiceSessionId,RtlCreateUnicodeString,RtlCreateUnicodeString,RtlFreeUnicodeString,RtlFreeUnicodeString, | 0_2_6CEE28F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF168EF ZwUnmapViewOfSection, | 0_2_6CF168EF |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF248D0 ZwWow64QueryInformationProcess64, | 0_2_6CF248D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF248C0 ZwWow64GetNativeSystemInformation, | 0_2_6CF248C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF248B0 ZwWow64GetCurrentProcessorNumberEx, | 0_2_6CF248B0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1C8B7 ZwTraceControl, | 0_2_6CF1C8B7 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF248A0 ZwWow64DebuggerCall, | 0_2_6CF248A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24890 ZwWow64CsrVerifyRegion, | 0_2_6CF24890 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE0887 RtlAcquireSRWLockExclusive,RtlAcquireSRWLockExclusive,ZwSubscribeWnfStateChange,RtlGetCurrentServiceSessionId,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockExclusive, | 0_2_6CEE0887 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6C89D RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CF6C89D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24880 ZwWow64CsrGetProcessId, | 0_2_6CF24880 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4887 ZwSetInformationWorkerFactory, | 0_2_6CFB4887 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24870 ZwWow64CsrCaptureMessageString, | 0_2_6CF24870 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24860 ZwWow64CsrCaptureMessageBuffer, | 0_2_6CF24860 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24850 ZwWow64CsrAllocateMessagePointer, | 0_2_6CF24850 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFA685D ZwGetCurrentProcessorNumber,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockExclusive, | 0_2_6CFA685D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF7A85E RtlInitializeSid,ZwQueryInformationToken,RtlSidDominates,RtlSidDominates,ZwPrivilegeCheck, | 0_2_6CF7A85E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24840 ZwWow64CsrFreeCaptureBuffer, | 0_2_6CF24840 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFA0840 ZwCreateSection,ZwMapViewOfSection,memset,memcpy,ZwUnmapViewOfSection,ZwClose, | 0_2_6CFA0840 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24830 ZwWow64CsrAllocateCaptureBuffer, | 0_2_6CF24830 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEE820 RtlLeaveCriticalSection,RtlpNotOwnerCriticalSection,RtlLeaveCriticalSection,ZwSetEvent,RtlRaiseStatus,LdrRscIsTypeExist, | 0_2_6CEEE820 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF16820 RtlClearThreadWorkOnBehalfTicket,memcmp,RtlClearThreadWorkOnBehalfTicket,ZwSetInformationThread, | 0_2_6CF16820 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24820 ZwWow64CsrClientCallServer, | 0_2_6CF24820 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24810 ZwWow64CsrIdentifyAlertableThread, | 0_2_6CF24810 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6C810 RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CF6C810 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24800 ZwWow64CsrClientConnectToServer, | 0_2_6CF24800 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF20800 ZwAllocateVirtualMemory,memset,RtlEnterCriticalSection,RtlLeaveCriticalSection, | 0_2_6CF20800 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6A800 RtlEncodeRemotePointer,ZwQueryInformationProcess, | 0_2_6CF6A800 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF129F9 DbgPrintEx,wcsrchr,memcpy,DbgPrintEx,ZwClose,DbgPrintEx,DbgPrintEx,RtlDosPathNameToRelativeNtPathName_U,DbgPrintEx,ZwOpenFile,ZwClose,RtlFreeHeap,DbgPrintEx,DbgPrintEx,DbgPrintEx,RtlDeleteBoundaryDescriptor,ZwClose,RtlFreeHeap, | 0_2_6CF129F9 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFA29F3 ZwAllocateVirtualMemoryEx, | 0_2_6CFA29F3 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE49FF ZwSetInformationWorkerFactory, | 0_2_6CEE49FF |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6A9E0 RtlReportExceptionEx,RtlReportException,ZwDuplicateObject,ZwDuplicateObject,memset,ZwTerminateProcess, | 0_2_6CF6A9E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6E9E0 RtlComputeImportTableHash,ZwCreateSection,ZwMapViewOfSection,ZwClose,RtlImageNtHeader,RtlAddressInSectionTable,RtlAllocateHeap,ZwUnmapViewOfSection,RtlFlushSecureMemoryCache,ZwUnmapViewOfSection, | 0_2_6CF6E9E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF769C0 RtlGetSessionProperties,RtlGetCurrentServiceSessionId,ZwQueryInformationJobObject, | 0_2_6CF769C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF229B3 ZwWaitForAlertByThreadId, | 0_2_6CF229B3 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF889B4 ZwOpenKey,ZwQueryValueKey,ZwClose, | 0_2_6CF889B4 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF649B8 ZwQueryInformationProcess,ZwMapViewOfSection,ZwClose, | 0_2_6CF649B8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1A9A0 RtlReleaseResource,ZwReleaseSemaphore,RtlRaiseStatus,ZwQueryValueKey,ZwReleaseSemaphore,RtlRaiseStatus,ZwClose, | 0_2_6CF1A9A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFAA987 ZwQueryVirtualMemory,ZwProtectVirtualMemory, | 0_2_6CFAA987 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF96970 RtlInitializeContext,ZwWriteVirtualMemory, | 0_2_6CF96970 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6C97C RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CF6C97C |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF06962 LdrInitializeThunk,ZwQueryInformationToken,RtlFindAceByType,RtlFindAceByType,RtlFindAceByType,RtlAllocateHeap,memcpy,memcpy,memcpy,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlCreateSecurityDescriptor,RtlFreeHeap,RtlCreateAcl,RtlAddMandatoryAce,RtlFreeHeap,memcpy,RtlFreeHeap,RtlSidDominates,RtlFreeHeap,RtlFreeHeap,RtlFindAceByType,ZwDuplicateToken,ZwAccessCheck,ZwClose,ZwPrivilegeCheck,ZwPrivilegeCheck,RtlFreeHeap,memset,memset,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap, | 0_2_6CF06962 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF2096E memset,memset,ZwQuerySystemInformation,ZwQueryInformationThread,ZwQueryInformationThread,ZwQuerySystemInformation,RtlAllocateHeap,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,memcpy,memcpy,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,memset,ZwWriteFile,RtlFreeHeap,ZwClose,ZwReadFile,ZwWriteFile,RtlQueryPerformanceCounter,RtlQueryPerformanceCounter,memcpy,ZwQueryVolumeInformationFile,ZwSetInformationFile, | 0_2_6CF2096E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0096D ZwWow64IsProcessorFeaturePresent, | 0_2_6CF0096D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB6940 PssNtCaptureSnapshot,ZwAllocateVirtualMemory,memset,PssNtFreeSnapshot,_allmul,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,_allmul,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,ZwCreateProcessEx,_allmul,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,PssNtFreeSnapshot,_allmul,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,_allmul,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,_allmul,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z, | 0_2_6CFB6940 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24930 DbgPrintEx,ZwTerminateProcess, | 0_2_6CF24930 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEFE920 RtlWow64EnableFsRedirectionEx,RtlEnterCriticalSection,RtlLeaveCriticalSection,ZwSetEvent, | 0_2_6CEFE920 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24920 ZwWow64IsProcessorFeaturePresent, | 0_2_6CF24920 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB8927 ZwDuplicateObject,ZwQueryObject,ZwClose,memset,_wcsicmp,ZwQueryObject,ZwQueryObject,_wcsicmp,ZwClose,RtlDebugPrintTimes,RtlDebugPrintTimes, | 0_2_6CFB8927 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24910 ZwWow64CallFunction64, | 0_2_6CF24910 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6C912 RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CF6C912 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24900 ZwWow64WriteVirtualMemory64, | 0_2_6CF24900 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF64908 RtlAllocateHeap,ZwQueryVirtualMemory,RtlFreeHeap, | 0_2_6CF64908 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22AF0 ZwWriteFile, | 0_2_6CF22AF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF8EAF0 RtlFlushSecureMemoryCache,ZwQueryVirtualMemory, | 0_2_6CF8EAF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22AE0 ZwDeviceIoControlFile, | 0_2_6CF22AE0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF7AAE0 RtlConvertExclusiveToShared,ZwReleaseSemaphore,RtlRaiseStatus, | 0_2_6CF7AAE0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22AD0 ZwReadFile, | 0_2_6CF22AD0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED8ACF ZwSetInformationThread, | 0_2_6CED8ACF |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22AC0 ZwCallbackReturn, | 0_2_6CF22AC0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9AACD ZwFreeVirtualMemory, | 0_2_6CF9AACD |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF36ACC memset,ZwQueryWnfStateData,RtlFreeHeap,RtlAllocateHeap,ZwQueryWnfStateData,ZwQueryWnfStateData,RtlFreeHeap, | 0_2_6CF36ACC |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22AB0 ZwWaitForSingleObject, | 0_2_6CF22AB0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22AA0 ZwMapUserPhysicalPagesScatter, | 0_2_6CF22AA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFA2AAC ZwQuerySystemInformation, | 0_2_6CFA2AAC |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF72AA9 ZwEnumerateValueKey,RtlInitUnicodeStringEx,RtlInitUnicodeStringEx,RtlCompareUnicodeString,RtlCompareUnicodeString,ZwEnumerateKey,ZwOpenKey,ZwClose, | 0_2_6CF72AA9 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9AA98 ZwAllocateVirtualMemory, | 0_2_6CF9AA98 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22A90 ZwAcceptConnectPort, | 0_2_6CF22A90 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22A80 ZwWorkerFactoryWorkerReady, | 0_2_6CF22A80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22A70 ZwAccessCheck, | 0_2_6CF22A70 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5CA72 ZwQueryValueKey,RtlAllocateHeap,ZwQueryValueKey,RtlFreeHeap, | 0_2_6CF5CA72 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB2A70 EtwSendNotification,ZwTraceControl,RtlNtStatusToDosError,ZwClose, | 0_2_6CFB2A70 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF94A63 ZwQuerySystemInformation,RtlAllocateHeap,RtlFreeHeap,RtlAllocateHeap, | 0_2_6CF94A63 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB0A50 EtwEventWriteString,ZwTraceEvent,RtlNtStatusToDosError, | 0_2_6CFB0A50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1AA45 ZwOpenKey,ZwQueryValueKey,ZwClose, | 0_2_6CF1AA45 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6A50 RtlAcquireSRWLockExclusive,RtlDebugPrintTimes,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlGetCurrentServiceSessionId,ZwSetInformationThread,ZwSetInformationThread,RtlGetCurrentServiceSessionId,ZwSetInformationThread,ZwSetInformationThread, | 0_2_6CEE6A50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF96A30 RtlRemoteCall,LdrControlFlowGuardEnforced,ZwSuspendThread,ZwGetContextThread,ZwResumeThread,ZwWriteVirtualMemory,ZwResumeThread,memcpy,memcpy,ZwWriteVirtualMemory,ZwSetContextThread,ZwResumeThread, | 0_2_6CF96A30 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB2A30 EtwReplyNotification,ZwTraceControl,RtlNtStatusToDosError, | 0_2_6CFB2A30 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDEA0C ZwCreateEvent,TpAllocWait,ZwSetWnfProcessNotificationEvent,TpSetWaitEx,TpReleaseWait,ZwClose, | 0_2_6CEDEA0C |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6CA11 RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CF6CA11 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF72A03 ZwDeleteKey,ZwClose, | 0_2_6CF72A03 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF60A0E RtlRunOnceExecuteOnce,ZwQuerySystemInformation,RtlCaptureContext,memset,RtlReportException, | 0_2_6CF60A0E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22BF0 ZwAllocateVirtualMemory, | 0_2_6CF22BF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF96BFC ZwQueryInformationProcess,RtlRaiseStatus,RtlDebugPrintTimes, | 0_2_6CF96BFC |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6CBF0 RtlAcquireSRWLockShared,RtlReleaseSRWLockShared,RtlAcquireSRWLockShared,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockShared,ZwGetCompleteWnfStateSubscription,RtlFreeHeap, | 0_2_6CF6CBF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0EBFC RtlAcquireSRWLockExclusive,RtlAcquireSRWLockExclusive,RtlGetCurrentServiceSessionId,ZwSubscribeWnfStateChange,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlDebugPrintTimes, | 0_2_6CF0EBFC |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22BE0 ZwQueryValueKey, | 0_2_6CF22BE0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22BD0 ZwQueryKey, | 0_2_6CF22BD0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE0BCD RtlAcquireSRWLockExclusive,memset,ZwTraceControl,RtlReleaseSRWLockExclusive,RtlSetLastWin32Error,RtlFreeHeap,RtlAllocateHeap,RtlNtStatusToDosError,RtlFreeHeap, | 0_2_6CEE0BCD |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6EBD0 CsrCaptureMessageMultiUnicodeStringsInPlace,ZwWow64CsrAllocateCaptureBuffer, | 0_2_6CF6EBD0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22BC0 ZwQueryDefaultLocale, | 0_2_6CF22BC0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22BB0 ZwFindAtom, | 0_2_6CF22BB0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6CBB0 ZwSetEvent, | 0_2_6CF6CBB0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDEBA6 ZwOpenFile,memcmp,ZwQueryInformationThread,TpWaitForWork,TpReleaseWork, | 0_2_6CEDEBA6 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22BA0 ZwEnumerateValueKey, | 0_2_6CF22BA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22B90 ZwOpenKey, | 0_2_6CF22B90 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB8B98 ZwGetNextThread,ZwAllocateVirtualMemory,ZwGetNextThread,RtlGetExtendedContextLength,ZwCreateSection,ZwMapViewOfSection,ZwClose,ZwUnmapViewOfSection,ZwUnmapViewOfSection, | 0_2_6CFB8B98 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22B80 ZwQueryInformationFile, | 0_2_6CF22B80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFAEB89 LdrInitializeThunk,ZwFreeVirtualMemory, | 0_2_6CFAEB89 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22B70 ZwQueryObject, | 0_2_6CF22B70 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22B60 ZwClose, | 0_2_6CF22B60 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9CB64 memset,RtlInitUnicodeString,RtlInitUnicodeString,ZwEnumerateValueKey,RtlInitUnicodeString,RtlCompareUnicodeStrings, | 0_2_6CF9CB64 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22B50 ZwSetEvent, | 0_2_6CF22B50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5CB5D RtlGetPersistedStateLocation,ZwOpenKeyEx, | 0_2_6CF5CB5D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF8EB50 RtlRegisterSecureMemoryCacheCallback,ZwQuerySystemInformation,RtlAllocateHeap,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive, | 0_2_6CF8EB50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB2B57 RtlAllocateHeap,RtlAllocateHeap,ZwTraceControl,RtlNtStatusToDosError,ZwTraceControl,RtlFreeHeap,RtlFreeHeap, | 0_2_6CFB2B57 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22B40 ZwSetInformationThread, | 0_2_6CF22B40 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF76B40 RtlIsUntrustedObject,ZwQuerySecurityObject,RtlAllocateHeap,ZwQuerySecurityObject,RtlFindAceByType,RtlFreeHeap, | 0_2_6CF76B40 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF7AB40 RtlConvertSharedToExclusive,ZwReleaseSemaphore,RtlRaiseStatus,ZwReleaseSemaphore,RtlRaiseStatus,RtlAcquireResourceExclusive, | 0_2_6CF7AB40 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED8B50 RtlDeleteTimerQueueEx,RtlAcquireSRWLockExclusive,TpTimerOutstandingCallbackCount,TpReleaseTimer,RtlDeleteTimerQueueEx,RtlDeleteTimerQueueEx,RtlDeleteTimerQueueEx,ZwWaitForAlertByThreadId, | 0_2_6CED8B50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22B30 ZwReplyPort, | 0_2_6CF22B30 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0EB20 TpSetWaitEx,RtlAllocateHeap,ZwGetCompleteWnfStateSubscription,RtlFreeHeap,TpSetWaitEx, | 0_2_6CF0EB20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22B20 ZwReplyWaitReceivePort, | 0_2_6CF22B20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDAB30 RtlCreateMemoryZone,ZwAllocateVirtualMemory, | 0_2_6CEDAB30 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22B10 ZwReleaseSemaphore, | 0_2_6CF22B10 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22B00 ZwRemoveIoCompletion, | 0_2_6CF22B00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFACB09 ZwQueryVirtualMemory, | 0_2_6CFACB09 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF244F0 ZwSetQuotaInformationFile, | 0_2_6CF244F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF8E4FD ZwOpenProcessTokenEx,ZwAdjustPrivilegesToken,ZwOpenFile,RtlCreateSecurityDescriptor,RtlSetOwnerSecurityDescriptor,ZwSetSecurityObject,ZwClose,ZwClose, | 0_2_6CF8E4FD |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE04E5 SbSelectProcedure,RtlDebugPrintTimes,RtlGetSuiteMask,RtlGetSuiteMask,RtlGetNtProductType,RtlInitUnicodeString,ZwQueryLicenseValue, | 0_2_6CEE04E5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF244E0 ZwSetLowWaitHighEventPair, | 0_2_6CF244E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF244D0 ZwSetLowEventPair, | 0_2_6CF244D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF244C0 ZwSetLdtEntries, | 0_2_6CF244C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF244B0 ZwSetIoCompletionEx, | 0_2_6CF244B0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE64AB memcmp,ZwSetInformationThread,RtlDeactivateActivationContextUnsafeFast,RtlSetThreadSubProcessTag,memset,RtlRaiseException,ZwSetInformationThread,DbgPrintEx,memset,RtlRaiseException,DbgPrintEx,memset,RtlRaiseException,DbgPrintEx,memset,RtlRaiseException,DbgPrintEx,memset,RtlRaiseException, | 0_2_6CEE64AB |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF244A0 ZwSetIoCompletion, | 0_2_6CF244A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24490 ZwSetIntervalProfile, | 0_2_6CF24490 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9A49A RtlAllocateHeap,ZwCreateEvent,TpAllocWork, | 0_2_6CF9A49A |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24480 ZwSetInformationWorkerFactory, | 0_2_6CF24480 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4480 TpSetPoolThreadCpuSets,RtlAcquireSRWLockExclusive,ZwSetInformationWorkerFactory,RtlReleaseSRWLockExclusive,RtlNumberOfSetBits, | 0_2_6CFB4480 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0A470 LdrUnloadAlternateResourceModuleEx,RtlAcquireSRWLockExclusive,ZwUnmapViewOfSection,ZwClose,RtlFreeHeap,LdrUnloadAlternateResourceModuleEx,RtlFreeHeap,RtlReAllocateHeap, | 0_2_6CF0A470 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24470 ZwSetInformationVirtualMemory, | 0_2_6CF24470 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24460 ZwSetInformationTransactionManager, | 0_2_6CF24460 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6C460 RtlTestAndPublishWnfStateData,ZwUpdateWnfStateData,RtlGetCurrentServiceSessionId, | 0_2_6CF6C460 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24450 ZwSetInformationTransaction, | 0_2_6CF24450 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFBA457 ZwDeviceIoControlFile, | 0_2_6CFBA457 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9A456 RtlUnsubscribeWnfNotificationWaitForCompletion,ZwClose,TpReleaseWork,RtlFreeHeap, | 0_2_6CF9A456 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1E443 ZwDelayExecution,ZwFreeVirtualMemory,ZwClose,ZwClose,RtlDeleteCriticalSection,RtlFreeUnicodeString,RtlFreeUnicodeString,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlFreeUnicodeString,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap, | 0_2_6CF1E443 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24440 ZwSetInformationToken, | 0_2_6CF24440 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24430 ZwSetInformationSymbolicLink, | 0_2_6CF24430 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDC427 memset,ZwIsUILanguageComitted,RtlpGetNameFromLangInfoNode,ZwQueryInstallUILanguage,RtlLCIDToCultureName,RtlFreeHeap, | 0_2_6CEDC427 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDE420 ZwTraceControl,EtwDeliverDataBlock,TpSetWaitEx,RtlAllocateHeap,RtlFreeHeap,RtlFreeHeap, | 0_2_6CEDE420 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24420 ZwSetInformationResourceManager, | 0_2_6CF24420 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF66420 RtlDefaultNpAcl,RtlAllocateHeap,ZwQueryInformationToken,ZwQueryInformationToken,RtlAllocateHeap,ZwQueryInformationToken,RtlGetAppContainerSidType,RtlGetAppContainerParent,RtlAllocateHeap,RtlCreateAcl,RtlInitializeSid,RtlInitializeSid,RtlInitializeSid,RtlInitializeSid,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap, | 0_2_6CF66420 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24410 ZwSetInformationKey, | 0_2_6CF24410 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFBA414 ZwClose, | 0_2_6CFBA414 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24400 ZwSetInformationJobObject, | 0_2_6CF24400 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF18402 RtlImageNtHeaderEx,ZwOpenKey,ZwOpenKey,ZwOpenKey,ZwQueryValueKey,ZwClose,RtlFormatCurrentUserKeyPath,RtlAllocateHeap,RtlAppendUnicodeStringToString,RtlAppendUnicodeToString,ZwOpenKey,RtlFreeHeap,RtlFreeUnicodeString,ZwQueryValueKey,ZwClose,ZwQueryKey,ZwClose,LdrLoadDll,ZwQueryValueKey,ZwQueryValueKey,ZwClose,LdrGetProcedureAddressForCaller,LdrUnloadDll, | 0_2_6CF18402 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE2410 RtlRandomEx,ZwQueryInformationProcess, | 0_2_6CEE2410 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF2410 RtlAcquireSRWLockExclusive,ZwWaitForAlertByThreadId,RtlAcquireSRWLockExclusive,ZwTerminateProcess, | 0_2_6CEF2410 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF245F0 ZwSignalAndWaitForSingleObject, | 0_2_6CF245F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB85F0 ZwQueryInformationProcess, | 0_2_6CFB85F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE25E0 ZwClose,RtlFreeHeap, | 0_2_6CEE25E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF245E0 ZwShutdownWorkerFactory, | 0_2_6CF245E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF725E4 ZwClose,RtlStringFromGUIDEx,ZwCreateKey,RtlFreeUnicodeString, | 0_2_6CF725E4 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1A5D0 RtlCreateTagHeap,ZwQuerySystemInformation, | 0_2_6CF1A5D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF245D0 ZwShutdownSystem, | 0_2_6CF245D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF245C0 ZwSetWnfProcessNotificationEvent, | 0_2_6CF245C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9A5C0 ZwWaitForSingleObject, | 0_2_6CF9A5C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE65D0 ZwReleaseWorkerFactoryWorker,memmove,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,_allshl,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlDebugPrintTimes,RtlFreeHeap,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive, | 0_2_6CEE65D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF205B0 EtwpCreateEtwThread,ZwResumeThread,EtwpCreateEtwThread,ZwTerminateThread,ZwClose, | 0_2_6CF205B0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF245B0 ZwSetVolumeInformationFile, | 0_2_6CF245B0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF245A0 ZwSetUuidSeed, | 0_2_6CF245A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6E5A2 ZwOpenKey,DbgPrintEx,ZwQueryValueKey,DbgPrintEx,DbgPrintEx,memcpy,ZwClose, | 0_2_6CF6E5A2 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED65B5 RtlInitUnicodeString,RtlDebugPrintTimes,RtlDebugPrintTimes,RtlEnterCriticalSection,RtlLeaveCriticalSection,RtlReleasePath,ZwTerminateProcess, | 0_2_6CED65B5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9A5A0 ZwSetEvent, | 0_2_6CF9A5A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24590 ZwSetTimerResolution, | 0_2_6CF24590 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB8590 ZwQueryMutant,ZwQueryMutant, | 0_2_6CFB8590 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24580 ZwSetTimerEx, | 0_2_6CF24580 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1A570 RtlWakeAllConditionVariable,ZwAlertThreadByThreadId,RtlWakeAllConditionVariable, | 0_2_6CF1A570 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1C570 RtlSetUserCallbackExceptionFilter,RtlSetUserCallbackExceptionFilter,ZwQueryInformationProcess,RtlRaiseStatus, | 0_2_6CF1C570 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24570 ZwSetTimer2, | 0_2_6CF24570 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24560 ZwSetThreadExecutionState, | 0_2_6CF24560 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB8560 ZwQueryEvent, | 0_2_6CFB8560 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24550 ZwSetSystemTime, | 0_2_6CF24550 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24540 ZwSetSystemPowerState, | 0_2_6CF24540 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6C540 RtlWaitForWnfMetaNotification,ZwQueryWnfStateNameInformation,ZwQueryWnfStateNameInformation,ZwCreateEvent,RtlRegisterForWnfMetaNotification,_allmul,ZwWaitForSingleObject,RtlUnsubscribeWnfNotificationWaitForCompletion,ZwClose, | 0_2_6CF6C540 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24530 ZwSetSystemInformation, | 0_2_6CF24530 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24520 ZwSetSystemEnvironmentValueEx, | 0_2_6CF24520 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24510 ZwSetSystemEnvironmentValue, | 0_2_6CF24510 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24500 ZwSetSecurityObject, | 0_2_6CF24500 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4500 TpTrimPools,RtlAcquireSRWLockExclusive,RtlAcquireSRWLockShared,RtlAcquireSRWLockExclusive,ZwSetInformationWorkerFactory,RtlSleepConditionVariableSRW,RtlAllocateHeap,ZwClose,RtlFreeHeap,RtlAllocateHeap,ZwClose,RtlFreeHeap,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockShared,ZwWaitForMultipleObjects,ZwClose,RtlFreeHeap,RtlFreeHeap,RtlFreeHeap,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockShared,RtlReleaseSRWLockExclusive, | 0_2_6CFB4500 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF246F0 ZwUnloadDriver, | 0_2_6CF246F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5E6F2 ZwQuerySystemInformation,ZwQuerySystemInformationEx,RtlAllocateHeap,ZwQuerySystemInformationEx,RtlFindCharInUnicodeString,RtlEnterCriticalSection,memcpy, | 0_2_6CF5E6F2 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF246E0 ZwUmsThreadYield, | 0_2_6CF246E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6A6E0 RtlWow64IsWowGuestMachineSupported,ZwQuerySystemInformationEx,_alloca_probe_16,ZwQuerySystemInformationEx, | 0_2_6CF6A6E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF246D0 ZwTranslateFilePath, | 0_2_6CF246D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF246C0 ZwTraceControl, | 0_2_6CF246C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1A6C7 RtlAllocateHeap,memcpy,ZwFreeVirtualMemory, | 0_2_6CF1A6C7 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF246B0 ZwThawTransactions, | 0_2_6CF246B0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF246A0 ZwThawRegistry, | 0_2_6CF246A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24690 ZwTestAlert, | 0_2_6CF24690 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6A690 RtlWow64GetSharedInfoProcess,ZwQueryInformationProcess,ZwReadVirtualMemory, | 0_2_6CF6A690 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF72699 memset,memset,ZwCreateUserProcess, | 0_2_6CF72699 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24680 ZwTerminateJobObject, | 0_2_6CF24680 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB8680 ZwQueryInformationThread,ZwQueryInformationThread, | 0_2_6CFB8680 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24670 ZwTerminateEnclave, | 0_2_6CF24670 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24660 ZwSystemDebugControl, | 0_2_6CF24660 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24650 ZwSuspendThread, | 0_2_6CF24650 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF86650 RtlpVerifyAndCommitUILanguageSettings,memset,ZwQueryInstallUILanguage,RtlLCIDToCultureName,RtlpCreateProcessRegistryInfo,ZwFlushInstallUILanguage,LdrInitializeThunk,ZwGetMUIRegistryInfo,ZwShutdownSystem, | 0_2_6CF86650 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9A650 ZwQueryInformationProcess,RtlRaiseStatus, | 0_2_6CF9A650 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB8650 ZwQuerySemaphore, | 0_2_6CFB8650 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24640 ZwSuspendProcess, | 0_2_6CF24640 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF96640 RtlSleepConditionVariableCS,RtlLeaveCriticalSection,ZwWaitForAlertByThreadId,ZwWaitForAlertByThreadId,RtlEnterCriticalSection, | 0_2_6CF96640 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24630 ZwSubscribeWnfStateChange, | 0_2_6CF24630 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF20634 ZwCreateThreadEx,ZwClose, | 0_2_6CF20634 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDC62A RtlInitUnicodeString,ZwOpenKey,ZwEnumerateKey,ZwClose, | 0_2_6CEDC62A |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF18620 ZwQueryInformationThread,ZwQueryInformationThread,RtlAcquireSRWLockShared,RtlApplicationVerifierStop, | 0_2_6CF18620 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24620 ZwStopProfile, | 0_2_6CF24620 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9C620 RtlpRefreshCachedUILanguage,ZwQueryInstallUILanguage,RtlInitUnicodeString,RtlCultureNameToLCID,ZwFlushInstallUILanguage,RtlpCreateProcessRegistryInfo,ZwFlushInstallUILanguage,ZwFlushInstallUILanguage,LdrInitializeThunk,ZwGetMUIRegistryInfo, | 0_2_6CF9C620 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB8620 ZwQuerySection, | 0_2_6CFB8620 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24610 ZwStartProfile, | 0_2_6CF24610 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24600 ZwSinglePhaseReject, | 0_2_6CF24600 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF247F0 ZwLoadKey3, | 0_2_6CF247F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF247E0 ZwWaitLowEventPair, | 0_2_6CF247E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF247D0 ZwWaitHighEventPair, | 0_2_6CF247D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF247C0 ZwWaitForWorkViaWorkerFactory, | 0_2_6CF247C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF607C3 ZwQueryInformationProcess,RtlRaiseStatus,RtlDebugPrintTimes,RtlUnhandledExceptionFilter2,EtwEventRegister,EtwEventWrite,EtwNotificationUnregister,ZwRaiseException, | 0_2_6CF607C3 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF667C0 RtlNewSecurityGrantedAccess,LdrInitializeThunk,ZwQueryInformationToken,RtlMapGenericMask,ZwPrivilegeCheck, | 0_2_6CF667C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF247B0 ZwWaitForKeyedEvent, | 0_2_6CF247B0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6A7B0 RtlDecodeRemotePointer,ZwQueryInformationProcess, | 0_2_6CF6A7B0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF247A0 ZwWaitForDebugEvent, | 0_2_6CF247A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED67BF memset,ZwTerminateProcess, | 0_2_6CED67BF |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF947A0 RtlHeapTrkInitialize,ZwMapViewOfSection,ZwQueryPerformanceCounter,RtlCreateHeap,RtlSetHeapInformation,RtlAllocateHeap,RtlAllocateHeap,ZwUnmapViewOfSection,RtlDestroyHeap,ZwUnmapViewOfSection,ZwClose, | 0_2_6CF947A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24790 ZwWaitForAlertByThreadId, | 0_2_6CF24790 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24780 ZwVdmControl, | 0_2_6CF24780 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF88785 ZwAllocateVirtualMemory,ZwDuplicateObject,ZwWriteVirtualMemory,ZwTerminateThread,ZwClose,ZwFreeVirtualMemory,ZwResumeThread,ZwWaitForSingleObject,ZwClose,ZwReadVirtualMemory, | 0_2_6CF88785 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24770 ZwUpdateWnfStateData, | 0_2_6CF24770 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDA760 EtwSetMark,ZwTraceEvent,RtlNtStatusToDosError, | 0_2_6CEDA760 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24760 ZwUnsubscribeWnfStateChange, | 0_2_6CF24760 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24750 ZwUnmapViewOfSectionEx, | 0_2_6CF24750 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDA740 ZwClose,RtlFreeHeap, | 0_2_6CEDA740 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24740 ZwUnlockVirtualMemory, | 0_2_6CF24740 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24730 ZwUnlockFile, | 0_2_6CF24730 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5C730 LdrAppxHandleIntegrityFailure,RtlQueryPackageIdentityEx,memset,ZwQueryValueKey,RtlFreeHeap,ZwClose,memset,memset,RtlCaptureContext,RtlReportException,ZwTerminateProcess, | 0_2_6CF5C730 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF20735 ZwAllocateVirtualMemory,ZwFreeVirtualMemory, | 0_2_6CF20735 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24720 ZwUnloadKeyEx, | 0_2_6CF24720 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF10710 RtlAllocateHandle,RtlReAllocateHeap,RtlAllocateHandle,ZwAllocateVirtualMemory,ZwAllocateVirtualMemory,RtlAllocateHeap, | 0_2_6CF10710 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24710 ZwUnloadKey2, | 0_2_6CF24710 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24700 ZwUnloadKey, | 0_2_6CF24700 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF66700 RtlNewInstanceSecurityObject,LdrInitializeThunk,ZwQueryInformationToken, | 0_2_6CF66700 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF220F0 RtlPublishWnfStateData,ZwUpdateWnfStateData,RtlGetCurrentServiceSessionId,RtlPublishWnfStateData, | 0_2_6CF220F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF240F0 ZwRaiseException, | 0_2_6CF240F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF240E0 ZwQueueApcThreadEx, | 0_2_6CF240E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5E0E0 LdrCreateEnclave,ZwCreateEnclave,LdrCreateEnclave, | 0_2_6CF5E0E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF240D0 ZwQueryWnfStateNameInformation, | 0_2_6CF240D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF620DE ZwRaiseHardError, | 0_2_6CF620DE |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFBA0D1 ZwDeviceIoControlFile, | 0_2_6CFBA0D1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF740DA ZwQueryVirtualMemory, | 0_2_6CF740DA |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1E0DF ZwDelayExecution, | 0_2_6CF1E0DF |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDC0C2 ZwAlertThreadByThreadId, | 0_2_6CEDC0C2 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF240C0 ZwQueryWnfStateData, | 0_2_6CF240C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE20DA ZwOpenThreadToken,ZwSetInformationThread,ZwClose, | 0_2_6CEE20DA |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6C0C0 RtlInitUnicodeString,ZwQueryValueKey, | 0_2_6CF6C0C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF640C9 ZwTerminateProcess,RtlLeaveCriticalSection, | 0_2_6CF640C9 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFA60B8 RtlAcquireSRWLockExclusive,ZwGetNlsSectionPtr,RtlAllocateHeap,RtlFreeHeap,RtlReleaseSRWLockExclusive,RtlReleaseSRWLockExclusive, | 0_2_6CFA60B8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF240B0 ZwQueryTimerResolution, | 0_2_6CF240B0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF740A7 ZwSetInformationFile, | 0_2_6CF740A7 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF240A0 ZwQuerySystemInformationEx, | 0_2_6CF240A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5E0A0 DbgUiWaitStateChange,ZwWaitForDebugEvent, | 0_2_6CF5E0A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24090 ZwQuerySystemEnvironmentValueEx, | 0_2_6CF24090 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1C080 RtlImpersonateSelfEx,ZwOpenProcessTokenEx,ZwDuplicateToken,ZwSetInformationThread,ZwClose,ZwClose,RtlImpersonateSelfEx, | 0_2_6CF1C080 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24080 ZwQuerySystemEnvironmentValue, | 0_2_6CF24080 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF68080 ZwReadVirtualMemory, | 0_2_6CF68080 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1608F ZwOpenKey,ZwCreateKey, | 0_2_6CF1608F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1A073 RtlInitUnicodeString,RtlInitAnsiString,RtlAnsiStringToUnicodeString,RtlInitUnicodeString,RtlInitUnicodeString,RtlInitUnicodeString,ZwRaiseHardError,RtlRaiseStatus,EtwTraceMessageVa,RtlNtStatusToDosError, | 0_2_6CF1A073 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24070 ZwQuerySymbolicLinkObject, | 0_2_6CF24070 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5E070 DbgUiStopDebugging,ZwRemoveProcessDebug, | 0_2_6CF5E070 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF06060 RtlCheckTokenMembershipEx,RtlCreateSecurityDescriptor,RtlSetOwnerSecurityDescriptor,RtlSetGroupSecurityDescriptor,RtlCreateAcl,RtlInitializeSidEx,RtlSetDaclSecurityDescriptor,ZwAccessCheck,RtlInitializeSidEx,ZwOpenThreadTokenEx,LdrInitializeThunk,ZwOpenProcessTokenEx,ZwDuplicateToken,ZwClose,ZwClose,RtlCheckTokenMembershipEx, | 0_2_6CF06060 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24060 ZwQuerySemaphore, | 0_2_6CF24060 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9A060 RtlOsDeploymentState,RtlInitUnicodeString,ZwOpenKey,RtlInitUnicodeString,ZwQueryValueKey, | 0_2_6CF9A060 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24050 ZwQuerySecurityPolicy, | 0_2_6CF24050 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24040 ZwQuerySecurityObject, | 0_2_6CF24040 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF16045 ZwClose, | 0_2_6CF16045 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF64043 ZwOpenFile,ZwQueryVirtualMemory,ZwOpenFile, | 0_2_6CF64043 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24030 ZwQuerySecurityAttributesToken, | 0_2_6CF24030 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6C03E RtlInitUnicodeString,ZwOpenKey,ZwClose, | 0_2_6CF6C03E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24020 ZwQueryQuotaInformationFile, | 0_2_6CF24020 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24010 ZwQueryPortInformationProcess, | 0_2_6CF24010 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24000 ZwQueryOpenSubKeysEx, | 0_2_6CF24000 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4003 RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,ZwSetInformationJobObject,ZwQueryInformationJobObject,RtlReleaseSRWLockExclusive,RtlDebugPrintTimes, | 0_2_6CFB4003 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1C1F0 RtlSetUnhandledExceptionFilter,RtlSetUnhandledExceptionFilter,ZwQueryInformationProcess,RtlRaiseStatus, | 0_2_6CF1C1F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF241F0 ZwReplyWaitReplyPort, | 0_2_6CF241F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB81F0 ZwQueryVirtualMemory,ZwPssCaptureVaSpaceBulk,ZwQueryVirtualMemory, | 0_2_6CFB81F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF241E0 ZwReplacePartitionUnit, | 0_2_6CF241E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF641E2 ZwGetCachedSigningLevel,ZwCompareSigningLevels,ZwSetCachedSigningLevel, | 0_2_6CF641E2 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB61E5 RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CFB61E5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF241D0 ZwReplaceKey, | 0_2_6CF241D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF801D0 RtlAssert,RtlCaptureContext,DbgPrintEx,DbgPrompt,ZwTerminateThread,DbgPrintEx,RtlAssert,ZwTerminateProcess, | 0_2_6CF801D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF941CB ZwQueryVirtualMemory,bsearch_s, | 0_2_6CF941CB |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF241C0 ZwRenameTransactionManager, | 0_2_6CF241C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFA61C3 RtlAllocateHeap,ZwQueryWnfStateData,ZwUpdateWnfStateData,RtlFreeHeap, | 0_2_6CFA61C3 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9A1C0 RtlQueryValidationRunlevel,ZwOpenKey,ZwQueryValueKey,ZwClose, | 0_2_6CF9A1C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB41C0 TpQueryPoolStackInformation,ZwQueryInformationWorkerFactory, | 0_2_6CFB41C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF241B0 ZwRenameKey, | 0_2_6CF241B0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFBA1B6 ZwCreateFile, | 0_2_6CFBA1B6 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF241A0 ZwRemoveProcessDebug, | 0_2_6CF241A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF141A2 ZwAlertThreadByThreadId, | 0_2_6CF141A2 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24190 ZwRemoveIoCompletionEx, | 0_2_6CF24190 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5E190 RtlFreeUserStack,ZwFreeVirtualMemory, | 0_2_6CF5E190 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6019F RtlGetCurrentServiceSessionId,RtlAllocateHeap,memcpy,RtlGetCurrentServiceSessionId,ZwTraceEvent,RtlFreeHeap, | 0_2_6CF6019F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE819E ZwOpenProcessTokenEx,ZwDuplicateToken,ZwSetInformationObject,ZwSetInformationThread,ZwAdjustPrivilegesToken,ZwSetInformationThread, | 0_2_6CEE819E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE419F ZwCreateTimer2,ZwCreateWaitCompletionPacket,ZwAssociateWaitCompletionPacket,ZwClose, | 0_2_6CEE419F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24180 ZwReleaseWorkerFactoryWorker, | 0_2_6CF24180 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF20185 ZwQuerySystemInformation,EtwpCreateEtwThread,RtlNtStatusToDosError,RtlNtStatusToDosError,ZwClose,RtlNtStatusToDosError, | 0_2_6CF20185 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDA197 RtlInitUnicodeStringEx,ZwQueryValueKey,RtlInitUnicodeStringEx,RtlPrefixUnicodeString,ZwEnumerateKey,ZwOpenKey,RtlInitUnicodeStringEx,ZwQueryValueKey,RtlFreeHeap,ZwClose,RtlAllocateHeap,RtlCompareUnicodeString,ZwClose,RtlFreeHeap,ZwClose, | 0_2_6CEDA197 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB6187 ZwSetInformationThread,memset,RtlRaiseException, | 0_2_6CFB6187 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24170 ZwReleaseKeyedEvent, | 0_2_6CF24170 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6417C ZwRaiseHardError, | 0_2_6CF6417C |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24160 ZwRegisterThreadTerminatePort, | 0_2_6CF24160 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22160 RtlCreateUserStack,RtlImageNtHeader,ZwSetInformationProcess,ZwAllocateVirtualMemory,ZwAllocateVirtualMemory,RtlFreeUserStack,RtlCreateUserStack,RtlCreateUserStack,RtlCreateUserStack, | 0_2_6CF22160 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFBA160 RtlGetNtSystemRoot,ZwClose, | 0_2_6CFBA160 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24150 ZwRegisterProtocolAddressInformation, | 0_2_6CF24150 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0215F ZwQueryAttributesFile,RtlDeleteBoundaryDescriptor, | 0_2_6CF0215F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24140 ZwRecoverTransactionManager, | 0_2_6CF24140 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF74144 RtlGetCurrentServiceSessionId,RtlGetCurrentServiceSessionId,RtlDetermineDosPathNameType_U,RtlDosPathNameToNtPathName_U,ZwQueryAttributesFile,RtlFreeHeap,RtlGetCurrentServiceSessionId,RtlGetCurrentServiceSessionId, | 0_2_6CF74144 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9A140 RtlQueryTokenHostIdAsUlong64,ZwQuerySecurityAttributesToken, | 0_2_6CF9A140 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB8142 ZwAllocateVirtualMemory,ZwFreeVirtualMemory,ZwQueryVirtualMemory, | 0_2_6CFB8142 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6154 RtlAcquireSRWLockExclusive,RtlAcquireSRWLockExclusive,RtlReleaseSRWLockExclusive,RtlAllocateHeap,ZwDuplicateObject,RtlFreeHeap,RtlReleaseSRWLockExclusive,RtlWakeConditionVariable, | 0_2_6CEE6154 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6C137 ZwQueryVirtualMemory,ZwQuerySystemInformation,ZwAllocateVirtualMemory,ZwProtectVirtualMemory, | 0_2_6CF6C137 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24130 ZwRecoverResourceManager, | 0_2_6CF24130 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6013A ZwOpenKeyEx,ZwClose, | 0_2_6CF6013A |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24120 ZwRecoverEnlistment, | 0_2_6CF24120 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24110 ZwReadOnlyEnlistment, | 0_2_6CF24110 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9A11F ZwClose, | 0_2_6CF9A11F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE2102 TpSetDefaultPoolMaxThreads,ZwDuplicateToken, | 0_2_6CEE2102 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24100 ZwRaiseHardError, | 0_2_6CF24100 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF74104 ZwQueryInformationFile, | 0_2_6CF74104 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF8E10E ZwQuerySecurityObject,RtlAllocateHeap,ZwQuerySecurityObject,RtlFreeHeap,RtlGetDaclSecurityDescriptor,RtlGetOwnerSecurityDescriptor,RtlEqualSid,RtlGetAce,RtlEqualSid,ZwSetSecurityObject,RtlSelfRelativeToAbsoluteSD2,RtlAllocateHeap,memcpy,RtlFreeHeap,RtlSelfRelativeToAbsoluteSD2,RtlFreeHeap,RtlSetOwnerSecurityDescriptor,RtlSetDaclSecurityDescriptor,RtlMakeSelfRelativeSD,RtlAllocateHeap,RtlMakeSelfRelativeSD,RtlFreeHeap,ZwSetSecurityObject,RtlFreeHeap, | 0_2_6CF8E10E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF68100 RtlSetProcessDebugInformation,ZwUnmapViewOfSection,RtlExitUserThread, | 0_2_6CF68100 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF942F9 ZwQueryVirtualMemory,ZwQueryVirtualMemory,RtlImageDirectoryEntryToData, | 0_2_6CF942F9 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF242F0 ZwSerializeBoot, | 0_2_6CF242F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFA02F4 ZwPowerInformation,ZwClose, | 0_2_6CFA02F4 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF02E1 RtlEnterCriticalSection,RtlAllocateHeap,RtlLeaveCriticalSection,RtlReAllocateHeap,RtlLeaveCriticalSection,ZwProtectVirtualMemory,RtlLeaveCriticalSection, | 0_2_6CEF02E1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF242E0 ZwSecureConnectPort, | 0_2_6CF242E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6C2E0 RtlQueryWnfMetaNotification,ZwQueryWnfStateNameInformation, | 0_2_6CF6C2E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF242D0 ZwSaveMergedKeys, | 0_2_6CF242D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB62D6 RtlGetCurrentServiceSessionId,ZwTraceEvent, | 0_2_6CFB62D6 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF242C0 ZwSaveKeyEx, | 0_2_6CF242C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF622C5 ZwOpenKey,ZwQueryValueKey,ZwClose, | 0_2_6CF622C5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF702C0 RtlQueryImageMitigationPolicy,RtlInitUnicodeStringEx,RtlInitUnicodeStringEx,ZwOpenKey,ZwQueryValueKey,ZwClose,memcpy,RtlQueryImageMitigationPolicy, | 0_2_6CF702C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF242B0 ZwSaveKey, | 0_2_6CF242B0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF242A0 ZwRollforwardTransactionManager, | 0_2_6CF242A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF762A0 RtlAcquirePrivilege,RtlAllocateHeap,ZwSetInformationThread,RtlImpersonateSelfEx,ZwOpenProcessTokenEx,ZwAdjustPrivilegesToken,RtlAllocateHeap,ZwAdjustPrivilegesToken,RtlFreeHeap,RtlFreeHeap,ZwClose,ZwSetInformationThread,ZwClose,RtlFreeHeap, | 0_2_6CF762A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF22B0 RtlSleepConditionVariableSRW,RtlReleaseSRWLockExclusive,ZwWaitForAlertByThreadId,RtlAcquireSRWLockExclusive,RtlAcquireSRWLockShared,RtlSleepConditionVariableSRW,RtlReleaseSRWLockShared,ZwWaitForAlertByThreadId, | 0_2_6CEF22B0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF12CF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF12CF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF12CF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF12CF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF12CF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF12CF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF12CF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF12CF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDCCC8 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDCCC8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED8CD0 mov eax, dword ptr fs:[00000030h] | 0_2_6CED8CD0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF08CB1 mov eax, dword ptr fs:[00000030h] | 0_2_6CF08CB1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF08CB1 mov eax, dword ptr fs:[00000030h] | 0_2_6CF08CB1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CF90CB5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CF90CB5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CF90CB5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CF90CB5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CF90CB5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CF90CB5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CF90CB5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CF90CB5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CF90CB5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CF90CB5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CF90CB5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CF90CB5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF90CB5 mov eax, dword ptr fs:[00000030h] | 0_2_6CF90CB5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5CCA0 mov ecx, dword ptr fs:[00000030h] | 0_2_6CF5CCA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5CCA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF5CCA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5CCA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF5CCA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5CCA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF5CCA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED8C8D mov eax, dword ptr fs:[00000030h] | 0_2_6CED8C8D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF7AC60 mov eax, dword ptr fs:[00000030h] | 0_2_6CF7AC60 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF7AC60 mov eax, dword ptr fs:[00000030h] | 0_2_6CF7AC60 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF14C59 mov eax, dword ptr fs:[00000030h] | 0_2_6CF14C59 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEAC50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEAC50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEAC50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEAC50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEAC50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEAC50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEAC50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEAC50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEAC50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEAC50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEAC50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEAC50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6C50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE6C50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6C50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE6C50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6C50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE6C50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF84C34 mov eax, dword ptr fs:[00000030h] | 0_2_6CF84C34 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF84C34 mov eax, dword ptr fs:[00000030h] | 0_2_6CF84C34 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF84C34 mov eax, dword ptr fs:[00000030h] | 0_2_6CF84C34 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF84C34 mov eax, dword ptr fs:[00000030h] | 0_2_6CF84C34 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF84C34 mov eax, dword ptr fs:[00000030h] | 0_2_6CF84C34 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF84C34 mov eax, dword ptr fs:[00000030h] | 0_2_6CF84C34 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF84C34 mov ecx, dword ptr fs:[00000030h] | 0_2_6CF84C34 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDEC20 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDEC20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF7CC20 mov eax, dword ptr fs:[00000030h] | 0_2_6CF7CC20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF7CC20 mov eax, dword ptr fs:[00000030h] | 0_2_6CF7CC20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF0C00 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF0C00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF0C00 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF0C00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF0C00 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF0C00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF0C00 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF0C00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1CC00 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1CC00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF64C0F mov eax, dword ptr fs:[00000030h] | 0_2_6CF64C0F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0CDF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0CDF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0CDF0 mov ecx, dword ptr fs:[00000030h] | 0_2_6CF0CDF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDCDEA mov eax, dword ptr fs:[00000030h] | 0_2_6CEDCDEA |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDCDEA mov eax, dword ptr fs:[00000030h] | 0_2_6CEDCDEA |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF80DF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF80DF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF80DF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF80DF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF00DE1 mov eax, dword ptr fs:[00000030h] | 0_2_6CF00DE1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED6DF6 mov eax, dword ptr fs:[00000030h] | 0_2_6CED6DF6 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF64DD7 mov eax, dword ptr fs:[00000030h] | 0_2_6CF64DD7 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF64DD7 mov eax, dword ptr fs:[00000030h] | 0_2_6CF64DD7 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0EDD3 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0EDD3 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0EDD3 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0EDD3 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1CDB1 mov ecx, dword ptr fs:[00000030h] | 0_2_6CF1CDB1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1CDB1 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1CDB1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1CDB1 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1CDB1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF08DBF mov eax, dword ptr fs:[00000030h] | 0_2_6CF08DBF |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF08DBF mov eax, dword ptr fs:[00000030h] | 0_2_6CF08DBF |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF16DA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF16DA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFA8DAE mov eax, dword ptr fs:[00000030h] | 0_2_6CFA8DAE |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFA8DAE mov eax, dword ptr fs:[00000030h] | 0_2_6CFA8DAE |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4DAD mov eax, dword ptr fs:[00000030h] | 0_2_6CFB4DAD |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF78D6B mov eax, dword ptr fs:[00000030h] | 0_2_6CF78D6B |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE0D59 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE0D59 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE0D59 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE0D59 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE0D59 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE0D59 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE8D59 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE8D59 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE8D59 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE8D59 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE8D59 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE8D59 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE8D59 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE8D59 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE8D59 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE8D59 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4D30 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB4D30 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF68D20 mov eax, dword ptr fs:[00000030h] | 0_2_6CF68D20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF98D10 mov eax, dword ptr fs:[00000030h] | 0_2_6CF98D10 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF98D10 mov eax, dword ptr fs:[00000030h] | 0_2_6CF98D10 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF14D1D mov eax, dword ptr fs:[00000030h] | 0_2_6CF14D1D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEFAD00 mov eax, dword ptr fs:[00000030h] | 0_2_6CEFAD00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEFAD00 mov eax, dword ptr fs:[00000030h] | 0_2_6CEFAD00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEFAD00 mov eax, dword ptr fs:[00000030h] | 0_2_6CEFAD00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED6D10 mov eax, dword ptr fs:[00000030h] | 0_2_6CED6D10 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED6D10 mov eax, dword ptr fs:[00000030h] | 0_2_6CED6D10 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED6D10 mov eax, dword ptr fs:[00000030h] | 0_2_6CED6D10 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF18EF5 mov eax, dword ptr fs:[00000030h] | 0_2_6CF18EF5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6EE0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE6EE0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6EE0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE6EE0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6EE0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE6EE0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6EE0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE6EE0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF96ED0 mov ecx, dword ptr fs:[00000030h] | 0_2_6CF96ED0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF7AEB0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF7AEB0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF7AEB0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF7AEB0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF96EB0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF96EB0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6CEA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF6CEA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6CEA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF6CEA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6CEA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF6CEA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF12E9C mov eax, dword ptr fs:[00000030h] | 0_2_6CF12E9C |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF12E9C mov ecx, dword ptr fs:[00000030h] | 0_2_6CF12E9C |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDAE90 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDAE90 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDAE90 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDAE90 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDAE90 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDAE90 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF60E7F mov eax, dword ptr fs:[00000030h] | 0_2_6CF60E7F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF60E7F mov eax, dword ptr fs:[00000030h] | 0_2_6CF60E7F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF60E7F mov eax, dword ptr fs:[00000030h] | 0_2_6CF60E7F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6E71 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE6E71 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB2E4F mov eax, dword ptr fs:[00000030h] | 0_2_6CFB2E4F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB2E4F mov eax, dword ptr fs:[00000030h] | 0_2_6CFB2E4F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDEE5A mov eax, dword ptr fs:[00000030h] | 0_2_6CEDEE5A |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF14E30 mov eax, dword ptr fs:[00000030h] | 0_2_6CF14E30 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF76E20 mov eax, dword ptr fs:[00000030h] | 0_2_6CF76E20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF76E20 mov eax, dword ptr fs:[00000030h] | 0_2_6CF76E20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF76E20 mov ecx, dword ptr fs:[00000030h] | 0_2_6CF76E20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF18E1A mov eax, dword ptr fs:[00000030h] | 0_2_6CF18E1A |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED8E1D mov eax, dword ptr fs:[00000030h] | 0_2_6CED8E1D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0AE00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0AE00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0AE00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0AE00 mov ecx, dword ptr fs:[00000030h] | 0_2_6CF0AE00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0AE00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0AE00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0AE00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0AE00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0AE00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0AE00 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0AE00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF20FF6 mov eax, dword ptr fs:[00000030h] | 0_2_6CF20FF6 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF20FF6 mov eax, dword ptr fs:[00000030h] | 0_2_6CF20FF6 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF20FF6 mov eax, dword ptr fs:[00000030h] | 0_2_6CF20FF6 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF20FF6 mov eax, dword ptr fs:[00000030h] | 0_2_6CF20FF6 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF96FF7 mov eax, dword ptr fs:[00000030h] | 0_2_6CF96FF7 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEFCFE0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEFCFE0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4FE7 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB4FE7 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED8FF0 mov ecx, dword ptr fs:[00000030h] | 0_2_6CED8FF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED8FF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CED8FF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE2FC8 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE2FC8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE2FC8 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE2FC8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE2FC8 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE2FC8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE2FC8 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE2FC8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDEFD8 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDEFD8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDEFD8 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDEFD8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDEFD8 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDEFD8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF12F98 mov eax, dword ptr fs:[00000030h] | 0_2_6CF12F98 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF12F98 mov eax, dword ptr fs:[00000030h] | 0_2_6CF12F98 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1CF80 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1CF80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF16F60 mov eax, dword ptr fs:[00000030h] | 0_2_6CF16F60 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF16F60 mov eax, dword ptr fs:[00000030h] | 0_2_6CF16F60 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4F68 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB4F68 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF82F60 mov eax, dword ptr fs:[00000030h] | 0_2_6CF82F60 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF82F60 mov eax, dword ptr fs:[00000030h] | 0_2_6CF82F60 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0AF69 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0AF69 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0AF69 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0AF69 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1CF50 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1CF50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF80F50 mov eax, dword ptr fs:[00000030h] | 0_2_6CF80F50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF64F40 mov eax, dword ptr fs:[00000030h] | 0_2_6CF64F40 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF64F40 mov eax, dword ptr fs:[00000030h] | 0_2_6CF64F40 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF64F40 mov eax, dword ptr fs:[00000030h] | 0_2_6CF64F40 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF64F40 mov eax, dword ptr fs:[00000030h] | 0_2_6CF64F40 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF84F42 mov eax, dword ptr fs:[00000030h] | 0_2_6CF84F42 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDCF50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDCF50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDCF50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDCF50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDCF50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDCF50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDCF50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDCF50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDCF50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDCF50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDCF50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDCF50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0EF28 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0EF28 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF24F10 mov eax, dword ptr fs:[00000030h] | 0_2_6CF24F10 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1CF1F mov eax, dword ptr fs:[00000030h] | 0_2_6CF1CF1F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF96F00 mov eax, dword ptr fs:[00000030h] | 0_2_6CF96F00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE2F12 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE2F12 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1C8F9 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1C8F9 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1C8F9 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1C8F9 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE28F0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE28F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE28F0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE28F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE28F0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE28F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE28F0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE28F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE28F0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE28F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE28F0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE28F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFAA8E4 mov eax, dword ptr fs:[00000030h] | 0_2_6CFAA8E4 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0E8C0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0E8C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB08C0 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB08C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE0887 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE0887 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6C89D mov eax, dword ptr fs:[00000030h] | 0_2_6CF6C89D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6E872 mov eax, dword ptr fs:[00000030h] | 0_2_6CF6E872 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6E872 mov eax, dword ptr fs:[00000030h] | 0_2_6CF6E872 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF76870 mov eax, dword ptr fs:[00000030h] | 0_2_6CF76870 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF76870 mov eax, dword ptr fs:[00000030h] | 0_2_6CF76870 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF10854 mov eax, dword ptr fs:[00000030h] | 0_2_6CF10854 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE4859 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE4859 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE4859 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE4859 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1A830 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1A830 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF8483A mov eax, dword ptr fs:[00000030h] | 0_2_6CF8483A |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF8483A mov eax, dword ptr fs:[00000030h] | 0_2_6CF8483A |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF02835 mov eax, dword ptr fs:[00000030h] | 0_2_6CF02835 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF02835 mov eax, dword ptr fs:[00000030h] | 0_2_6CF02835 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF02835 mov eax, dword ptr fs:[00000030h] | 0_2_6CF02835 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF02835 mov ecx, dword ptr fs:[00000030h] | 0_2_6CF02835 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF02835 mov eax, dword ptr fs:[00000030h] | 0_2_6CF02835 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF02835 mov eax, dword ptr fs:[00000030h] | 0_2_6CF02835 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6C810 mov eax, dword ptr fs:[00000030h] | 0_2_6CF6C810 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF129F9 mov eax, dword ptr fs:[00000030h] | 0_2_6CF129F9 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF129F9 mov eax, dword ptr fs:[00000030h] | 0_2_6CF129F9 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6E9E0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF6E9E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF149D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF149D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFAA9D3 mov eax, dword ptr fs:[00000030h] | 0_2_6CFAA9D3 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF769C0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF769C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEA9D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEA9D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEA9D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEA9D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEA9D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEA9D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEA9D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEA9D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEA9D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEA9D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEA9D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEA9D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE09AD mov eax, dword ptr fs:[00000030h] | 0_2_6CEE09AD |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE09AD mov eax, dword ptr fs:[00000030h] | 0_2_6CEE09AD |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF689B3 mov esi, dword ptr fs:[00000030h] | 0_2_6CF689B3 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF689B3 mov eax, dword ptr fs:[00000030h] | 0_2_6CF689B3 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF689B3 mov eax, dword ptr fs:[00000030h] | 0_2_6CF689B3 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF29A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF29A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF29A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF29A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF29A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF29A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF29A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF29A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF29A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF29A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF29A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF29A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF29A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEF29A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF84978 mov eax, dword ptr fs:[00000030h] | 0_2_6CF84978 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF84978 mov eax, dword ptr fs:[00000030h] | 0_2_6CF84978 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1C970 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1C970 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1C970 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1C970 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6C97C mov eax, dword ptr fs:[00000030h] | 0_2_6CF6C97C |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF06962 mov eax, dword ptr fs:[00000030h] | 0_2_6CF06962 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF06962 mov eax, dword ptr fs:[00000030h] | 0_2_6CF06962 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF06962 mov eax, dword ptr fs:[00000030h] | 0_2_6CF06962 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF2096E mov eax, dword ptr fs:[00000030h] | 0_2_6CF2096E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF2096E mov edx, dword ptr fs:[00000030h] | 0_2_6CF2096E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF2096E mov eax, dword ptr fs:[00000030h] | 0_2_6CF2096E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1A950 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1A950 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF60946 mov eax, dword ptr fs:[00000030h] | 0_2_6CF60946 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4940 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB4940 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6892A mov eax, dword ptr fs:[00000030h] | 0_2_6CF6892A |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF7892B mov eax, dword ptr fs:[00000030h] | 0_2_6CF7892B |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6C912 mov eax, dword ptr fs:[00000030h] | 0_2_6CF6C912 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED8918 mov eax, dword ptr fs:[00000030h] | 0_2_6CED8918 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED8918 mov eax, dword ptr fs:[00000030h] | 0_2_6CED8918 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5E908 mov eax, dword ptr fs:[00000030h] | 0_2_6CF5E908 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5E908 mov eax, dword ptr fs:[00000030h] | 0_2_6CF5E908 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1AAEE mov eax, dword ptr fs:[00000030h] | 0_2_6CF1AAEE |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1AAEE mov eax, dword ptr fs:[00000030h] | 0_2_6CF1AAEE |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF14AD0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF14AD0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF14AD0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF14AD0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE0AD0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE0AD0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF36ACC mov eax, dword ptr fs:[00000030h] | 0_2_6CF36ACC |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF36ACC mov eax, dword ptr fs:[00000030h] | 0_2_6CF36ACC |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF36ACC mov eax, dword ptr fs:[00000030h] | 0_2_6CF36ACC |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE8AA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE8AA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE8AA0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE8AA0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF36AA4 mov eax, dword ptr fs:[00000030h] | 0_2_6CF36AA4 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF18A90 mov edx, dword ptr fs:[00000030h] | 0_2_6CF18A90 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDEA80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDEA80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEEA80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEEA80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEEA80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEEA80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEEA80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEEA80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEEA80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEEA80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEEEA80 mov eax, dword ptr fs:[00000030h] | 0_2_6CEEEA80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4A80 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB4A80 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5CA72 mov eax, dword ptr fs:[00000030h] | 0_2_6CF5CA72 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5CA72 mov eax, dword ptr fs:[00000030h] | 0_2_6CF5CA72 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF8EA60 mov eax, dword ptr fs:[00000030h] | 0_2_6CF8EA60 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1CA6F mov eax, dword ptr fs:[00000030h] | 0_2_6CF1CA6F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1CA6F mov eax, dword ptr fs:[00000030h] | 0_2_6CF1CA6F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1CA6F mov eax, dword ptr fs:[00000030h] | 0_2_6CF1CA6F |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF10A50 mov eax, dword ptr fs:[00000030h] | 0_2_6CF10A50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF0A5B mov eax, dword ptr fs:[00000030h] | 0_2_6CEF0A5B |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF0A5B mov eax, dword ptr fs:[00000030h] | 0_2_6CEF0A5B |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6A50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE6A50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6A50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE6A50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6A50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE6A50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6A50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE6A50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6A50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE6A50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6A50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE6A50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE6A50 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE6A50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF04A35 mov eax, dword ptr fs:[00000030h] | 0_2_6CF04A35 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF04A35 mov eax, dword ptr fs:[00000030h] | 0_2_6CF04A35 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1CA38 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1CA38 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1CA24 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1CA24 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0EA2E mov eax, dword ptr fs:[00000030h] | 0_2_6CF0EA2E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6CA11 mov eax, dword ptr fs:[00000030h] | 0_2_6CF6CA11 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED8A00 mov eax, dword ptr fs:[00000030h] | 0_2_6CED8A00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED8A00 mov eax, dword ptr fs:[00000030h] | 0_2_6CED8A00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF18BF0 mov ecx, dword ptr fs:[00000030h] | 0_2_6CF18BF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF18BF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF18BF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF18BF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF18BF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6CBF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF6CBF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0EBFC mov eax, dword ptr fs:[00000030h] | 0_2_6CF0EBFC |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE8BF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE8BF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE8BF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE8BF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE8BF0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE8BF0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE0BCD mov eax, dword ptr fs:[00000030h] | 0_2_6CEE0BCD |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE0BCD mov eax, dword ptr fs:[00000030h] | 0_2_6CEE0BCD |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE0BCD mov eax, dword ptr fs:[00000030h] | 0_2_6CEE0BCD |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF8EBD0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF8EBD0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF00BCB mov eax, dword ptr fs:[00000030h] | 0_2_6CF00BCB |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF00BCB mov eax, dword ptr fs:[00000030h] | 0_2_6CF00BCB |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF00BCB mov eax, dword ptr fs:[00000030h] | 0_2_6CF00BCB |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF94BB0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF94BB0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF94BB0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF94BB0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF0BBE mov eax, dword ptr fs:[00000030h] | 0_2_6CEF0BBE |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF0BBE mov eax, dword ptr fs:[00000030h] | 0_2_6CEF0BBE |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDCB7E mov eax, dword ptr fs:[00000030h] | 0_2_6CEDCB7E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF8EB50 mov eax, dword ptr fs:[00000030h] | 0_2_6CF8EB50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB2B57 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB2B57 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB2B57 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB2B57 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB2B57 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB2B57 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB2B57 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB2B57 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF94B4B mov eax, dword ptr fs:[00000030h] | 0_2_6CF94B4B |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF94B4B mov eax, dword ptr fs:[00000030h] | 0_2_6CF94B4B |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF76B40 mov eax, dword ptr fs:[00000030h] | 0_2_6CF76B40 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF76B40 mov eax, dword ptr fs:[00000030h] | 0_2_6CF76B40 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF88B42 mov eax, dword ptr fs:[00000030h] | 0_2_6CF88B42 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFAAB40 mov eax, dword ptr fs:[00000030h] | 0_2_6CFAAB40 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED8B50 mov eax, dword ptr fs:[00000030h] | 0_2_6CED8B50 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0EB20 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0EB20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0EB20 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0EB20 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CF5EB1D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CF5EB1D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CF5EB1D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CF5EB1D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CF5EB1D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CF5EB1D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CF5EB1D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CF5EB1D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5EB1D mov eax, dword ptr fs:[00000030h] | 0_2_6CF5EB1D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4B00 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB4B00 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE04E5 mov ecx, dword ptr fs:[00000030h] | 0_2_6CEE04E5 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF144B0 mov ecx, dword ptr fs:[00000030h] | 0_2_6CF144B0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE64AB mov eax, dword ptr fs:[00000030h] | 0_2_6CEE64AB |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6A4B0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF6A4B0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9A49A mov eax, dword ptr fs:[00000030h] | 0_2_6CF9A49A |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0A470 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0A470 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0A470 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0A470 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0A470 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0A470 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6C460 mov ecx, dword ptr fs:[00000030h] | 0_2_6CF6C460 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0245A mov eax, dword ptr fs:[00000030h] | 0_2_6CF0245A |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF9A456 mov eax, dword ptr fs:[00000030h] | 0_2_6CF9A456 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED645D mov eax, dword ptr fs:[00000030h] | 0_2_6CED645D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1E443 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1E443 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1E443 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1E443 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1E443 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1E443 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1E443 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1E443 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1E443 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1E443 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1E443 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1E443 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1E443 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1E443 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1E443 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1E443 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1A430 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1A430 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDC427 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDC427 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDE420 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDE420 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDE420 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDE420 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDE420 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDE420 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF66420 mov eax, dword ptr fs:[00000030h] | 0_2_6CF66420 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF66420 mov eax, dword ptr fs:[00000030h] | 0_2_6CF66420 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF66420 mov eax, dword ptr fs:[00000030h] | 0_2_6CF66420 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF66420 mov eax, dword ptr fs:[00000030h] | 0_2_6CF66420 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF66420 mov eax, dword ptr fs:[00000030h] | 0_2_6CF66420 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF66420 mov eax, dword ptr fs:[00000030h] | 0_2_6CF66420 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF66420 mov eax, dword ptr fs:[00000030h] | 0_2_6CF66420 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF18402 mov eax, dword ptr fs:[00000030h] | 0_2_6CF18402 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF18402 mov eax, dword ptr fs:[00000030h] | 0_2_6CF18402 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF18402 mov eax, dword ptr fs:[00000030h] | 0_2_6CF18402 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE25E0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE25E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1C5ED mov eax, dword ptr fs:[00000030h] | 0_2_6CF1C5ED |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1C5ED mov eax, dword ptr fs:[00000030h] | 0_2_6CF1C5ED |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1A5D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1A5D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1A5D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1A5D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1E5CF mov eax, dword ptr fs:[00000030h] | 0_2_6CF1E5CF |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1E5CF mov eax, dword ptr fs:[00000030h] | 0_2_6CF1E5CF |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE65D0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE65D0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF045B1 mov eax, dword ptr fs:[00000030h] | 0_2_6CF045B1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF045B1 mov eax, dword ptr fs:[00000030h] | 0_2_6CF045B1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE2582 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE2582 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE2582 mov ecx, dword ptr fs:[00000030h] | 0_2_6CEE2582 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDA580 mov ecx, dword ptr fs:[00000030h] | 0_2_6CEDA580 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDA580 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDA580 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1E59C mov eax, dword ptr fs:[00000030h] | 0_2_6CF1E59C |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF14588 mov eax, dword ptr fs:[00000030h] | 0_2_6CF14588 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE8550 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE8550 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE8550 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE8550 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0E53E mov eax, dword ptr fs:[00000030h] | 0_2_6CF0E53E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0E53E mov eax, dword ptr fs:[00000030h] | 0_2_6CF0E53E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0E53E mov eax, dword ptr fs:[00000030h] | 0_2_6CF0E53E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0E53E mov eax, dword ptr fs:[00000030h] | 0_2_6CF0E53E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0E53E mov eax, dword ptr fs:[00000030h] | 0_2_6CF0E53E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF76500 mov eax, dword ptr fs:[00000030h] | 0_2_6CF76500 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4500 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB4500 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4500 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB4500 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4500 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB4500 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4500 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB4500 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4500 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB4500 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4500 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB4500 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFB4500 mov eax, dword ptr fs:[00000030h] | 0_2_6CFB4500 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5E6F2 mov eax, dword ptr fs:[00000030h] | 0_2_6CF5E6F2 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5E6F2 mov eax, dword ptr fs:[00000030h] | 0_2_6CF5E6F2 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5E6F2 mov eax, dword ptr fs:[00000030h] | 0_2_6CF5E6F2 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5E6F2 mov eax, dword ptr fs:[00000030h] | 0_2_6CF5E6F2 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF606F1 mov eax, dword ptr fs:[00000030h] | 0_2_6CF606F1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF606F1 mov eax, dword ptr fs:[00000030h] | 0_2_6CF606F1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1A6C7 mov ebx, dword ptr fs:[00000030h] | 0_2_6CF1A6C7 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1A6C7 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1A6C7 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF166B0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF166B0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1C6A6 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1C6A6 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE4690 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE4690 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE4690 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE4690 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF12674 mov eax, dword ptr fs:[00000030h] | 0_2_6CF12674 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1A660 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1A660 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1A660 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1A660 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEFC640 mov eax, dword ptr fs:[00000030h] | 0_2_6CEFC640 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE262C mov eax, dword ptr fs:[00000030h] | 0_2_6CEE262C |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEFE627 mov eax, dword ptr fs:[00000030h] | 0_2_6CEFE627 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF16620 mov eax, dword ptr fs:[00000030h] | 0_2_6CF16620 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF18620 mov eax, dword ptr fs:[00000030h] | 0_2_6CF18620 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF260B mov eax, dword ptr fs:[00000030h] | 0_2_6CEF260B |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF260B mov eax, dword ptr fs:[00000030h] | 0_2_6CEF260B |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF260B mov eax, dword ptr fs:[00000030h] | 0_2_6CEF260B |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF260B mov eax, dword ptr fs:[00000030h] | 0_2_6CEF260B |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF260B mov eax, dword ptr fs:[00000030h] | 0_2_6CEF260B |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF260B mov eax, dword ptr fs:[00000030h] | 0_2_6CEF260B |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEF260B mov eax, dword ptr fs:[00000030h] | 0_2_6CEF260B |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22619 mov eax, dword ptr fs:[00000030h] | 0_2_6CF22619 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5E609 mov eax, dword ptr fs:[00000030h] | 0_2_6CF5E609 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1C7F0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1C7F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE47FB mov eax, dword ptr fs:[00000030h] | 0_2_6CEE47FB |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE47FB mov eax, dword ptr fs:[00000030h] | 0_2_6CEE47FB |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6E7E1 mov eax, dword ptr fs:[00000030h] | 0_2_6CF6E7E1 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF027ED mov eax, dword ptr fs:[00000030h] | 0_2_6CF027ED |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF027ED mov eax, dword ptr fs:[00000030h] | 0_2_6CF027ED |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF027ED mov eax, dword ptr fs:[00000030h] | 0_2_6CF027ED |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF067C0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF067C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF067C0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF067C0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF607C3 mov eax, dword ptr fs:[00000030h] | 0_2_6CF607C3 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE07AF mov eax, dword ptr fs:[00000030h] | 0_2_6CEE07AF |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF947A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF947A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF8678E mov eax, dword ptr fs:[00000030h] | 0_2_6CF8678E |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE8770 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE8770 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22750 mov eax, dword ptr fs:[00000030h] | 0_2_6CF22750 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF22750 mov eax, dword ptr fs:[00000030h] | 0_2_6CF22750 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF64755 mov eax, dword ptr fs:[00000030h] | 0_2_6CF64755 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF6E75D mov eax, dword ptr fs:[00000030h] | 0_2_6CF6E75D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDA740 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDA740 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1674D mov esi, dword ptr fs:[00000030h] | 0_2_6CF1674D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1674D mov eax, dword ptr fs:[00000030h] | 0_2_6CF1674D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1674D mov eax, dword ptr fs:[00000030h] | 0_2_6CF1674D |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE0750 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE0750 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF5C730 mov eax, dword ptr fs:[00000030h] | 0_2_6CF5C730 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1273C mov eax, dword ptr fs:[00000030h] | 0_2_6CF1273C |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1273C mov ecx, dword ptr fs:[00000030h] | 0_2_6CF1273C |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1273C mov eax, dword ptr fs:[00000030h] | 0_2_6CF1273C |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1C720 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1C720 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1C720 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1C720 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF10710 mov eax, dword ptr fs:[00000030h] | 0_2_6CF10710 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1C700 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1C700 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE0710 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE0710 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF220F0 mov ecx, dword ptr fs:[00000030h] | 0_2_6CF220F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE80E9 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE80E9 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDA0E3 mov ecx, dword ptr fs:[00000030h] | 0_2_6CEDA0E3 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF660E0 mov eax, dword ptr fs:[00000030h] | 0_2_6CF660E0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDC0F0 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDC0F0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF620DE mov eax, dword ptr fs:[00000030h] | 0_2_6CF620DE |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFA60B8 mov eax, dword ptr fs:[00000030h] | 0_2_6CFA60B8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CFA60B8 mov ecx, dword ptr fs:[00000030h] | 0_2_6CFA60B8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CED80A0 mov eax, dword ptr fs:[00000030h] | 0_2_6CED80A0 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF780A8 mov eax, dword ptr fs:[00000030h] | 0_2_6CF780A8 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE208A mov eax, dword ptr fs:[00000030h] | 0_2_6CEE208A |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF0C073 mov eax, dword ptr fs:[00000030h] | 0_2_6CF0C073 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF1A060 mov eax, dword ptr fs:[00000030h] | 0_2_6CF1A060 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF66050 mov eax, dword ptr fs:[00000030h] | 0_2_6CF66050 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEE2050 mov eax, dword ptr fs:[00000030h] | 0_2_6CEE2050 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF76030 mov eax, dword ptr fs:[00000030h] | 0_2_6CF76030 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDA020 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDA020 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CEDC020 mov eax, dword ptr fs:[00000030h] | 0_2_6CEDC020 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF64000 mov ecx, dword ptr fs:[00000030h] | 0_2_6CF64000 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF82000 mov eax, dword ptr fs:[00000030h] | 0_2_6CF82000 |
Source: C:\Users\user\Desktop\FgfPZQyCMj.exe | Code function: 0_2_6CF82000 mov eax, dword ptr fs:[00000030h] | 0_2_6CF82000 |