Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 40BCF0 second address: 40BCF5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 40BCF5 second address: 40BCFA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 58DB92 second address: 58DB9C instructions: 0x00000000 rdtsc 0x00000002 ja 00007FB83CF3EE46h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 58DB9C second address: 58DBB4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jnc 00007FB83CBE53C2h 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 58DBB4 second address: 58DBD1 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE58h 0x00000007 pushad 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 58DE46 second address: 58DE75 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 je 00007FB83CBE53C8h 0x0000000b jmp 00007FB83CBE53BEh 0x00000010 push eax 0x00000011 push edx 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 58DE75 second address: 58DE7B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 590F62 second address: 590F6C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jl 00007FB83CBE53B6h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 590F6C second address: 590F94 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE53h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov eax, dword ptr [eax] 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FB83CF3EE4Bh 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 590F94 second address: 590F99 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 590FE7 second address: 591006 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE4Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push eax 0x0000000b push edx 0x0000000c jnc 00007FB83CF3EE4Ch 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 591006 second address: 591010 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jg 00007FB83CBE53B6h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5910CE second address: 5910DF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 popad 0x00000006 push eax 0x00000007 jc 00007FB83CF3EE54h 0x0000000d push eax 0x0000000e push edx 0x0000000f push edi 0x00000010 pop edi 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5910DF second address: 5910E3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5910E3 second address: 591135 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 mov eax, dword ptr [esp+04h] 0x0000000a push edi 0x0000000b jmp 00007FB83CF3EE57h 0x00000010 pop edi 0x00000011 mov eax, dword ptr [eax] 0x00000013 jmp 00007FB83CF3EE56h 0x00000018 mov dword ptr [esp+04h], eax 0x0000001c pushad 0x0000001d jmp 00007FB83CF3EE4Eh 0x00000022 push eax 0x00000023 push edx 0x00000024 push esi 0x00000025 pop esi 0x00000026 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 591135 second address: 59118D instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 pop eax 0x00000008 push 00000000h 0x0000000a push ebx 0x0000000b call 00007FB83CBE53B8h 0x00000010 pop ebx 0x00000011 mov dword ptr [esp+04h], ebx 0x00000015 add dword ptr [esp+04h], 00000014h 0x0000001d inc ebx 0x0000001e push ebx 0x0000001f ret 0x00000020 pop ebx 0x00000021 ret 0x00000022 pushad 0x00000023 add dx, 0A5Ah 0x00000028 mov dword ptr [ebp+122D1A9Ch], ecx 0x0000002e popad 0x0000002f lea ebx, dword ptr [ebp+12458E61h] 0x00000035 mov cx, EBF0h 0x00000039 mov dword ptr [ebp+122D1A9Ch], ebx 0x0000003f push eax 0x00000040 pushad 0x00000041 push eax 0x00000042 push edx 0x00000043 jmp 00007FB83CBE53C3h 0x00000048 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 591278 second address: 59127C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 59127C second address: 5912FD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ecx 0x00000007 xor dword ptr [esp], 55386B14h 0x0000000e push 00000000h 0x00000010 push ebx 0x00000011 call 00007FB83CBE53B8h 0x00000016 pop ebx 0x00000017 mov dword ptr [esp+04h], ebx 0x0000001b add dword ptr [esp+04h], 00000016h 0x00000023 inc ebx 0x00000024 push ebx 0x00000025 ret 0x00000026 pop ebx 0x00000027 ret 0x00000028 or ecx, dword ptr [ebp+122D1A21h] 0x0000002e push 00000003h 0x00000030 mov cx, ax 0x00000033 push 00000000h 0x00000035 mov ecx, 03B80F00h 0x0000003a push 00000003h 0x0000003c push 00000000h 0x0000003e push ebp 0x0000003f call 00007FB83CBE53B8h 0x00000044 pop ebp 0x00000045 mov dword ptr [esp+04h], ebp 0x00000049 add dword ptr [esp+04h], 00000019h 0x00000051 inc ebp 0x00000052 push ebp 0x00000053 ret 0x00000054 pop ebp 0x00000055 ret 0x00000056 mov ecx, dword ptr [ebp+122D38A8h] 0x0000005c push eax 0x0000005d mov edi, dword ptr [ebp+122D1F0Eh] 0x00000063 pop ecx 0x00000064 push 99CF73A9h 0x00000069 pushad 0x0000006a push eax 0x0000006b push edx 0x0000006c jmp 00007FB83CBE53BAh 0x00000071 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5913D4 second address: 5913D8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5913D8 second address: 5913DC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5913DC second address: 591474 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 mov dword ptr [esp], eax 0x0000000a mov si, 196Ch 0x0000000e push 00000000h 0x00000010 sub dword ptr [ebp+122D320Bh], edi 0x00000016 push 310BAE04h 0x0000001b jg 00007FB83CF3EE58h 0x00000021 jmp 00007FB83CF3EE52h 0x00000026 xor dword ptr [esp], 310BAE84h 0x0000002d call 00007FB83CF3EE57h 0x00000032 mov cl, CCh 0x00000034 pop esi 0x00000035 push 00000003h 0x00000037 push 00000000h 0x00000039 jmp 00007FB83CF3EE4Fh 0x0000003e push 00000003h 0x00000040 mov edx, 618F6CE6h 0x00000045 call 00007FB83CF3EE49h 0x0000004a push esi 0x0000004b jbe 00007FB83CF3EE48h 0x00000051 push ecx 0x00000052 pop ecx 0x00000053 pop esi 0x00000054 push eax 0x00000055 push eax 0x00000056 push edx 0x00000057 push ebx 0x00000058 jmp 00007FB83CF3EE52h 0x0000005d pop ebx 0x0000005e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 591474 second address: 5914B6 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pushad 0x00000004 popad 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov eax, dword ptr [esp+04h] 0x0000000c push ecx 0x0000000d jg 00007FB83CBE53BCh 0x00000013 pop ecx 0x00000014 mov eax, dword ptr [eax] 0x00000016 jnc 00007FB83CBE53BEh 0x0000001c mov dword ptr [esp+04h], eax 0x00000020 push eax 0x00000021 push edx 0x00000022 jmp 00007FB83CBE53C2h 0x00000027 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5914B6 second address: 5914C0 instructions: 0x00000000 rdtsc 0x00000002 je 00007FB83CF3EE4Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5A2E5E second address: 5A2E63 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5A2E63 second address: 5A2E69 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push esi 0x00000005 pop esi 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 577D39 second address: 577D58 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 jmp 00007FB83CBE53C8h 0x00000008 pop ecx 0x00000009 push ebx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5AF86E second address: 5AF874 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5AF874 second address: 5AF88B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 popad 0x00000006 pushad 0x00000007 pushad 0x00000008 pushad 0x00000009 popad 0x0000000a pushad 0x0000000b popad 0x0000000c jne 00007FB83CBE53B6h 0x00000012 popad 0x00000013 push eax 0x00000014 push edx 0x00000015 pushad 0x00000016 popad 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5AF88B second address: 5AF88F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5AF88F second address: 5AF89B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a push esi 0x0000000b pop esi 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5AFDB8 second address: 5AFDBE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5B008B second address: 5B008F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5B008F second address: 5B0093 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5B0E10 second address: 5B0E14 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5B0E14 second address: 5B0E39 instructions: 0x00000000 rdtsc 0x00000002 jl 00007FB83CF3EE4Ah 0x00000008 push edi 0x00000009 pop edi 0x0000000a pushad 0x0000000b popad 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FB83CF3EE51h 0x00000013 jbe 00007FB83CF3EE46h 0x00000019 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5B1102 second address: 5B1107 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5B4740 second address: 5B478C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE4Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 popad 0x0000000a mov eax, dword ptr [esp+04h] 0x0000000e jmp 00007FB83CF3EE59h 0x00000013 mov eax, dword ptr [eax] 0x00000015 push eax 0x00000016 jg 00007FB83CF3EE48h 0x0000001c pop eax 0x0000001d mov dword ptr [esp+04h], eax 0x00000021 push eax 0x00000022 push edx 0x00000023 pushad 0x00000024 jmp 00007FB83CF3EE4Ah 0x00000029 push eax 0x0000002a push edx 0x0000002b rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5B478C second address: 5B4791 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5B36DC second address: 5B36E0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5B49DF second address: 5B49F4 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C1h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 580215 second address: 58021B instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BD3DA second address: 5BD3E9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FB83CBE53BBh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BD3E9 second address: 5BD3ED instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BD541 second address: 5BD56C instructions: 0x00000000 rdtsc 0x00000002 jp 00007FB83CBE53B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push ebx 0x0000000b push ebx 0x0000000c pop ebx 0x0000000d pop ebx 0x0000000e jmp 00007FB83CBE53C4h 0x00000013 popad 0x00000014 push eax 0x00000015 push edx 0x00000016 push edx 0x00000017 push ebx 0x00000018 pop ebx 0x00000019 push edi 0x0000001a pop edi 0x0000001b pop edx 0x0000001c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BD6DF second address: 5BD6E9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jl 00007FB83CF3EE46h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BD6E9 second address: 5BD70C instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 jmp 00007FB83CBE53C8h 0x0000000d pushad 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BD70C second address: 5BD734 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 popad 0x00000007 popad 0x00000008 push eax 0x00000009 push edx 0x0000000a push edi 0x0000000b jg 00007FB83CF3EE46h 0x00000011 pop edi 0x00000012 push eax 0x00000013 push edx 0x00000014 pushad 0x00000015 popad 0x00000016 jmp 00007FB83CF3EE52h 0x0000001b rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BD734 second address: 5BD754 instructions: 0x00000000 rdtsc 0x00000002 js 00007FB83CBE53B6h 0x00000008 jmp 00007FB83CBE53C6h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BDA56 second address: 5BDA92 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FB83CF3EE53h 0x00000009 jmp 00007FB83CF3EE4Fh 0x0000000e popad 0x0000000f jnc 00007FB83CF3EE59h 0x00000015 jmp 00007FB83CF3EE4Dh 0x0000001a push eax 0x0000001b push edx 0x0000001c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BDA92 second address: 5BDAA9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FB83CBE53BEh 0x00000009 pushad 0x0000000a push edi 0x0000000b pop edi 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BDBD4 second address: 5BDBD8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BDD43 second address: 5BDD47 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BE703 second address: 5BE70B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 push edi 0x00000007 pop edi 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BE847 second address: 5BE84B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BE84B second address: 5BE84F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BE84F second address: 5BE855 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BE855 second address: 5BE86C instructions: 0x00000000 rdtsc 0x00000002 je 00007FB83CF3EE4Ch 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push eax 0x0000000c push edx 0x0000000d push eax 0x0000000e push edx 0x0000000f pushad 0x00000010 popad 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BE86C second address: 5BE870 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BE870 second address: 5BE876 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BE876 second address: 5BE87C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BE994 second address: 5BE998 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BEB42 second address: 5BEB68 instructions: 0x00000000 rdtsc 0x00000002 je 00007FB83CBE53B8h 0x00000008 pushad 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FB83CBE53C7h 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5BF721 second address: 5BF725 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 583716 second address: 583762 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 ja 00007FB83CBE53B6h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c jnc 00007FB83CBE53C2h 0x00000012 popad 0x00000013 pushad 0x00000014 jmp 00007FB83CBE53C9h 0x00000019 push eax 0x0000001a push edx 0x0000001b jmp 00007FB83CBE53C1h 0x00000020 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C1B7E second address: 5C1B82 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C1B82 second address: 5C1B88 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C2C10 second address: 5C2C95 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FB83CF3EE59h 0x00000009 popad 0x0000000a mov dword ptr [esp], eax 0x0000000d jl 00007FB83CF3EE57h 0x00000013 js 00007FB83CF3EE51h 0x00000019 call 00007FB83CF3EE4Ah 0x0000001e pop esi 0x0000001f push 00000000h 0x00000021 movsx esi, cx 0x00000024 push 00000000h 0x00000026 push 00000000h 0x00000028 push esi 0x00000029 call 00007FB83CF3EE48h 0x0000002e pop esi 0x0000002f mov dword ptr [esp+04h], esi 0x00000033 add dword ptr [esp+04h], 0000001Dh 0x0000003b inc esi 0x0000003c push esi 0x0000003d ret 0x0000003e pop esi 0x0000003f ret 0x00000040 adc si, A35Fh 0x00000045 xchg eax, ebx 0x00000046 push ebx 0x00000047 jns 00007FB83CF3EE48h 0x0000004d pushad 0x0000004e popad 0x0000004f pop ebx 0x00000050 push eax 0x00000051 push eax 0x00000052 push edx 0x00000053 jmp 00007FB83CF3EE4Eh 0x00000058 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C3E1E second address: 5C3E22 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C48FE second address: 5C4902 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C3E22 second address: 5C3E28 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C5BE7 second address: 5C5BF6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FB83CF3EE4Bh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C4902 second address: 5C490C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C3E28 second address: 5C3E32 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jng 00007FB83CF3EE46h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C5BF6 second address: 5C5BFA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C5BFA second address: 5C5C20 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jg 00007FB83CF3EE60h 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C5C20 second address: 5C5C2A instructions: 0x00000000 rdtsc 0x00000002 js 00007FB83CBE53C2h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C5C2A second address: 5C5C30 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 57E759 second address: 57E774 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 push edx 0x00000008 jmp 00007FB83CBE53C1h 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C6277 second address: 5C627B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C6D13 second address: 5C6D19 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C7997 second address: 5C799C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C799C second address: 5C79A9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 pop edx 0x00000006 pop eax 0x00000007 push eax 0x00000008 pushad 0x00000009 push eax 0x0000000a push edx 0x0000000b push edi 0x0000000c pop edi 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C79A9 second address: 5C79B6 instructions: 0x00000000 rdtsc 0x00000002 jg 00007FB83CF3EE46h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pushad 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C79B6 second address: 5C79BC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C817B second address: 5C8184 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5CBDFB second address: 5CBE81 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C4h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop esi 0x0000000a nop 0x0000000b push 00000000h 0x0000000d push edi 0x0000000e call 00007FB83CBE53B8h 0x00000013 pop edi 0x00000014 mov dword ptr [esp+04h], edi 0x00000018 add dword ptr [esp+04h], 0000001Dh 0x00000020 inc edi 0x00000021 push edi 0x00000022 ret 0x00000023 pop edi 0x00000024 ret 0x00000025 mov ebx, dword ptr [ebp+1246A083h] 0x0000002b push 00000000h 0x0000002d add dword ptr [ebp+122D1E09h], edi 0x00000033 push 00000000h 0x00000035 push 00000000h 0x00000037 push eax 0x00000038 call 00007FB83CBE53B8h 0x0000003d pop eax 0x0000003e mov dword ptr [esp+04h], eax 0x00000042 add dword ptr [esp+04h], 0000001Ch 0x0000004a inc eax 0x0000004b push eax 0x0000004c ret 0x0000004d pop eax 0x0000004e ret 0x0000004f push eax 0x00000050 push eax 0x00000051 push edx 0x00000052 pushad 0x00000053 jmp 00007FB83CBE53BCh 0x00000058 push ecx 0x00000059 pop ecx 0x0000005a popad 0x0000005b rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5CDF80 second address: 5CDFF6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 mov dword ptr [esp], eax 0x00000009 call 00007FB83CF3EE56h 0x0000000e pop ebx 0x0000000f push 00000000h 0x00000011 push 00000000h 0x00000013 push eax 0x00000014 call 00007FB83CF3EE48h 0x00000019 pop eax 0x0000001a mov dword ptr [esp+04h], eax 0x0000001e add dword ptr [esp+04h], 0000001Dh 0x00000026 inc eax 0x00000027 push eax 0x00000028 ret 0x00000029 pop eax 0x0000002a ret 0x0000002b add dword ptr [ebp+1246A048h], ebx 0x00000031 push 00000000h 0x00000033 mov edi, 3D893900h 0x00000038 and ebx, 54301FCEh 0x0000003e xchg eax, esi 0x0000003f js 00007FB83CF3EE4Ah 0x00000045 push edx 0x00000046 push eax 0x00000047 pop eax 0x00000048 pop edx 0x00000049 push eax 0x0000004a push eax 0x0000004b push edx 0x0000004c jmp 00007FB83CF3EE4Eh 0x00000051 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5CD13A second address: 5CD155 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FB83CBE53C7h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5CF168 second address: 5CF16C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D0F5E second address: 5D0F64 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D0F64 second address: 5D0F6E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jnc 00007FB83CF3EE46h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D0F6E second address: 5D0F72 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D2F64 second address: 5D2F6E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jp 00007FB83CF3EE46h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D76D3 second address: 5D76DD instructions: 0x00000000 rdtsc 0x00000002 jp 00007FB83CBE53B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D6632 second address: 5D6636 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D851D second address: 5D8530 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pushad 0x00000004 popad 0x00000005 pop ebx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push eax 0x0000000a push edx 0x0000000b jng 00007FB83CBE53BCh 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D559E second address: 5D55A2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D95D8 second address: 5D95DC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D76DD second address: 5D770A instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE50h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d jmp 00007FB83CF3EE54h 0x00000012 pop eax 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5DA4CA second address: 5DA4CE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D6636 second address: 5D663B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D8530 second address: 5D8534 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D95DC second address: 5D95E2 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D770A second address: 5D7710 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5DA4CE second address: 5DA4D2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D663B second address: 5D6649 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a pushad 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D7710 second address: 5D7714 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D85D2 second address: 5D85D7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5D85D7 second address: 5D85DD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5DB604 second address: 5DB608 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5DB608 second address: 5DB657 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 mov dword ptr [esp], eax 0x0000000a add ebx, 03308B9Eh 0x00000010 push 00000000h 0x00000012 pushad 0x00000013 mov edx, eax 0x00000015 sbb edx, 21F48DABh 0x0000001b popad 0x0000001c push 00000000h 0x0000001e push 00000000h 0x00000020 push edi 0x00000021 call 00007FB83CF3EE48h 0x00000026 pop edi 0x00000027 mov dword ptr [esp+04h], edi 0x0000002b add dword ptr [esp+04h], 0000001Ch 0x00000033 inc edi 0x00000034 push edi 0x00000035 ret 0x00000036 pop edi 0x00000037 ret 0x00000038 mov edi, dword ptr [ebp+122D38A8h] 0x0000003e xchg eax, esi 0x0000003f push edi 0x00000040 pushad 0x00000041 pushad 0x00000042 popad 0x00000043 push eax 0x00000044 push edx 0x00000045 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5DA778 second address: 5DA782 instructions: 0x00000000 rdtsc 0x00000002 jnc 00007FB83CBE53B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5DB7CA second address: 5DB7CE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5DB7CE second address: 5DB872 instructions: 0x00000000 rdtsc 0x00000002 ja 00007FB83CBE53B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push edx 0x0000000b pushad 0x0000000c popad 0x0000000d pop edx 0x0000000e popad 0x0000000f mov dword ptr [esp], eax 0x00000012 mov di, si 0x00000015 push dword ptr fs:[00000000h] 0x0000001c or dword ptr [ebp+122D1AA8h], edx 0x00000022 mov dword ptr fs:[00000000h], esp 0x00000029 push 00000000h 0x0000002b push edi 0x0000002c call 00007FB83CBE53B8h 0x00000031 pop edi 0x00000032 mov dword ptr [esp+04h], edi 0x00000036 add dword ptr [esp+04h], 00000019h 0x0000003e inc edi 0x0000003f push edi 0x00000040 ret 0x00000041 pop edi 0x00000042 ret 0x00000043 cld 0x00000044 mov eax, dword ptr [ebp+122D0E5Dh] 0x0000004a push 00000000h 0x0000004c push edx 0x0000004d call 00007FB83CBE53B8h 0x00000052 pop edx 0x00000053 mov dword ptr [esp+04h], edx 0x00000057 add dword ptr [esp+04h], 00000018h 0x0000005f inc edx 0x00000060 push edx 0x00000061 ret 0x00000062 pop edx 0x00000063 ret 0x00000064 add dword ptr [ebp+122D2126h], ebx 0x0000006a push FFFFFFFFh 0x0000006c jmp 00007FB83CBE53C5h 0x00000071 push eax 0x00000072 pushad 0x00000073 push eax 0x00000074 push edx 0x00000075 jmp 00007FB83CBE53C2h 0x0000007a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5E1576 second address: 5E1589 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FB83CF3EE4Eh 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5E800A second address: 5E8036 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C5h 0x00000007 jmp 00007FB83CBE53C3h 0x0000000c pop edx 0x0000000d pop eax 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5E8036 second address: 5E8043 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 jnp 00007FB83CF3EE46h 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5E8043 second address: 5E8049 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5E8049 second address: 5E806D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 pushad 0x00000008 pushad 0x00000009 push edx 0x0000000a pop edx 0x0000000b jmp 00007FB83CF3EE52h 0x00000010 pushad 0x00000011 popad 0x00000012 popad 0x00000013 push eax 0x00000014 push edx 0x00000015 push edx 0x00000016 pop edx 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5E7738 second address: 5E774C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FB83CBE53C0h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5E774C second address: 5E775B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FB83CF3EE4Bh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5E775B second address: 5E7767 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push edx 0x0000000b pop edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5E78E7 second address: 5E78FB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 pushad 0x00000006 push esi 0x00000007 pop esi 0x00000008 jnc 00007FB83CF3EE46h 0x0000000e popad 0x0000000f push ecx 0x00000010 push ecx 0x00000011 pop ecx 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5EC86C second address: 5EC88A instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53BEh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a push eax 0x0000000b push eax 0x0000000c push edx 0x0000000d jbe 00007FB83CBE53B8h 0x00000013 pushad 0x00000014 popad 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5ECB1B second address: 5ECB20 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 57CC42 second address: 57CC4D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jl 00007FB83CBE53B6h 0x0000000a pop edi 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 57CC4D second address: 57CC53 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 57CC53 second address: 57CC71 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C2h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b jp 00007FB83CBE53B6h 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 57CC71 second address: 57CC75 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5F1A7D second address: 5F1A81 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5F1A81 second address: 5F1A85 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5F1A85 second address: 5F1A9B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 pushad 0x00000008 popad 0x00000009 push esi 0x0000000a pop esi 0x0000000b jg 00007FB83CBE53B6h 0x00000011 popad 0x00000012 push eax 0x00000013 push edx 0x00000014 push edi 0x00000015 pop edi 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5F1A9B second address: 5F1AA5 instructions: 0x00000000 rdtsc 0x00000002 js 00007FB83CF3EE46h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5F206C second address: 5F2089 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FB83CBE53C4h 0x00000009 popad 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5F2089 second address: 5F2093 instructions: 0x00000000 rdtsc 0x00000002 ja 00007FB83CF3EE46h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5F21BE second address: 5F21EF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 js 00007FB83CBE53C6h 0x0000000d jne 00007FB83CBE53B6h 0x00000013 jmp 00007FB83CBE53BAh 0x00000018 je 00007FB83CBE53BAh 0x0000001e popad 0x0000001f push ebx 0x00000020 jnp 00007FB83CBE53BEh 0x00000026 push eax 0x00000027 push edx 0x00000028 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5F2B82 second address: 5F2B88 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5F2B88 second address: 5F2BA2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 push eax 0x00000006 push edx 0x00000007 push esi 0x00000008 pop esi 0x00000009 jmp 00007FB83CBE53C1h 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5F2BA2 second address: 5F2BCF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE58h 0x00000007 jmp 00007FB83CF3EE4Eh 0x0000000c pop edx 0x0000000d pop eax 0x0000000e pushad 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5F2BCF second address: 5F2BD5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5F75AC second address: 5F75CF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jmp 00007FB83CF3EE54h 0x0000000a push eax 0x0000000b push edx 0x0000000c push edx 0x0000000d pop edx 0x0000000e je 00007FB83CF3EE46h 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C8C21 second address: 5C8C5B instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jmp 00007FB83CBE53C5h 0x0000000e popad 0x0000000f push eax 0x00000010 push eax 0x00000011 push edx 0x00000012 push eax 0x00000013 push edx 0x00000014 pop edx 0x00000015 pop eax 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C8F42 second address: 5C8F48 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C8F48 second address: 5C8F4E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C8F4E second address: 5C8F52 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C91A2 second address: 5C91C1 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push ecx 0x00000008 pushad 0x00000009 jmp 00007FB83CBE53C4h 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C936B second address: 5C936F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C936F second address: 5C9380 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 push ebx 0x00000004 pop ebx 0x00000005 pop edx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov dword ptr [esp+04h], eax 0x0000000c pushad 0x0000000d push eax 0x0000000e push edx 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C9380 second address: 5C9384 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C95C2 second address: 5C95C6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C95C6 second address: 5C95CC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C9A22 second address: 5C9A27 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C9A27 second address: 5C9A46 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a pushad 0x0000000b pushad 0x0000000c jmp 00007FB83CF3EE51h 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C9A46 second address: 5C9A66 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 jmp 00007FB83CBE53C9h 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C9E0D second address: 5C9E1E instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push eax 0x00000008 push edx 0x00000009 push eax 0x0000000a push edx 0x0000000b jnp 00007FB83CF3EE46h 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C9E1E second address: 5C9E24 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5F6AC7 second address: 5F6ACD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5F6ACD second address: 5F6AD1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5FD1ED second address: 5FD1FA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jng 00007FB83CF3EE46h 0x00000009 push ecx 0x0000000a pop ecx 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5FBEE3 second address: 5FBEF2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 pushad 0x00000006 push esi 0x00000007 pop esi 0x00000008 pushad 0x00000009 popad 0x0000000a push eax 0x0000000b pop eax 0x0000000c push eax 0x0000000d pop eax 0x0000000e popad 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5FC082 second address: 5FC09D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FB83CF3EE57h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5FC09D second address: 5FC0AD instructions: 0x00000000 rdtsc 0x00000002 jp 00007FB83CBE53B6h 0x00000008 push ebx 0x00000009 pop ebx 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5FC1FF second address: 5FC209 instructions: 0x00000000 rdtsc 0x00000002 jne 00007FB83CF3EE46h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5FC209 second address: 5FC20F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5FC20F second address: 5FC215 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5FC36A second address: 5FC36E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5FC4A3 second address: 5FC4AE instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5FC4AE second address: 5FC4BF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jng 00007FB83CBE53B6h 0x0000000a jnc 00007FB83CBE53B6h 0x00000010 popad 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5FC642 second address: 5FC66C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jbe 00007FB83CF3EE46h 0x0000000a popad 0x0000000b jnl 00007FB83CF3EE5Fh 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5FC66C second address: 5FC68A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FB83CBE53BAh 0x00000008 pushad 0x00000009 popad 0x0000000a jo 00007FB83CBE53B6h 0x00000010 popad 0x00000011 jo 00007FB83CBE53BEh 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5FCBEC second address: 5FCBF2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5FCBF2 second address: 5FCC0C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C6h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 609C45 second address: 609C57 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FB83CF3EE4Eh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 609C57 second address: 609C89 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C4h 0x00000007 jl 00007FB83CBE53B6h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f push eax 0x00000010 push edx 0x00000011 ja 00007FB83CBE53C2h 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 608A4D second address: 608A5C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FB83CF3EE4Bh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 608A5C second address: 608A60 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 608C1A second address: 608C1F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 608F62 second address: 608F67 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 608F67 second address: 608F6D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 609379 second address: 60937E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 60937E second address: 6093B0 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push edx 0x00000004 pop edx 0x00000005 jmp 00007FB83CF3EE4Ch 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007FB83CF3EE58h 0x00000012 jp 00007FB83CF3EE46h 0x00000018 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 60969A second address: 60969F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 60969F second address: 6096C3 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE54h 0x00000007 push edx 0x00000008 jmp 00007FB83CF3EE4Bh 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 609939 second address: 60996F instructions: 0x00000000 rdtsc 0x00000002 jc 00007FB83CBE53BAh 0x00000008 pushad 0x00000009 popad 0x0000000a push ebx 0x0000000b pop ebx 0x0000000c pushad 0x0000000d jp 00007FB83CBE53B6h 0x00000013 jmp 00007FB83CBE53BDh 0x00000018 push ebx 0x00000019 pop ebx 0x0000001a popad 0x0000001b pop edx 0x0000001c pop eax 0x0000001d push ebx 0x0000001e jmp 00007FB83CBE53BBh 0x00000023 pushad 0x00000024 push edx 0x00000025 pop edx 0x00000026 push eax 0x00000027 push edx 0x00000028 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 60FFA0 second address: 60FFB0 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 jbe 00007FB83CF3EE46h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 60FFB0 second address: 60FFB4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 60FFB4 second address: 60FFBF instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 60FA1D second address: 60FA23 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 60FB77 second address: 60FB7B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 60FB7B second address: 60FB9E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push edx 0x00000008 pop edx 0x00000009 jmp 00007FB83CBE53C8h 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 616B04 second address: 616B23 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 pop eax 0x00000005 jmp 00007FB83CF3EE52h 0x0000000a jl 00007FB83CF3EE46h 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6156D6 second address: 6156DA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6156DA second address: 6156E6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 ja 00007FB83CF3EE46h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6156E6 second address: 6156F5 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 push edx 0x00000004 pop edx 0x00000005 js 00007FB83CBE53B6h 0x0000000b pop edx 0x0000000c push ecx 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C9831 second address: 5C9835 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C9835 second address: 5C9854 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ebx 0x00000007 push eax 0x00000008 jc 00007FB83CBE53D1h 0x0000000e push eax 0x0000000f push edx 0x00000010 jmp 00007FB83CBE53BFh 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C9854 second address: 5C9858 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C9858 second address: 5C9899 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 nop 0x00000007 mov edx, dword ptr [ebp+122D2E47h] 0x0000000d push 00000004h 0x0000000f push 00000000h 0x00000011 push eax 0x00000012 call 00007FB83CBE53B8h 0x00000017 pop eax 0x00000018 mov dword ptr [esp+04h], eax 0x0000001c add dword ptr [esp+04h], 00000015h 0x00000024 inc eax 0x00000025 push eax 0x00000026 ret 0x00000027 pop eax 0x00000028 ret 0x00000029 mov ecx, dword ptr [ebp+122D1F59h] 0x0000002f cld 0x00000030 nop 0x00000031 pushad 0x00000032 jp 00007FB83CBE53B8h 0x00000038 pushad 0x00000039 popad 0x0000003a push eax 0x0000003b push edx 0x0000003c push eax 0x0000003d push edx 0x0000003e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 5C9899 second address: 5C989D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 615C83 second address: 615C8A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 615C8A second address: 615CC2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FB83CF3EE53h 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 jmp 00007FB83CF3EE58h 0x00000015 push esi 0x00000016 pop esi 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 615CC2 second address: 615CC8 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6167EF second address: 616801 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 pop eax 0x00000007 pop ebx 0x00000008 jnp 00007FB83CF3EE4Eh 0x0000000e push eax 0x0000000f pop eax 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 61AC64 second address: 61AC71 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop ecx 0x00000007 push eax 0x00000008 push edx 0x00000009 push edi 0x0000000a pop edi 0x0000000b pushad 0x0000000c popad 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 61AC71 second address: 61AC7D instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pushad 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 61AC7D second address: 61AC83 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 61AF2A second address: 61AF38 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 pushad 0x00000007 popad 0x00000008 jns 00007FB83CF3EE46h 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 61AF38 second address: 61AF3C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 61B099 second address: 61B09D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 61B09D second address: 61B0A5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 61E538 second address: 61E543 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 61E543 second address: 61E547 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 61E547 second address: 61E54B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 61E54B second address: 61E566 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007FB83CBE53C0h 0x0000000b popad 0x0000000c push ecx 0x0000000d pushad 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 625D7E second address: 625D90 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE4Ch 0x00000007 push edx 0x00000008 pop edx 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 623F55 second address: 623F5B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 623F5B second address: 623F86 instructions: 0x00000000 rdtsc 0x00000002 jg 00007FB83CF3EE46h 0x00000008 jmp 00007FB83CF3EE52h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f jmp 00007FB83CF3EE4Bh 0x00000014 push eax 0x00000015 push edx 0x00000016 push edx 0x00000017 pop edx 0x00000018 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 623F86 second address: 623F8A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 623F8A second address: 623F90 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 623F90 second address: 623F9C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 pushad 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 623F9C second address: 623FA0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 623FA0 second address: 623FA4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 623FA4 second address: 623FC6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jns 00007FB83CF3EE57h 0x0000000c push ebx 0x0000000d push edi 0x0000000e pop edi 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 62475F second address: 62476E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 ja 00007FB83CBE53B6h 0x0000000c pushad 0x0000000d popad 0x0000000e popad 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 624C43 second address: 624C47 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 624C47 second address: 624C83 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FB83CBE53C4h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pushad 0x0000000c ja 00007FB83CBE53B6h 0x00000012 jne 00007FB83CBE53B6h 0x00000018 jmp 00007FB83CBE53C4h 0x0000001d popad 0x0000001e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 624C83 second address: 624C8E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jnl 00007FB83CF3EE46h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6257F9 second address: 6257FF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6257FF second address: 625805 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 625805 second address: 62580A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 62580A second address: 625849 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE52h 0x00000007 pushad 0x00000008 push eax 0x00000009 pop eax 0x0000000a pushad 0x0000000b popad 0x0000000c pushad 0x0000000d popad 0x0000000e popad 0x0000000f pop edx 0x00000010 pop eax 0x00000011 push ecx 0x00000012 jmp 00007FB83CF3EE4Ch 0x00000017 push eax 0x00000018 push edx 0x00000019 jmp 00007FB83CF3EE50h 0x0000001e pushad 0x0000001f popad 0x00000020 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 625849 second address: 62584D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 629EFD second address: 629F02 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 62A049 second address: 62A055 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnc 00007FB83CBE53B6h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 62A055 second address: 62A06F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 jmp 00007FB83CF3EE4Eh 0x0000000d push edi 0x0000000e push esi 0x0000000f pop esi 0x00000010 pop edi 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 62A58C second address: 62A5C2 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53BFh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c jg 00007FB83CBE53B8h 0x00000012 jmp 00007FB83CBE53C8h 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 62A5C2 second address: 62A5C7 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 62A787 second address: 62A79C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 ja 00007FB83CBE53B6h 0x00000009 pop eax 0x0000000a pushad 0x0000000b pushad 0x0000000c popad 0x0000000d jbe 00007FB83CBE53B6h 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 62A942 second address: 62A94E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jo 00007FB83CF3EE46h 0x0000000a push edi 0x0000000b pop edi 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 62AA74 second address: 62AA7A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 639066 second address: 639089 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE50h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push edx 0x0000000a pushad 0x0000000b popad 0x0000000c pop edx 0x0000000d popad 0x0000000e push eax 0x0000000f push edx 0x00000010 jnc 00007FB83CF3EE48h 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 639089 second address: 639091 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 639091 second address: 639095 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 637623 second address: 63764D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pushad 0x00000007 popad 0x00000008 popad 0x00000009 pushad 0x0000000a jmp 00007FB83CBE53BBh 0x0000000f jmp 00007FB83CBE53C2h 0x00000014 pushad 0x00000015 popad 0x00000016 popad 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 637795 second address: 6377A6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 pop edx 0x00000007 pushad 0x00000008 push edx 0x00000009 pop edx 0x0000000a js 00007FB83CF3EE46h 0x00000010 popad 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6377A6 second address: 6377C7 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 jmp 00007FB83CBE53C5h 0x00000008 pop ecx 0x00000009 jnc 00007FB83CBE53BCh 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6377C7 second address: 6377DC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 jmp 00007FB83CF3EE4Ah 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6377DC second address: 6377E0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6377E0 second address: 6377EC instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a pushad 0x0000000b popad 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6377EC second address: 6377F0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6377F0 second address: 637832 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FB83CF3EE56h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pushad 0x0000000c pushad 0x0000000d popad 0x0000000e jmp 00007FB83CF3EE54h 0x00000013 jng 00007FB83CF3EE46h 0x00000019 popad 0x0000001a push eax 0x0000001b push edx 0x0000001c je 00007FB83CF3EE46h 0x00000022 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 637832 second address: 637838 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 637969 second address: 63796D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 63796D second address: 637977 instructions: 0x00000000 rdtsc 0x00000002 jl 00007FB83CBE53B6h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 637ADE second address: 637B0E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 jnl 00007FB83CF3EE46h 0x0000000d pushad 0x0000000e popad 0x0000000f je 00007FB83CF3EE46h 0x00000015 jmp 00007FB83CF3EE52h 0x0000001a popad 0x0000001b push eax 0x0000001c push edx 0x0000001d push eax 0x0000001e push edx 0x0000001f push ecx 0x00000020 pop ecx 0x00000021 pushad 0x00000022 popad 0x00000023 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 637B0E second address: 637B12 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 637B12 second address: 637B20 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jnp 00007FB83CF3EE48h 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 637B20 second address: 637B36 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FB83CBE53C0h 0x00000009 pushad 0x0000000a popad 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6405C9 second address: 6405CD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6405CD second address: 6405DD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jl 00007FB83CBE53BEh 0x0000000c pushad 0x0000000d popad 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6401A0 second address: 6401AE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jng 00007FB83CF3EE46h 0x0000000a popad 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6401AE second address: 6401B4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 64DF1F second address: 64DF34 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 je 00007FB83CF3EE4Ch 0x0000000c jne 00007FB83CF3EE46h 0x00000012 push edx 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 653CDF second address: 653CE4 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 657A56 second address: 657A6A instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 jnl 00007FB83CF3EE46h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e jne 00007FB83CF3EE46h 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 657A6A second address: 657A6E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 657905 second address: 657920 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 jmp 00007FB83CF3EE53h 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 65CEEE second address: 65CEF2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 660F5C second address: 660F63 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 667AE3 second address: 667AF6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FB83CBE53BEh 0x00000009 popad 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 667AF6 second address: 667B01 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 pop eax 0x00000007 push ecx 0x00000008 pop ecx 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 66796E second address: 667974 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 667974 second address: 667987 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 push eax 0x00000006 push edx 0x00000007 jmp 00007FB83CF3EE4Ch 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 671B01 second address: 671B07 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 671B07 second address: 671B1B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push edi 0x00000005 pop edi 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c js 00007FB83CF3EE4Eh 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 671B1B second address: 671B21 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 671D8A second address: 671D92 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 672A19 second address: 672A1F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 672A1F second address: 672A29 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 672A29 second address: 672A2D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 676604 second address: 67661C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE54h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 67A5A0 second address: 67A5A4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 67A5A4 second address: 67A5AA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 67A5AA second address: 67A5B0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 67A5B0 second address: 67A5B6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 67A5B6 second address: 67A5C8 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a ja 00007FB83CBE53B6h 0x00000010 pushad 0x00000011 popad 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6901E7 second address: 6901EB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6901EB second address: 6901EF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 69039D second address: 6903A7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jbe 00007FB83CF3EE46h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6903A7 second address: 6903B3 instructions: 0x00000000 rdtsc 0x00000002 js 00007FB83CBE53B6h 0x00000008 pushad 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6903B3 second address: 6903BE instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 ja 00007FB83CF3EE46h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 697349 second address: 69734F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 69734F second address: 69735B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jo 00007FB83CF3EE46h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 69735B second address: 69736E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 pushad 0x00000007 popad 0x00000008 pushad 0x00000009 popad 0x0000000a push esi 0x0000000b pop esi 0x0000000c ja 00007FB83CBE53B6h 0x00000012 popad 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 69736E second address: 69737A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 js 00007FB83CF3EE46h 0x0000000a push eax 0x0000000b pop eax 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 69737A second address: 69739F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 jmp 00007FB83CBE53BFh 0x0000000d pop edx 0x0000000e pop eax 0x0000000f je 00007FB83CBE53CCh 0x00000015 push eax 0x00000016 push edx 0x00000017 push edx 0x00000018 pop edx 0x00000019 push edx 0x0000001a pop edx 0x0000001b rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 69739F second address: 6973A9 instructions: 0x00000000 rdtsc 0x00000002 jng 00007FB83CF3EE46h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 696421 second address: 69643B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jmp 00007FB83CBE53C5h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6966F2 second address: 6966F8 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 6966F8 second address: 696704 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a push edi 0x0000000b pop edi 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 696704 second address: 69671D instructions: 0x00000000 rdtsc 0x00000002 ja 00007FB83CF3EE46h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b jmp 00007FB83CF3EE4Ch 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 696B37 second address: 696B3B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 696DE1 second address: 696DEE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 jg 00007FB83CF3EE46h 0x0000000c popad 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 696DEE second address: 696DF4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edi 0x00000005 pop edi 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 696DF4 second address: 696DF8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 696DF8 second address: 696DFE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 69A1FC second address: 69A202 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 69A27E second address: 69A29F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 popad 0x00000007 jmp 00007FB83CBE53BFh 0x0000000c popad 0x0000000d push eax 0x0000000e jp 00007FB83CBE53BEh 0x00000014 push ecx 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 69A29F second address: 69A2EA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 nop 0x00000006 mov edx, dword ptr [ebp+122D1E02h] 0x0000000c add dx, 0153h 0x00000011 push 00000004h 0x00000013 push 00000000h 0x00000015 push ebp 0x00000016 call 00007FB83CF3EE48h 0x0000001b pop ebp 0x0000001c mov dword ptr [esp+04h], ebp 0x00000020 add dword ptr [esp+04h], 00000015h 0x00000028 inc ebp 0x00000029 push ebp 0x0000002a ret 0x0000002b pop ebp 0x0000002c ret 0x0000002d jng 00007FB83CF3EE4Ch 0x00000033 mov edx, dword ptr [ebp+122D1FD0h] 0x00000039 push 2E288CA5h 0x0000003e push eax 0x0000003f push edx 0x00000040 jnl 00007FB83CF3EE48h 0x00000046 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 69A2EA second address: 69A2F0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 69B7DF second address: 69B7E9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 pop edx 0x00000007 pushad 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 69D772 second address: 69D776 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 69D776 second address: 69D77C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 69F462 second address: 69F476 instructions: 0x00000000 rdtsc 0x00000002 jl 00007FB83CBE53B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d popad 0x0000000e jbe 00007FB83CBE53B6h 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 69F476 second address: 69F480 instructions: 0x00000000 rdtsc 0x00000002 ja 00007FB83CF3EE46h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 69F480 second address: 69F486 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 402CE0 second address: 402CE0 instructions: 0x00000000 rdtsc 0x00000002 push ebp 0x00000003 mov ebp, esp 0x00000005 push ebx 0x00000006 push edi 0x00000007 push esi 0x00000008 imul eax, eax, 001E7319h 0x0000000e add eax, 3CFB5543h 0x00000013 rcr eax, 10h 0x00000016 add eax, esi 0x00000018 imul eax, edi 0x0000001b xor edx, edx 0x0000001d mul dword ptr [ebp+08h] 0x00000020 mov eax, edx 0x00000022 pop esi 0x00000023 pop edi 0x00000024 pop ebx 0x00000025 leave 0x00000026 retn 0004h 0x00000029 lea eax, dword ptr [eax+00000300h] 0x0000002f push eax 0x00000030 push 00405BFCh 0x00000035 call 00007FB83CF40815h 0x0000003a push ebp 0x0000003b mov ebp, esp 0x0000003d push ebx 0x0000003e push edi 0x0000003f push esi 0x00000040 mov edi, dword ptr [ebp+08h] 0x00000043 push 000000FFh 0x00000048 call 00007FB83CF3F11Eh 0x0000004d rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49306DE second address: 49306E4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49306E4 second address: 49306E8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 493073F second address: 493075B instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C8h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 493075B second address: 4930761 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4930818 second address: 493081E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4930761 second address: 4930765 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 493081E second address: 4930822 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4930765 second address: 49307CD instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE4Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b xchg eax, ebp 0x0000000c jmp 00007FB83CF3EE4Eh 0x00000011 mov ebp, esp 0x00000013 pushad 0x00000014 mov bh, cl 0x00000016 movsx edi, ax 0x00000019 popad 0x0000001a pop ebp 0x0000001b pushad 0x0000001c pushfd 0x0000001d jmp 00007FB83CF3EE50h 0x00000022 xor cx, A778h 0x00000027 jmp 00007FB83CF3EE4Bh 0x0000002c popfd 0x0000002d push eax 0x0000002e push edx 0x0000002f call 00007FB83CF3EE56h 0x00000034 pop eax 0x00000035 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4930822 second address: 493088C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C3h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b xchg eax, ebp 0x0000000c jmp 00007FB83CBE53C6h 0x00000011 mov ebp, esp 0x00000013 pushad 0x00000014 mov si, 887Dh 0x00000018 pushfd 0x00000019 jmp 00007FB83CBE53BAh 0x0000001e add cl, 00000058h 0x00000021 jmp 00007FB83CBE53BBh 0x00000026 popfd 0x00000027 popad 0x00000028 pop ebp 0x00000029 push eax 0x0000002a push edx 0x0000002b jmp 00007FB83CBE53C5h 0x00000030 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49307CD second address: 491052B instructions: 0x00000000 rdtsc 0x00000002 mov ecx, edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 jmp dword ptr [759811CCh] 0x0000000d mov edi, edi 0x0000000f push ebp 0x00000010 mov ebp, esp 0x00000012 mov eax, dword ptr [ebp+08h] 0x00000015 sub esp, 1Ch 0x00000018 test eax, eax 0x0000001a je 00007FB83CF3EEDEh 0x00000020 mov eax, dword ptr fs:[00000030h] 0x00000026 mov eax, dword ptr [eax+08h] 0x00000029 mov esp, ebp 0x0000002b pop ebp 0x0000002c retn 0004h 0x0000002f mov dword ptr [ebp-04h], eax 0x00000032 mov dword ptr [ebp-48h], 00000000h 0x00000039 mov eax, dword ptr [ebp+08h] 0x0000003c mov dword ptr [ebp-44h], eax 0x0000003f mov dword ptr [ebp-40h], 00000000h 0x00000046 mov dword ptr [ebp-3Ch], 00000000h 0x0000004d mov eax, dword ptr [ebp-04h] 0x00000050 mov dword ptr [ebp-38h], eax 0x00000053 mov dword ptr [ebp-28h], 00000000h 0x0000005a lea eax, dword ptr [ebp-0000024Ch] 0x00000060 mov dword ptr [ebp-24h], eax 0x00000063 push 00007F04h 0x00000068 push 00000000h 0x0000006a call 00007FB83CF40A07h 0x0000006f jmp 00007FB84144C226h 0x00000074 mov edi, edi 0x00000076 push eax 0x00000077 push edx 0x00000078 jmp 00007FB83CF3EE57h 0x0000007d rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491052B second address: 491053F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FB83CBE53BFh 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491053F second address: 49105B5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 xchg eax, ebp 0x00000008 pushad 0x00000009 call 00007FB83CF3EE52h 0x0000000e pushfd 0x0000000f jmp 00007FB83CF3EE52h 0x00000014 sub esi, 62F16218h 0x0000001a jmp 00007FB83CF3EE4Bh 0x0000001f popfd 0x00000020 pop ecx 0x00000021 push edi 0x00000022 pushad 0x00000023 popad 0x00000024 pop eax 0x00000025 popad 0x00000026 push eax 0x00000027 push eax 0x00000028 push edx 0x00000029 pushad 0x0000002a pushfd 0x0000002b jmp 00007FB83CF3EE4Dh 0x00000030 adc ecx, 25BF23B6h 0x00000036 jmp 00007FB83CF3EE51h 0x0000003b popfd 0x0000003c mov ecx, 230A5DA7h 0x00000041 popad 0x00000042 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49105B5 second address: 49105BB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49105BB second address: 49105D4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 xchg eax, ebp 0x00000009 push eax 0x0000000a push edx 0x0000000b jmp 00007FB83CF3EE4Eh 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49105D4 second address: 49105F9 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53BBh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov ebp, esp 0x0000000b push eax 0x0000000c push edx 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FB83CBE53C0h 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49105F9 second address: 49105FF instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49105FF second address: 4910605 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910605 second address: 4910609 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910609 second address: 491060D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491060D second address: 4910636 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 xchg eax, ecx 0x00000009 jmp 00007FB83CF3EE54h 0x0000000e push eax 0x0000000f push eax 0x00000010 push edx 0x00000011 pushad 0x00000012 mov esi, 593F90E3h 0x00000017 mov ebx, eax 0x00000019 popad 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910636 second address: 491066C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C5h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, ecx 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FB83CBE53C8h 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491066C second address: 4910672 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910672 second address: 4910706 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53BEh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, edi 0x0000000a pushad 0x0000000b pushad 0x0000000c jmp 00007FB83CBE53BCh 0x00000011 pushfd 0x00000012 jmp 00007FB83CBE53C2h 0x00000017 xor ax, F518h 0x0000001c jmp 00007FB83CBE53BBh 0x00000021 popfd 0x00000022 popad 0x00000023 mov esi, 1ABF64CFh 0x00000028 popad 0x00000029 push eax 0x0000002a jmp 00007FB83CBE53C5h 0x0000002f xchg eax, edi 0x00000030 pushad 0x00000031 mov ebx, eax 0x00000033 mov ah, 76h 0x00000035 popad 0x00000036 mov edi, 00000000h 0x0000003b pushad 0x0000003c push eax 0x0000003d push edx 0x0000003e pushfd 0x0000003f jmp 00007FB83CBE53BCh 0x00000044 jmp 00007FB83CBE53C5h 0x00000049 popfd 0x0000004a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910706 second address: 491072B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 call 00007FB83CF3EE4Ch 0x0000000b pop eax 0x0000000c popad 0x0000000d test dword ptr [ebp+0Ch], FFFF0000h 0x00000014 push eax 0x00000015 push edx 0x00000016 pushad 0x00000017 movzx esi, bx 0x0000001a mov si, bx 0x0000001d popad 0x0000001e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491072B second address: 4910772 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FB83CBE53BAh 0x00000009 xor eax, 5853BE98h 0x0000000f jmp 00007FB83CBE53BBh 0x00000014 popfd 0x00000015 call 00007FB83CBE53C8h 0x0000001a pop ecx 0x0000001b popad 0x0000001c pop edx 0x0000001d pop eax 0x0000001e jne 00007FB8ADD743C2h 0x00000024 pushad 0x00000025 push eax 0x00000026 push edx 0x00000027 mov eax, edx 0x00000029 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910772 second address: 49107CC instructions: 0x00000000 rdtsc 0x00000002 movsx edx, cx 0x00000005 pop edx 0x00000006 pop eax 0x00000007 call 00007FB83CF3EE52h 0x0000000c pushfd 0x0000000d jmp 00007FB83CF3EE52h 0x00000012 adc eax, 664CB288h 0x00000018 jmp 00007FB83CF3EE4Bh 0x0000001d popfd 0x0000001e pop eax 0x0000001f popad 0x00000020 mov edx, dword ptr [ebp+0Ch] 0x00000023 jmp 00007FB83CF3EE4Fh 0x00000028 mov ecx, dword ptr [ebp+08h] 0x0000002b pushad 0x0000002c push eax 0x0000002d push edx 0x0000002e mov edi, ecx 0x00000030 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49107CC second address: 4910840 instructions: 0x00000000 rdtsc 0x00000002 mov cx, D23Dh 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 mov ax, 54DFh 0x0000000d pushfd 0x0000000e jmp 00007FB83CBE53C4h 0x00000013 sbb eax, 24BC2748h 0x00000019 jmp 00007FB83CBE53BBh 0x0000001e popfd 0x0000001f popad 0x00000020 popad 0x00000021 call 00007FB83CBE53B9h 0x00000026 jmp 00007FB83CBE53C6h 0x0000002b push eax 0x0000002c jmp 00007FB83CBE53BBh 0x00000031 mov eax, dword ptr [esp+04h] 0x00000035 push eax 0x00000036 push edx 0x00000037 push eax 0x00000038 push edx 0x00000039 jmp 00007FB83CBE53BBh 0x0000003e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910840 second address: 4910844 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910844 second address: 491084A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491084A second address: 4910887 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE54h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov eax, dword ptr [eax] 0x0000000b pushad 0x0000000c call 00007FB83CF3EE51h 0x00000011 movzx ecx, dx 0x00000014 pop edx 0x00000015 mov edx, esi 0x00000017 popad 0x00000018 mov dword ptr [esp+04h], eax 0x0000001c push eax 0x0000001d push edx 0x0000001e push eax 0x0000001f push edx 0x00000020 pushad 0x00000021 popad 0x00000022 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910887 second address: 491088D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491088D second address: 49108E8 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE53h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop eax 0x0000000a jmp 00007FB83CF3EE56h 0x0000000f xchg eax, edi 0x00000010 push eax 0x00000011 push edx 0x00000012 pushad 0x00000013 pushfd 0x00000014 jmp 00007FB83CF3EE4Dh 0x00000019 sbb ecx, 48017096h 0x0000001f jmp 00007FB83CF3EE51h 0x00000024 popfd 0x00000025 push ecx 0x00000026 pop edx 0x00000027 popad 0x00000028 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49108E8 second address: 49108EE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49108EE second address: 4910933 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE4Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c jmp 00007FB83CF3EE59h 0x00000011 xchg eax, edi 0x00000012 jmp 00007FB83CF3EE4Eh 0x00000017 xchg eax, edi 0x00000018 push eax 0x00000019 push edx 0x0000001a push eax 0x0000001b push edx 0x0000001c push eax 0x0000001d push edx 0x0000001e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910933 second address: 4910937 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910937 second address: 491093B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491093B second address: 4910941 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49109BF second address: 49109C5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49109C5 second address: 49109C9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49109C9 second address: 4910A03 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE4Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pop edi 0x0000000c pushad 0x0000000d push eax 0x0000000e push edx 0x0000000f pushfd 0x00000010 jmp 00007FB83CF3EE52h 0x00000015 add ecx, 6E6BA628h 0x0000001b jmp 00007FB83CF3EE4Bh 0x00000020 popfd 0x00000021 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910A03 second address: 4910AC0 instructions: 0x00000000 rdtsc 0x00000002 pushfd 0x00000003 jmp 00007FB83CBE53C8h 0x00000008 or ax, 5888h 0x0000000d jmp 00007FB83CBE53BBh 0x00000012 popfd 0x00000013 pop edx 0x00000014 pop eax 0x00000015 pushfd 0x00000016 jmp 00007FB83CBE53C8h 0x0000001b sbb cx, BAE8h 0x00000020 jmp 00007FB83CBE53BBh 0x00000025 popfd 0x00000026 popad 0x00000027 leave 0x00000028 pushad 0x00000029 mov si, 5DFBh 0x0000002d mov cx, DED7h 0x00000031 popad 0x00000032 retn 0008h 0x00000035 mov dword ptr [ebp-34h], eax 0x00000038 push 00007F01h 0x0000003d push 00000000h 0x0000003f call 00007FB83CBE6F62h 0x00000044 jmp 00007FB8410F2CF6h 0x00000049 mov edi, edi 0x0000004b pushad 0x0000004c pushfd 0x0000004d jmp 00007FB83CBE53C8h 0x00000052 sub ecx, 13C01878h 0x00000058 jmp 00007FB83CBE53BBh 0x0000005d popfd 0x0000005e jmp 00007FB83CBE53C8h 0x00000063 popad 0x00000064 xchg eax, ebp 0x00000065 push eax 0x00000066 push edx 0x00000067 push eax 0x00000068 push edx 0x00000069 jmp 00007FB83CBE53BAh 0x0000006e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910AC0 second address: 4910AC4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910AC4 second address: 4910ACA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910ACA second address: 4910ADB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FB83CF3EE4Dh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910ADB second address: 4910AF9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push eax 0x0000000a push edx 0x0000000b jmp 00007FB83CBE53C3h 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910AF9 second address: 4910AFF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910AFF second address: 4910B36 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 xchg eax, ebp 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c pushfd 0x0000000d jmp 00007FB83CBE53C8h 0x00000012 or cl, FFFFFFF8h 0x00000015 jmp 00007FB83CBE53BBh 0x0000001a popfd 0x0000001b pushad 0x0000001c popad 0x0000001d popad 0x0000001e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910B36 second address: 4910B99 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE4Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov ebp, esp 0x0000000b jmp 00007FB83CF3EE56h 0x00000010 xchg eax, ecx 0x00000011 pushad 0x00000012 pushfd 0x00000013 jmp 00007FB83CF3EE4Eh 0x00000018 add ax, 06B8h 0x0000001d jmp 00007FB83CF3EE4Bh 0x00000022 popfd 0x00000023 mov edi, esi 0x00000025 popad 0x00000026 push eax 0x00000027 push eax 0x00000028 push edx 0x00000029 jmp 00007FB83CF3EE50h 0x0000002e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910B99 second address: 4910BC5 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FB83CBE53C1h 0x00000008 pushad 0x00000009 popad 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d xchg eax, ecx 0x0000000e jmp 00007FB83CBE53BCh 0x00000013 xchg eax, edi 0x00000014 pushad 0x00000015 push eax 0x00000016 push edx 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910BC5 second address: 4910BC9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910BC9 second address: 4910C1F instructions: 0x00000000 rdtsc 0x00000002 mov dx, ax 0x00000005 pop edx 0x00000006 pop eax 0x00000007 mov edx, eax 0x00000009 popad 0x0000000a push eax 0x0000000b jmp 00007FB83CBE53BBh 0x00000010 xchg eax, edi 0x00000011 jmp 00007FB83CBE53C6h 0x00000016 sub edi, edi 0x00000018 jmp 00007FB83CBE53C1h 0x0000001d test dword ptr [ebp+0Ch], FFFF0000h 0x00000024 push eax 0x00000025 push edx 0x00000026 jmp 00007FB83CBE53BDh 0x0000002b rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910C1F second address: 4910C43 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 jne 00007FB8AE0D4E3Fh 0x0000000e pushad 0x0000000f mov ebx, 7FDDDED6h 0x00000014 popad 0x00000015 mov edx, dword ptr [ebp+0Ch] 0x00000018 push eax 0x00000019 push edx 0x0000001a pushad 0x0000001b mov ecx, 296284E5h 0x00000020 movzx eax, bx 0x00000023 popad 0x00000024 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910C43 second address: 4910C49 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910C49 second address: 4910C4D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910C4D second address: 4910C78 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov ecx, dword ptr [ebp+08h] 0x0000000b jmp 00007FB83CBE53C2h 0x00000010 push 07C3EA0Bh 0x00000015 push eax 0x00000016 push edx 0x00000017 pushad 0x00000018 push eax 0x00000019 pop edi 0x0000001a mov bx, ax 0x0000001d popad 0x0000001e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910C78 second address: 4910CD2 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE4Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xor dword ptr [esp], 07C36A4Bh 0x00000010 pushad 0x00000011 mov bh, ch 0x00000013 push edx 0x00000014 pushfd 0x00000015 jmp 00007FB83CF3EE4Ch 0x0000001a jmp 00007FB83CF3EE55h 0x0000001f popfd 0x00000020 pop eax 0x00000021 popad 0x00000022 push ebp 0x00000023 push eax 0x00000024 push edx 0x00000025 push eax 0x00000026 push edx 0x00000027 jmp 00007FB83CF3EE56h 0x0000002c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910CD2 second address: 4910CD6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910CD6 second address: 4910CDC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910CDC second address: 4910D19 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FB83CBE53BCh 0x00000009 and esi, 22C43E78h 0x0000000f jmp 00007FB83CBE53BBh 0x00000014 popfd 0x00000015 mov ecx, 17D101AFh 0x0000001a popad 0x0000001b pop edx 0x0000001c pop eax 0x0000001d mov dword ptr [esp], edi 0x00000020 push eax 0x00000021 push edx 0x00000022 push eax 0x00000023 push edx 0x00000024 jmp 00007FB83CBE53BCh 0x00000029 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910D19 second address: 4910D1F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910008 second address: 491000C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491000C second address: 4910010 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910010 second address: 4910016 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910016 second address: 491001C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491001C second address: 4910020 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910020 second address: 491003A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 xchg eax, ebp 0x00000009 push eax 0x0000000a push edx 0x0000000b jmp 00007FB83CF3EE4Fh 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491003A second address: 491006F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a jmp 00007FB83CBE53C1h 0x0000000f xchg eax, ebp 0x00000010 push eax 0x00000011 push edx 0x00000012 pushad 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491006F second address: 4910076 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 mov dh, FAh 0x00000006 popad 0x00000007 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910076 second address: 49100ED instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53BBh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov ebp, esp 0x0000000b pushad 0x0000000c movzx eax, di 0x0000000f call 00007FB83CBE53C1h 0x00000014 mov di, cx 0x00000017 pop ecx 0x00000018 popad 0x00000019 and esp, FFFFFFF8h 0x0000001c pushad 0x0000001d push ebx 0x0000001e pushfd 0x0000001f jmp 00007FB83CBE53C4h 0x00000024 adc si, 1618h 0x00000029 jmp 00007FB83CBE53BBh 0x0000002e popfd 0x0000002f pop esi 0x00000030 movsx edx, si 0x00000033 popad 0x00000034 sub esp, 30h 0x00000037 push eax 0x00000038 push edx 0x00000039 jmp 00007FB83CBE53C7h 0x0000003e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49100ED second address: 49100F3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49100F3 second address: 49100F7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49100F7 second address: 491018A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov eax, dword ptr [ebp+08h] 0x0000000b jmp 00007FB83CF3EE57h 0x00000010 sub edx, edx 0x00000012 pushad 0x00000013 pushad 0x00000014 mov bh, 63h 0x00000016 call 00007FB83CF3EE4Ch 0x0000001b pop ecx 0x0000001c popad 0x0000001d mov dh, 4Ah 0x0000001f popad 0x00000020 xchg eax, esi 0x00000021 pushad 0x00000022 call 00007FB83CF3EE58h 0x00000027 movzx esi, di 0x0000002a pop ebx 0x0000002b jmp 00007FB83CF3EE4Ch 0x00000030 popad 0x00000031 push eax 0x00000032 pushad 0x00000033 pushad 0x00000034 pushad 0x00000035 popad 0x00000036 popad 0x00000037 mov di, 690Ch 0x0000003b popad 0x0000003c xchg eax, esi 0x0000003d pushad 0x0000003e movsx edi, ax 0x00000041 mov ebx, ecx 0x00000043 popad 0x00000044 xchg eax, edi 0x00000045 jmp 00007FB83CF3EE54h 0x0000004a push eax 0x0000004b push eax 0x0000004c push edx 0x0000004d push eax 0x0000004e push edx 0x0000004f pushad 0x00000050 popad 0x00000051 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491018A second address: 49101A6 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C8h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49101A6 second address: 49101B8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FB83CF3EE4Eh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49101B8 second address: 49101EC instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53BBh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b xchg eax, edi 0x0000000c jmp 00007FB83CBE53C6h 0x00000011 push 00000009h 0x00000013 push eax 0x00000014 push edx 0x00000015 pushad 0x00000016 mov ecx, edi 0x00000018 mov bx, 5A8Ch 0x0000001c popad 0x0000001d rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49101EC second address: 49101F2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49101F2 second address: 4910231 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pop ecx 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c pushfd 0x0000000d jmp 00007FB83CBE53C5h 0x00000012 sbb cx, D416h 0x00000017 jmp 00007FB83CBE53C1h 0x0000001c popfd 0x0000001d mov ecx, 1A1FAE87h 0x00000022 popad 0x00000023 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910231 second address: 491024B instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE4Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 lea esi, dword ptr [eax+04h] 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491024B second address: 491024F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491024F second address: 4910262 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE4Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910262 second address: 491027A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FB83CBE53C4h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491027A second address: 4910293 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE4Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov eax, dword ptr [eax] 0x0000000d pushad 0x0000000e push eax 0x0000000f push edx 0x00000010 movzx eax, bx 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910293 second address: 49102E1 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C7h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pushad 0x0000000a pushfd 0x0000000b jmp 00007FB83CBE53C6h 0x00000010 xor ch, FFFFFF88h 0x00000013 jmp 00007FB83CBE53BBh 0x00000018 popfd 0x00000019 mov ebx, esi 0x0000001b popad 0x0000001c popad 0x0000001d push 00000001h 0x0000001f push eax 0x00000020 push edx 0x00000021 pushad 0x00000022 mov dh, cl 0x00000024 popad 0x00000025 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49102E1 second address: 49102E7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49102E7 second address: 49102EB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49102EB second address: 49103AC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 lea edi, dword ptr [esp+14h] 0x0000000c jmp 00007FB83CF3EE4Ah 0x00000011 rep movsd 0x00000013 rep movsd 0x00000015 rep movsd 0x00000017 rep movsd 0x00000019 rep movsd 0x0000001b rep movsd 0x0000001d rep movsd 0x0000001f rep movsd 0x00000021 rep movsd 0x00000023 jmp 00007FB83CF3EE50h 0x00000028 and dword ptr [esp+38h], 00000000h 0x0000002d jmp 00007FB83CF3EE50h 0x00000032 lea ecx, dword ptr [esp+0Ch] 0x00000036 jmp 00007FB83CF3EE50h 0x0000003b push 68D4114Bh 0x00000040 jmp 00007FB83CF3EE51h 0x00000045 xor dword ptr [esp], 68D411CBh 0x0000004c pushad 0x0000004d mov edi, eax 0x0000004f mov eax, 36C28B8Fh 0x00000054 popad 0x00000055 push 00000000h 0x00000057 push eax 0x00000058 push edx 0x00000059 pushad 0x0000005a pushfd 0x0000005b jmp 00007FB83CF3EE57h 0x00000060 jmp 00007FB83CF3EE53h 0x00000065 popfd 0x00000066 jmp 00007FB83CF3EE58h 0x0000006b popad 0x0000006c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49103AC second address: 49103D6 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53BBh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov dword ptr [esp+18h], eax 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FB83CBE53C5h 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49103D6 second address: 49103DC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49103DC second address: 49103E0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491040A second address: 491040E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 491040E second address: 4910414 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910414 second address: 4910447 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov edi, eax 0x00000005 push eax 0x00000006 pop ebx 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edi 0x0000000b jmp 00007FB83CF3EE4Eh 0x00000010 pop esi 0x00000011 push eax 0x00000012 push edx 0x00000013 jmp 00007FB83CF3EE57h 0x00000018 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4910447 second address: 49104CD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FB83CBE53BFh 0x00000009 and cl, FFFFFFDEh 0x0000000c jmp 00007FB83CBE53C9h 0x00000011 popfd 0x00000012 popad 0x00000013 pop edx 0x00000014 pop eax 0x00000015 mov esp, ebp 0x00000017 pushad 0x00000018 pushfd 0x00000019 jmp 00007FB83CBE53C3h 0x0000001e adc si, A5EEh 0x00000023 jmp 00007FB83CBE53C9h 0x00000028 popfd 0x00000029 mov bx, cx 0x0000002c popad 0x0000002d pop ebp 0x0000002e push eax 0x0000002f push edx 0x00000030 push eax 0x00000031 push edx 0x00000032 jmp 00007FB83CBE53C4h 0x00000037 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49104CD second address: 49104D3 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49104D3 second address: 493005F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FB83CBE53BCh 0x00000009 adc ch, FFFFFFC8h 0x0000000c jmp 00007FB83CBE53BBh 0x00000011 popfd 0x00000012 jmp 00007FB83CBE53C8h 0x00000017 popad 0x00000018 pop edx 0x00000019 pop eax 0x0000001a retn 0004h 0x0000001d push 00000000h 0x0000001f push dword ptr [ebp-04h] 0x00000022 push 00000000h 0x00000024 push 00000000h 0x00000026 push 00000096h 0x0000002b push 000001F4h 0x00000030 push FFFFFC18h 0x00000035 push FFFFFC18h 0x0000003a push 00C80000h 0x0000003f lea eax, dword ptr [ebp-0000014Ch] 0x00000045 push eax 0x00000046 lea eax, dword ptr [ebp-0000024Ch] 0x0000004c push eax 0x0000004d push 00000080h 0x00000052 call 00007FB83CBE6EEBh 0x00000057 jmp 00007FB8411122B6h 0x0000005c mov edi, edi 0x0000005e pushad 0x0000005f pushad 0x00000060 mov al, dh 0x00000062 movzx eax, di 0x00000065 popad 0x00000066 popad 0x00000067 push edx 0x00000068 jmp 00007FB83CBE53BCh 0x0000006d mov dword ptr [esp], ebp 0x00000070 jmp 00007FB83CBE53C0h 0x00000075 mov ebp, esp 0x00000077 pushad 0x00000078 jmp 00007FB83CBE53BEh 0x0000007d mov ch, 79h 0x0000007f popad 0x00000080 mov eax, 00000000h 0x00000085 push eax 0x00000086 push edx 0x00000087 jmp 00007FB83CBE53C9h 0x0000008c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 493005F second address: 4930065 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4930065 second address: 49300A2 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C3h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov edx, dword ptr [ebp+0Ch] 0x0000000e push eax 0x0000000f push edx 0x00000010 pushad 0x00000011 mov edx, 3DAD4616h 0x00000016 call 00007FB83CBE53C7h 0x0000001b pop eax 0x0000001c popad 0x0000001d rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49300A2 second address: 49300C1 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 pop edi 0x00000005 push ecx 0x00000006 pop edi 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a nop 0x0000000b jmp 00007FB83CF3EE4Ah 0x00000010 push eax 0x00000011 push eax 0x00000012 push edx 0x00000013 pushad 0x00000014 mov cl, A2h 0x00000016 movsx edi, si 0x00000019 popad 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49300C1 second address: 49300C7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49300C7 second address: 49300E6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 nop 0x00000009 push eax 0x0000000a push edx 0x0000000b jmp 00007FB83CF3EE54h 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49300E6 second address: 49300FE instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53BBh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 nop 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d mov dh, FCh 0x0000000f mov edi, ecx 0x00000011 popad 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49300FE second address: 493018F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FB83CF3EE4Fh 0x00000009 adc cx, 576Eh 0x0000000e jmp 00007FB83CF3EE59h 0x00000013 popfd 0x00000014 pushfd 0x00000015 jmp 00007FB83CF3EE50h 0x0000001a xor eax, 5424EAE8h 0x00000020 jmp 00007FB83CF3EE4Bh 0x00000025 popfd 0x00000026 popad 0x00000027 pop edx 0x00000028 pop eax 0x00000029 push eax 0x0000002a pushad 0x0000002b mov bx, D38Ah 0x0000002f movsx ebx, ax 0x00000032 popad 0x00000033 nop 0x00000034 jmp 00007FB83CF3EE4Ah 0x00000039 push 08F05416h 0x0000003e pushad 0x0000003f movsx edi, cx 0x00000042 popad 0x00000043 add dword ptr [esp], 370FABEBh 0x0000004a push eax 0x0000004b push edx 0x0000004c jmp 00007FB83CF3EE51h 0x00000051 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 493018F second address: 49301C5 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C1h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 nop 0x0000000a pushad 0x0000000b jmp 00007FB83CBE53BCh 0x00000010 mov ecx, 664BEDA1h 0x00000015 popad 0x00000016 push eax 0x00000017 push eax 0x00000018 push edx 0x00000019 jmp 00007FB83CBE53BAh 0x0000001e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49301C5 second address: 49301E9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push edi 0x00000004 pop eax 0x00000005 mov ax, di 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b nop 0x0000000c jmp 00007FB83CF3EE4Fh 0x00000011 push dword ptr [ebp+34h] 0x00000014 push eax 0x00000015 push edx 0x00000016 push eax 0x00000017 push edx 0x00000018 push eax 0x00000019 push edx 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49301E9 second address: 49301ED instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49301ED second address: 49301F1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49301F1 second address: 49301F7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49301F7 second address: 4930214 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FB83CF3EE59h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4930214 second address: 493023F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov ecx, dword ptr [ebp+08h] 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e call 00007FB83CBE53C6h 0x00000013 pop esi 0x00000014 mov edx, 3624B696h 0x00000019 popad 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 493023F second address: 4930260 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE4Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push dword ptr [ebp+30h] 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 jmp 00007FB83CF3EE4Ah 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4930260 second address: 4930264 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4930264 second address: 493026A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 493026A second address: 49302BE instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53BEh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push dword ptr [ebp+2Ch] 0x0000000c jmp 00007FB83CBE53C0h 0x00000011 push dword ptr [ebp+28h] 0x00000014 jmp 00007FB83CBE53C0h 0x00000019 push dword ptr [ebp+24h] 0x0000001c push eax 0x0000001d push edx 0x0000001e jmp 00007FB83CBE53C7h 0x00000023 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49302BE second address: 49302E4 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE59h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push dword ptr [ebp+20h] 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49302E4 second address: 49302E8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49302E8 second address: 49302EE instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4930388 second address: 49303BF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53BEh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop ebp 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d call 00007FB83CBE53BDh 0x00000012 pop eax 0x00000013 call 00007FB83CBE53C1h 0x00000018 pop esi 0x00000019 popad 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49303BF second address: 49303C5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49303C5 second address: 49303C9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49303C9 second address: 49303CD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920ACB second address: 4920AF7 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov ax, dx 0x00000006 jmp 00007FB83CBE53BDh 0x0000000b popad 0x0000000c pop edx 0x0000000d pop eax 0x0000000e xchg eax, ebp 0x0000000f jmp 00007FB83CBE53BEh 0x00000014 push eax 0x00000015 push eax 0x00000016 push edx 0x00000017 push eax 0x00000018 push edx 0x00000019 pushad 0x0000001a popad 0x0000001b rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920AF7 second address: 4920B13 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE58h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920B13 second address: 4920B19 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920B19 second address: 4920B1D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920B1D second address: 4920B31 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 xchg eax, ebp 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c mov cx, 4761h 0x00000010 movzx esi, dx 0x00000013 popad 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920B31 second address: 4920B44 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FB83CF3EE4Fh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920B44 second address: 4920C3B instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov ebp, esp 0x0000000d jmp 00007FB83CBE53BEh 0x00000012 push 00000001h 0x00000014 jmp 00007FB83CBE53C0h 0x00000019 push 00000000h 0x0000001b jmp 00007FB83CBE53C0h 0x00000020 push 00000000h 0x00000022 pushad 0x00000023 push eax 0x00000024 call 00007FB83CBE53BDh 0x00000029 pop eax 0x0000002a pop edi 0x0000002b pushfd 0x0000002c jmp 00007FB83CBE53BEh 0x00000031 sub ecx, 50440448h 0x00000037 jmp 00007FB83CBE53BBh 0x0000003c popfd 0x0000003d popad 0x0000003e push dword ptr [ebp+0Ch] 0x00000041 jmp 00007FB83CBE53C6h 0x00000046 sub edx, edx 0x00000048 jmp 00007FB83CBE53C1h 0x0000004d sub ecx, ecx 0x0000004f pushad 0x00000050 pushad 0x00000051 call 00007FB83CBE53C3h 0x00000056 pop esi 0x00000057 mov bx, 2F4Ch 0x0000005b popad 0x0000005c mov ebx, 15B2F438h 0x00000061 popad 0x00000062 push dword ptr [ebp+08h] 0x00000065 push eax 0x00000066 push edx 0x00000067 push eax 0x00000068 push edx 0x00000069 jmp 00007FB83CBE53C9h 0x0000006e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920C3B second address: 4920C41 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 492005A second address: 4920062 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 movzx eax, di 0x00000007 popad 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920062 second address: 492008C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FB83CF3EE4Ch 0x00000008 push eax 0x00000009 pop ebx 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d xchg eax, ebp 0x0000000e push eax 0x0000000f push edx 0x00000010 jmp 00007FB83CF3EE53h 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 492008C second address: 49200BB instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 mov si, dx 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov ebp, esp 0x0000000d jmp 00007FB83CBE53C7h 0x00000012 mov ecx, dword ptr [75AF4C30h] 0x00000018 pushad 0x00000019 push eax 0x0000001a push edx 0x0000001b push eax 0x0000001c push edx 0x0000001d rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49200BB second address: 49200BF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49200BF second address: 49200EA instructions: 0x00000000 rdtsc 0x00000002 call 00007FB83CBE53C0h 0x00000007 pop eax 0x00000008 pop edx 0x00000009 pop eax 0x0000000a mov dh, 7Bh 0x0000000c popad 0x0000000d xchg eax, ebx 0x0000000e push eax 0x0000000f push edx 0x00000010 pushad 0x00000011 push edi 0x00000012 pop eax 0x00000013 call 00007FB83CBE53BBh 0x00000018 pop eax 0x00000019 popad 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49200EA second address: 49200F0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49200F0 second address: 4920117 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C0h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FB83CBE53BEh 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920117 second address: 4920196 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 movsx ebx, cx 0x00000006 pushfd 0x00000007 jmp 00007FB83CF3EE4Ah 0x0000000c adc ecx, 343F7ED8h 0x00000012 jmp 00007FB83CF3EE4Bh 0x00000017 popfd 0x00000018 popad 0x00000019 pop edx 0x0000001a pop eax 0x0000001b xchg eax, ebx 0x0000001c pushad 0x0000001d pushfd 0x0000001e jmp 00007FB83CF3EE54h 0x00000023 sbb esi, 40E34938h 0x00000029 jmp 00007FB83CF3EE4Bh 0x0000002e popfd 0x0000002f push ecx 0x00000030 jmp 00007FB83CF3EE4Fh 0x00000035 pop esi 0x00000036 popad 0x00000037 push ecx 0x00000038 jmp 00007FB83CF3EE54h 0x0000003d mov dword ptr [esp], esi 0x00000040 push eax 0x00000041 push edx 0x00000042 push eax 0x00000043 push edx 0x00000044 pushad 0x00000045 popad 0x00000046 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920196 second address: 49201B3 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49201B3 second address: 49201B9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49201B9 second address: 49201BD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49201BD second address: 49201D7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov ebx, 00000000h 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FB83CF3EE4Bh 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49201D7 second address: 4920261 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FB83CBE53BFh 0x00000009 add cx, DF1Eh 0x0000000e jmp 00007FB83CBE53C9h 0x00000013 popfd 0x00000014 popad 0x00000015 pop edx 0x00000016 pop eax 0x00000017 push ecx 0x00000018 jmp 00007FB83CBE53BAh 0x0000001d mov dword ptr [esp], edi 0x00000020 pushad 0x00000021 mov cx, dx 0x00000024 popad 0x00000025 mov edi, dword ptr [ebp+08h] 0x00000028 pushad 0x00000029 pushfd 0x0000002a jmp 00007FB83CBE53C5h 0x0000002f add eax, 380F46B6h 0x00000035 jmp 00007FB83CBE53C1h 0x0000003a popfd 0x0000003b push ecx 0x0000003c pop esi 0x0000003d popad 0x0000003e movzx eax, di 0x00000041 push eax 0x00000042 push edx 0x00000043 pushad 0x00000044 pushad 0x00000045 popad 0x00000046 mov si, 6597h 0x0000004a popad 0x0000004b rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920261 second address: 49202C6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FB83CF3EE53h 0x00000009 or ax, 949Eh 0x0000000e jmp 00007FB83CF3EE59h 0x00000013 popfd 0x00000014 mov ch, 30h 0x00000016 popad 0x00000017 pop edx 0x00000018 pop eax 0x00000019 cmp ebx, dword ptr [ecx+0Ch] 0x0000001c pushad 0x0000001d mov bh, 2Bh 0x0000001f mov eax, 28DF5EF1h 0x00000024 popad 0x00000025 jc 00007FB8AE0A921Eh 0x0000002b jmp 00007FB83CF3EE4Ch 0x00000030 ja 00007FB8AE0A9287h 0x00000036 push eax 0x00000037 push edx 0x00000038 push eax 0x00000039 push edx 0x0000003a pushad 0x0000003b popad 0x0000003c rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49202C6 second address: 49202CA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49202CA second address: 49202D0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 490001D second address: 4900023 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4900023 second address: 4900088 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push 6AE9AA7Ah 0x0000000d pushad 0x0000000e mov ax, D201h 0x00000012 mov ebx, eax 0x00000014 popad 0x00000015 add dword ptr [esp], 0AC4EDCEh 0x0000001c jmp 00007FB83CF3EE58h 0x00000021 call 00007FB8AE0D4961h 0x00000026 push 75A92B70h 0x0000002b push dword ptr fs:[00000000h] 0x00000032 mov eax, dword ptr [esp+10h] 0x00000036 mov dword ptr [esp+10h], ebp 0x0000003a lea ebp, dword ptr [esp+10h] 0x0000003e sub esp, eax 0x00000040 push ebx 0x00000041 push esi 0x00000042 push edi 0x00000043 mov eax, dword ptr [75AF4538h] 0x00000048 xor dword ptr [ebp-04h], eax 0x0000004b xor eax, ebp 0x0000004d push eax 0x0000004e mov dword ptr [ebp-18h], esp 0x00000051 push dword ptr [ebp-08h] 0x00000054 mov eax, dword ptr [ebp-04h] 0x00000057 mov dword ptr [ebp-04h], FFFFFFFEh 0x0000005e mov dword ptr [ebp-08h], eax 0x00000061 lea eax, dword ptr [ebp-10h] 0x00000064 mov dword ptr fs:[00000000h], eax 0x0000006a ret 0x0000006b jmp 00007FB83CF3EE50h 0x00000070 mov ecx, dword ptr [ebp+08h] 0x00000073 push eax 0x00000074 push edx 0x00000075 jmp 00007FB83CF3EE57h 0x0000007a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4900088 second address: 490008E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 490008E second address: 4900092 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4900114 second address: 4900118 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4900118 second address: 4900128 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE4Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4900128 second address: 4900154 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53BBh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 je 00007FB8ADD58FC0h 0x0000000f push eax 0x00000010 push edx 0x00000011 jmp 00007FB83CBE53C5h 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4900154 second address: 490016D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push ebx 0x00000004 pop eax 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 and dword ptr [ebp-04h], 00000000h 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FB83CF3EE4Bh 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 490016D second address: 4900172 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4900172 second address: 49001B6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 mov di, 3218h 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov edi, dword ptr [ebp+10h] 0x0000000e jmp 00007FB83CF3EE57h 0x00000013 test edi, edi 0x00000015 push eax 0x00000016 push edx 0x00000017 pushad 0x00000018 mov ecx, edi 0x0000001a jmp 00007FB83CF3EE57h 0x0000001f popad 0x00000020 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49001B6 second address: 49001BC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49001BC second address: 49001C0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49001C0 second address: 49001C4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49001C4 second address: 4900221 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 je 00007FB8AE0B29A0h 0x0000000e jmp 00007FB83CF3EE57h 0x00000013 mov ecx, dword ptr [ebx+00000080h] 0x00000019 push eax 0x0000001a push edx 0x0000001b pushad 0x0000001c pushfd 0x0000001d jmp 00007FB83CF3EE4Bh 0x00000022 and si, 2E4Eh 0x00000027 jmp 00007FB83CF3EE59h 0x0000002c popfd 0x0000002d mov di, cx 0x00000030 popad 0x00000031 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4900221 second address: 4900227 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4900227 second address: 490022B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 490022B second address: 490026C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov edx, dword ptr [ebx+00000084h] 0x0000000e pushad 0x0000000f pushfd 0x00000010 jmp 00007FB83CBE53C1h 0x00000015 add cl, 00000036h 0x00000018 jmp 00007FB83CBE53C1h 0x0000001d popfd 0x0000001e mov ebx, esi 0x00000020 popad 0x00000021 mov eax, ecx 0x00000023 push eax 0x00000024 push edx 0x00000025 push eax 0x00000026 push edx 0x00000027 pushad 0x00000028 popad 0x00000029 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 490026C second address: 4900272 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4900381 second address: 49003EF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 call 00007FB83CBE53BEh 0x00000009 pop esi 0x0000000a popad 0x0000000b pushad 0x0000000c mov dx, si 0x0000000f popad 0x00000010 popad 0x00000011 xchg eax, esi 0x00000012 push eax 0x00000013 push edx 0x00000014 pushad 0x00000015 pushfd 0x00000016 jmp 00007FB83CBE53BBh 0x0000001b adc esi, 439FA16Eh 0x00000021 jmp 00007FB83CBE53C9h 0x00000026 popfd 0x00000027 pushfd 0x00000028 jmp 00007FB83CBE53C0h 0x0000002d sub ecx, 5756E4E8h 0x00000033 jmp 00007FB83CBE53BBh 0x00000038 popfd 0x00000039 popad 0x0000003a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49003EF second address: 4900424 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CF3EE59h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FB83CF3EE53h 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4900424 second address: 4900441 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4900441 second address: 4900447 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4900447 second address: 490044B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 490044B second address: 4900468 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 xchg eax, esi 0x00000009 push eax 0x0000000a push edx 0x0000000b jmp 00007FB83CF3EE52h 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4900560 second address: 49005B5 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C1h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 or eax, dword ptr [esi+0000008Ch] 0x0000000f push eax 0x00000010 push edx 0x00000011 pushad 0x00000012 pushfd 0x00000013 jmp 00007FB83CBE53C3h 0x00000018 add ecx, 7B18629Eh 0x0000001e jmp 00007FB83CBE53C9h 0x00000023 popfd 0x00000024 mov edx, ecx 0x00000026 popad 0x00000027 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49005B5 second address: 49005D1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FB83CF3EE58h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49005D1 second address: 4920304 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53BBh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b jmp 00007FB8ADD692D0h 0x00000010 jne 00007FB83CBE53C3h 0x00000012 test byte ptr [esi+11h], 00000010h 0x00000016 jne 00007FB83CBE53BDh 0x00000018 mov eax, dword ptr [esi+38h] 0x0000001b or eax, dword ptr [esi+3Ch] 0x0000001e jne 00007FB83CBE53B5h 0x00000020 inc eax 0x00000021 jmp 00007FB83CBE53BDh 0x00000023 pop esi 0x00000024 pop ebp 0x00000025 retn 0004h 0x00000028 push 00000000h 0x0000002a push 00000000h 0x0000002c push 00000000h 0x0000002e lea eax, dword ptr [ebp-20h] 0x00000031 push eax 0x00000032 call 00007FB83CBE6EE5h 0x00000037 jmp 00007FB841102594h 0x0000003c mov edi, edi 0x0000003e push eax 0x0000003f push edx 0x00000040 push eax 0x00000041 push edx 0x00000042 push eax 0x00000043 push edx 0x00000044 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920304 second address: 4920308 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920308 second address: 492030C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 492030C second address: 4920312 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920312 second address: 4920322 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov dx, cx 0x00000006 popad 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, ebp 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920322 second address: 4920326 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920326 second address: 492032C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 492032C second address: 4920349 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FB83CF3EE59h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920349 second address: 492041E instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FB83CBE53C1h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c jmp 00007FB83CBE53C1h 0x00000011 xchg eax, ebp 0x00000012 pushad 0x00000013 pushfd 0x00000014 jmp 00007FB83CBE53BCh 0x00000019 adc cl, FFFFFFA8h 0x0000001c jmp 00007FB83CBE53BBh 0x00000021 popfd 0x00000022 pushad 0x00000023 movzx esi, di 0x00000026 mov eax, edi 0x00000028 popad 0x00000029 popad 0x0000002a mov ebp, esp 0x0000002c pushad 0x0000002d call 00007FB83CBE53C3h 0x00000032 call 00007FB83CBE53C8h 0x00000037 pop ecx 0x00000038 pop edx 0x00000039 pushfd 0x0000003a jmp 00007FB83CBE53C0h 0x0000003f jmp 00007FB83CBE53C5h 0x00000044 popfd 0x00000045 popad 0x00000046 mov edx, dword ptr [ebp+10h] 0x00000049 jmp 00007FB83CBE53BEh 0x0000004e sub esp, 20h 0x00000051 pushad 0x00000052 call 00007FB83CBE53BEh 0x00000057 pop ebx 0x00000058 popad 0x00000059 mov ecx, dword ptr [ebp+14h] 0x0000005c push eax 0x0000005d push edx 0x0000005e push eax 0x0000005f push edx 0x00000060 push eax 0x00000061 push edx 0x00000062 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 492041E second address: 4920422 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920422 second address: 4920428 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 4920428 second address: 49204AA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov ch, bh 0x00000005 mov ebx, eax 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a mov eax, edx 0x0000000c jmp 00007FB83CF3EE50h 0x00000011 or eax, ecx 0x00000013 jmp 00007FB83CF3EE50h 0x00000018 xchg eax, esi 0x00000019 pushad 0x0000001a pushfd 0x0000001b jmp 00007FB83CF3EE4Eh 0x00000020 add esi, 117DB318h 0x00000026 jmp 00007FB83CF3EE4Bh 0x0000002b popfd 0x0000002c movzx esi, di 0x0000002f popad 0x00000030 push eax 0x00000031 jmp 00007FB83CF3EE52h 0x00000036 xchg eax, esi 0x00000037 push eax 0x00000038 push edx 0x00000039 jmp 00007FB83CF3EE57h 0x0000003e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.19167.22607.exe | RDTSC instruction interceptor: First address: 49204AA second address: 49204D6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov di, A74Ah 0x00000007 push edx 0x00000008 pop eax 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c mov esi, FFFE0000h 0x00000011 pushad 0x00000012 jmp 00007FB83CBE53C3h 0x00000017 push eax 0x00000018 push edx 0x00000019 mov eax, 1FCB9195h 0x0000001e rdtsc |