Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0040146B SetTimer,GetTickCount,GetTickCount,GetMessageW,GetTickCount,GetFocus,TranslateAcceleratorW,GetKeyState,GetWindowLongW,IsWindowEnabled,GetKeyState,GetKeyState,GetKeyState,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SendMessageW,IsDialogMessageW,ShowWindow,GetForegroundWindow,GetWindowThreadProcessId,GetClassNameW,IsDialogMessageW,SetCurrentDirectoryW, | 0_2_0040146B |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0040F956 GetTickCount,GetTickCount,PeekMessageW,GetTickCount,_wcschr,_wcschr,__wcsnicmp,_free,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetWindowThreadProcessId,AttachThreadInput,BlockInput, | 0_2_0040F956 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0040F520 __wcsnicmp,__wcsnicmp,GetWindowThreadProcessId,AttachThreadInput,GetKeyboardLayout,GetTickCount,GetCurrentThreadId,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetGUIThreadInfo,GetWindowThreadProcessId,GetTickCount,BlockInput,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,_wcschr,_wcschr,__wcsnicmp,__wcsnicmp,_wcschr,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsicoll,PostMessageW,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,__wcsnicmp,__wcsnicmp,__fassign,PostMessageW,PostMessageW,PostMessageW,__itow,PostMessageW,_free,GetTickCount,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetWindowThreadProcessId,AttachThreadInput,BlockInput,GetForegroundWindow,GetWindowThreadProcessId, | 0_2_0040F520 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_00412DD0 GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetWindowThreadProcessId,GetKeyState, | 0_2_00412DD0 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_004013F4 GlobalUnlock,CloseClipboard,SetTimer,GetTickCount,GetTickCount,GetMessageW,GetTickCount,GetFocus,TranslateAcceleratorW,GetKeyState,GetWindowLongW,IsWindowEnabled,GetKeyState,GetKeyState,GetKeyState,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SendMessageW,IsDialogMessageW,ShowWindow,GetForegroundWindow,GetWindowThreadProcessId,GetClassNameW,KillTimer,DragQueryFileW,DragFinish,GetTickCount,DragFinish,DragFinish,_wcsncpy,_wcsncpy,GetTickCount,_wcsncpy,GetTickCount,IsDialogMessageW,SetCurrentDirectoryW,TranslateAcceleratorW,TranslateMessage,DispatchMessageW, | 1_2_004013F4 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0040F520 __wcsnicmp,__wcsnicmp,GetWindowThreadProcessId,AttachThreadInput,GetKeyboardLayout,GetTickCount,GetCurrentThreadId,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetGUIThreadInfo,GetWindowThreadProcessId,GetTickCount,BlockInput,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,_wcschr,_wcschr,__wcsnicmp,__wcsnicmp,_wcschr,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsicoll,PostMessageW,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,__wcsnicmp,__wcsnicmp,__fassign,PostMessageW,PostMessageW,PostMessageW,__itow,PostMessageW,_free,GetTickCount,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetWindowThreadProcessId,AttachThreadInput,BlockInput,GetForegroundWindow,GetWindowThreadProcessId, | 1_2_0040F520 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0040F956 GetTickCount,GetTickCount,PeekMessageW,GetTickCount,_wcschr,_wcschr,__wcsnicmp,_free,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetWindowThreadProcessId,AttachThreadInput,BlockInput, | 1_2_0040F956 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00412DD0 GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetWindowThreadProcessId,GetKeyState, | 1_2_00412DD0 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_004013F4 GlobalUnlock,CloseClipboard,SetTimer,GetTickCount,GetTickCount,GetMessageW,GetTickCount,GetFocus,TranslateAcceleratorW,GetKeyState,GetWindowLongW,IsWindowEnabled,GetKeyState,GetKeyState,GetKeyState,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SendMessageW,IsDialogMessageW,ShowWindow,GetForegroundWindow,GetWindowThreadProcessId,GetClassNameW,KillTimer,DragQueryFileW,DragFinish,GetTickCount,DragFinish,DragFinish,_wcsncpy,_wcsncpy,GetTickCount,_wcsncpy,GetTickCount,IsDialogMessageW,SetCurrentDirectoryW,TranslateAcceleratorW,TranslateMessage,DispatchMessageW, | 2_2_004013F4 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0040F520 __wcsnicmp,__wcsnicmp,GetWindowThreadProcessId,AttachThreadInput,GetKeyboardLayout,GetTickCount,GetCurrentThreadId,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetGUIThreadInfo,GetWindowThreadProcessId,GetTickCount,BlockInput,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,_wcschr,_wcschr,__wcsnicmp,__wcsnicmp,_wcschr,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsicoll,PostMessageW,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,__wcsnicmp,__wcsnicmp,__fassign,PostMessageW,PostMessageW,PostMessageW,__itow,PostMessageW,_free,GetTickCount,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetWindowThreadProcessId,AttachThreadInput,BlockInput,GetForegroundWindow,GetWindowThreadProcessId, | 2_2_0040F520 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0040F956 GetTickCount,GetTickCount,PeekMessageW,GetTickCount,_wcschr,_wcschr,__wcsnicmp,_free,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetWindowThreadProcessId,AttachThreadInput,BlockInput, | 2_2_0040F956 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00412DD0 GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetWindowThreadProcessId,GetKeyState, | 2_2_00412DD0 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0040C800 | 0_2_0040C800 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0049B08C | 0_2_0049B08C |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0040C1E0 | 0_2_0040C1E0 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_004999EF | 0_2_004999EF |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0040DA40 | 0_2_0040DA40 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_00496A05 | 0_2_00496A05 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_00414AC1 | 0_2_00414AC1 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_00414AC0 | 0_2_00414AC0 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_00408290 | 0_2_00408290 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0042F2A0 | 0_2_0042F2A0 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0040F520 | 0_2_0040F520 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_00401DE0 | 0_2_00401DE0 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_004195A8 | 0_2_004195A8 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_004925B2 | 0_2_004925B2 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0041CEB4 | 0_2_0041CEB4 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_00407FC0 | 0_2_00407FC0 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0043A7A0 | 0_2_0043A7A0 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_004013F4 | 1_2_004013F4 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0049F010 | 1_2_0049F010 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0049B08C | 1_2_0049B08C |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00460170 | 1_2_00460170 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0040C1E0 | 1_2_0040C1E0 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0049D1F1 | 1_2_0049D1F1 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00448260 | 1_2_00448260 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0047F260 | 1_2_0047F260 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00408290 | 1_2_00408290 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0042F2A0 | 1_2_0042F2A0 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00420490 | 1_2_00420490 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00442570 | 1_2_00442570 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0040F520 | 1_2_0040F520 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_004925B2 | 1_2_004925B2 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0048E600 | 1_2_0048E600 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_004186B0 | 1_2_004186B0 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00482755 | 1_2_00482755 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0041C700 | 1_2_0041C700 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_004897EE | 1_2_004897EE |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0043A7A0 | 1_2_0043A7A0 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0043F870 | 1_2_0043F870 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0040C800 | 1_2_0040C800 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0049D8CD | 1_2_0049D8CD |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00484970 | 1_2_00484970 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_004829C5 | 1_2_004829C5 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_004999EF | 1_2_004999EF |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0040DA40 | 1_2_0040DA40 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00496A05 | 1_2_00496A05 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00414AC0 | 1_2_00414AC0 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00432DD0 | 1_2_00432DD0 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00401DE0 | 1_2_00401DE0 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00481E4B | 1_2_00481E4B |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00499F40 | 1_2_00499F40 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00475F00 | 1_2_00475F00 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00404F10 | 1_2_00404F10 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00407FC0 | 1_2_00407FC0 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_004013F4 | 2_2_004013F4 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0040F520 | 2_2_0040F520 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0049F010 | 2_2_0049F010 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0049B08C | 2_2_0049B08C |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00460170 | 2_2_00460170 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0040C1E0 | 2_2_0040C1E0 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0049D1F1 | 2_2_0049D1F1 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00448260 | 2_2_00448260 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0047F260 | 2_2_0047F260 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00408290 | 2_2_00408290 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0042F2A0 | 2_2_0042F2A0 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00420490 | 2_2_00420490 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00442570 | 2_2_00442570 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_004925B2 | 2_2_004925B2 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0048E600 | 2_2_0048E600 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_004186B0 | 2_2_004186B0 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00482755 | 2_2_00482755 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0041C700 | 2_2_0041C700 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_004897EE | 2_2_004897EE |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0043A7A0 | 2_2_0043A7A0 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0043F870 | 2_2_0043F870 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0040C800 | 2_2_0040C800 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0049D8CD | 2_2_0049D8CD |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00484970 | 2_2_00484970 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_004829C5 | 2_2_004829C5 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_004999EF | 2_2_004999EF |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0040DA40 | 2_2_0040DA40 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00496A05 | 2_2_00496A05 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00414AC0 | 2_2_00414AC0 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00432DD0 | 2_2_00432DD0 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00401DE0 | 2_2_00401DE0 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00481E4B | 2_2_00481E4B |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00499F40 | 2_2_00499F40 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00475F00 | 2_2_00475F00 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00404F10 | 2_2_00404F10 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00407FC0 | 2_2_00407FC0 |
Source: unknown | Process created: C:\Users\user\Desktop\Andrej Simulator X.exe "C:\Users\user\Desktop\Andrej Simulator X.exe" | |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Process created: C:\Users\user\AppData\Local\Temp\aaa.exe C:\Users\user\AppData\Local\Temp\aaa.exe | |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Process created: C:\Users\user\AppData\Local\Temp\bbb.exe C:\Users\user\AppData\Local\Temp\bbb.exe | |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2080,i,2628610554253254953,2625306694296692569,262144 --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2108 /prefetch:3 | |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Process created: C:\Users\user\AppData\Local\Temp\aaa.exe C:\Users\user\AppData\Local\Temp\aaa.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Process created: C:\Users\user\AppData\Local\Temp\bbb.exe C:\Users\user\AppData\Local\Temp\bbb.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Users\user\AppData\Local\Temp\kitty.exe C:\Users\user\AppData\Local\Temp/kitty.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2080,i,2628610554253254953,2625306694296692569,262144 --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2108 /prefetch:3 | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c "echo a>%windir%\system32\hal.dll" | |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Section loaded: kbdsg.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textshaping.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textinputframework.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coreuicomponents.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: edputil.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: urlmon.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: iertutil.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: srvcli.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: appresolver.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: bcp47langs.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: slc.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sppc.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textshaping.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textinputframework.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coreuicomponents.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: edputil.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: urlmon.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: iertutil.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: srvcli.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: appresolver.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: bcp47langs.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: slc.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sppc.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textshaping.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: edputil.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: urlmon.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: iertutil.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: srvcli.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textinputframework.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coreuicomponents.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: appresolver.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: bcp47langs.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: slc.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sppc.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textshaping.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textinputframework.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coreuicomponents.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: edputil.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: urlmon.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: iertutil.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: srvcli.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: appresolver.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: bcp47langs.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: slc.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sppc.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textshaping.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: edputil.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: urlmon.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: iertutil.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: srvcli.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textinputframework.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coreuicomponents.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: appresolver.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: bcp47langs.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: slc.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sppc.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textshaping.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textinputframework.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coreuicomponents.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: edputil.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: urlmon.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: iertutil.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: srvcli.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: appresolver.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: bcp47langs.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: slc.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sppc.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textshaping.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textinputframework.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coreuicomponents.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: edputil.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: urlmon.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: iertutil.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: srvcli.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: appresolver.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: bcp47langs.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: slc.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sppc.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textshaping.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: textinputframework.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coreuicomponents.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: edputil.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: urlmon.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: iertutil.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: srvcli.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: appresolver.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: bcp47langs.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: slc.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: sppc.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\kitty.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0043D800 GetCursorPos,GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,WindowFromPoint,EnumChildWindows,_memset,EnumChildWindows,GetClassNameW,EnumChildWindows, | 0_2_0043D800 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_00453120 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,CreateDCW,GetDC,GetPixel,DeleteDC,ReleaseDC, | 0_2_00453120 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_00477AB0 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen, | 0_2_00477AB0 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0047A3E0 GetForegroundWindow,IsWindowVisible,IsIconic,ShowWindow, | 0_2_0047A3E0 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_00439490 GetForegroundWindow,IsWindowVisible,GetWindowThreadProcessId,IsZoomed,IsIconic,GetWindowLongW,GetModuleHandleW,GetProcAddress, | 0_2_00439490 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0047A520 GetWindowThreadProcessId,GetWindowThreadProcessId,GetForegroundWindow,IsIconic,ShowWindow,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,SetForegroundWindow,SetForegroundWindow,GetForegroundWindow,GetWindow,AttachThreadInput,AttachThreadInput,BringWindowToTop, | 0_2_0047A520 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0046A590 SendMessageW,SendMessageW,SendMessageW,GetWindowLongW,IsWindowVisible,IsIconic,GetFocus,GetWindowRect,GetPropW,ShowWindow,GetUpdateRect,SendMessageW,GetWindowLongW,ShowWindow,EnableWindow,GetWindowRect,PtInRect,PtInRect,PtInRect,SetFocus,SendMessageW,SendMessageW,ShowWindow,SetFocus,InvalidateRect,InvalidateRect,InvalidateRect,MapWindowPoints,InvalidateRect, | 0_2_0046A590 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0043A7A0 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,GetDC,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,ReleaseDC,SelectObject,DeleteDC,DeleteObject,_free,GetPixel,ReleaseDC, | 0_2_0043A7A0 |
Source: C:\Users\user\Desktop\Andrej Simulator X.exe | Code function: 0_2_0043AFB0 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,_wcsrchr,__wcsicoll,__wcsicoll,__wcsicoll,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,__wcsnicmp,__fassign,__wcsnicmp,_wcsncpy,__fassign,__fassign,__fassign,__fassign,GetDC,DestroyIcon,DeleteObject,DeleteObject,GetIconInfo,DeleteObject,DeleteObject,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,ReleaseDC,DeleteObject,SelectObject,DeleteDC,DeleteObject,_free,_free,_free, | 0_2_0043AFB0 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00460170 MulDiv,MulDiv,MulDiv,_wcschr,__wcsicoll,MulDiv,MulDiv,MulDiv,GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,MulDiv,MulDiv,GetDC,SelectObject,GetTextMetricsW,GetSystemMetrics,GetDC,SelectObject,GetTextMetricsW,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,_wcschr,DrawTextW,DrawTextW,GetCharABCWidthsW,MulDiv,GetSystemMetrics,GetSystemMetrics,MulDiv,MulDiv,MulDiv,MulDiv,GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,IsWindowVisible,IsIconic,GetWindowLongW,GetPropW,MapWindowPoints,GetWindowLongW,SendMessageW,CreateWindowExW,CreateWindowExW,CreateWindowExW,CreateWindowExW,GetWindowLongW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,CreateWindowExW,SendMessageW,CreateWindowExW,SendMessageW,SendMessageW,MulDiv,MulDiv,MulDiv,MoveWindow,SelectObject,ReleaseDC,SendMessageW,SendMessageW,GetClientRect,SetWindowLongW,SendMessageW,SetWindowLongW,MoveWindow,GetWindowRect,SendMessageW,SetWindowPos,GetWindowRect,MapWindowPoints,InvalidateRect,SetWindowPos,SetWindowPos,MapWindowPoints, | 1_2_00460170 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00453120 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,CreateDCW,GetDC,GetPixel,DeleteDC,ReleaseDC, | 1_2_00453120 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0047A3E0 GetForegroundWindow,IsWindowVisible,IsIconic,ShowWindow, | 1_2_0047A3E0 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00463410 GetWindowLongW,GetWindowLongW,GetWindowLongW,__wcsnicmp,__wcsnicmp,__wcsicoll,SetWindowPos,__wcsicoll,__wcsicoll,__wcsnicmp,__wcsicoll,__wcsicoll,__wcsicoll,EnableWindow,__wcsnicmp,__wcsnicmp,__wcsicoll,__wcsicoll,__wcsicoll,__wcsnicmp,MulDiv,MulDiv,__wcsnicmp,MulDiv,MulDiv,__wcsicoll,__wcsicoll,__wcsicoll,__wcsicoll,__wcsicoll,__wcsicoll,__wcstoi64,IsWindow,SetParent,SetWindowLongW,SetParent,IsWindowVisible,IsIconic,SetWindowLongW,SetWindowLongW,SetWindowPos,InvalidateRect, | 1_2_00463410 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00439490 GetForegroundWindow,IsWindowVisible,GetWindowThreadProcessId,IsZoomed,IsIconic,GetWindowLongW,GetModuleHandleW,GetProcAddress, | 1_2_00439490 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0047A520 GetWindowThreadProcessId,GetWindowThreadProcessId,GetForegroundWindow,IsIconic,ShowWindow,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,SetForegroundWindow,SetForegroundWindow,GetForegroundWindow,GetWindow,AttachThreadInput,AttachThreadInput,BringWindowToTop, | 1_2_0047A520 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0046A590 SendMessageW,SendMessageW,SendMessageW,GetWindowLongW,IsWindowVisible,IsIconic,GetFocus,GetWindowRect,GetPropW,ShowWindow,GetUpdateRect,SendMessageW,GetWindowLongW,ShowWindow,EnableWindow,GetWindowRect,PtInRect,PtInRect,PtInRect,SetFocus,SendMessageW,SendMessageW,ShowWindow,SetFocus,InvalidateRect,InvalidateRect,InvalidateRect,MapWindowPoints,InvalidateRect, | 1_2_0046A590 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00466740 SetWindowTextW,IsZoomed,IsIconic,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,MulDiv,MulDiv,ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,GetWindowRect,GetWindowLongW,GetWindowRect,GetClientRect,IsWindowVisible,GetWindowLongW,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,SystemParametersInfoW,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow,GetDlgCtrlID,SetFocus, | 1_2_00466740 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00466740 SetWindowTextW,IsZoomed,IsIconic,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,MulDiv,MulDiv,ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,GetWindowRect,GetWindowLongW,GetWindowRect,GetClientRect,IsWindowVisible,GetWindowLongW,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,SystemParametersInfoW,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow,GetDlgCtrlID,SetFocus, | 1_2_00466740 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0043A7A0 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,GetDC,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,ReleaseDC,SelectObject,DeleteDC,DeleteObject,_free,GetPixel,ReleaseDC, | 1_2_0043A7A0 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0043D800 GetCursorPos,GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,WindowFromPoint,EnumChildWindows,_memset,EnumChildWindows,GetClassNameW,EnumChildWindows, | 1_2_0043D800 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0043C970 SendMessageW,SendMessageW,SendMessageW,IsWindowVisible,ShowWindow,ShowWindow,IsIconic,ShowWindow,GetForegroundWindow,SetForegroundWindow,SendMessageW, | 1_2_0043C970 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00477AB0 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen, | 1_2_00477AB0 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_00477B10 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen, | 1_2_00477B10 |
Source: C:\Users\user\AppData\Local\Temp\aaa.exe | Code function: 1_2_0043AFB0 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,_wcsrchr,__wcsicoll,__wcsicoll,__wcsicoll,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,__wcsnicmp,__fassign,__wcsnicmp,_wcsncpy,__fassign,__fassign,__fassign,__fassign,GetDC,DestroyIcon,DeleteObject,DeleteObject,GetIconInfo,DeleteObject,DeleteObject,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,ReleaseDC,DeleteObject,SelectObject,DeleteDC,DeleteObject,_free,_free,_free, | 1_2_0043AFB0 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00460170 MulDiv,MulDiv,MulDiv,_wcschr,__wcsicoll,MulDiv,MulDiv,MulDiv,GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,MulDiv,MulDiv,GetDC,SelectObject,GetTextMetricsW,GetSystemMetrics,GetDC,SelectObject,GetTextMetricsW,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,_wcschr,DrawTextW,DrawTextW,GetCharABCWidthsW,MulDiv,GetSystemMetrics,GetSystemMetrics,MulDiv,MulDiv,MulDiv,MulDiv,GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,IsWindowVisible,IsIconic,GetWindowLongW,GetPropW,MapWindowPoints,GetWindowLongW,SendMessageW,CreateWindowExW,CreateWindowExW,CreateWindowExW,CreateWindowExW,GetWindowLongW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,CreateWindowExW,SendMessageW,CreateWindowExW,SendMessageW,SendMessageW,MulDiv,MulDiv,MulDiv,MoveWindow,SelectObject,ReleaseDC,SendMessageW,SendMessageW,GetClientRect,SetWindowLongW,SendMessageW,SetWindowLongW,MoveWindow,GetWindowRect,SendMessageW,SetWindowPos,GetWindowRect,MapWindowPoints,InvalidateRect,SetWindowPos,SetWindowPos,MapWindowPoints, | 2_2_00460170 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00453120 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,CreateDCW,GetDC,GetPixel,DeleteDC,ReleaseDC, | 2_2_00453120 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0047A3E0 GetForegroundWindow,IsWindowVisible,IsIconic,ShowWindow, | 2_2_0047A3E0 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00463410 GetWindowLongW,GetWindowLongW,GetWindowLongW,__wcsnicmp,__wcsnicmp,__wcsicoll,SetWindowPos,__wcsicoll,__wcsicoll,__wcsnicmp,__wcsicoll,__wcsicoll,__wcsicoll,EnableWindow,__wcsnicmp,__wcsnicmp,__wcsicoll,__wcsicoll,__wcsicoll,__wcsnicmp,MulDiv,MulDiv,__wcsnicmp,MulDiv,MulDiv,__wcsicoll,__wcsicoll,__wcsicoll,__wcsicoll,__wcsicoll,__wcsicoll,__wcstoi64,IsWindow,SetParent,SetWindowLongW,SetParent,IsWindowVisible,IsIconic,SetWindowLongW,SetWindowLongW,SetWindowPos,InvalidateRect, | 2_2_00463410 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00439490 GetForegroundWindow,IsWindowVisible,GetWindowThreadProcessId,IsZoomed,IsIconic,GetWindowLongW,GetModuleHandleW,GetProcAddress, | 2_2_00439490 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0047A520 GetWindowThreadProcessId,GetWindowThreadProcessId,GetForegroundWindow,IsIconic,ShowWindow,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,SetForegroundWindow,SetForegroundWindow,GetForegroundWindow,GetWindow,AttachThreadInput,AttachThreadInput,BringWindowToTop, | 2_2_0047A520 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0046A590 SendMessageW,SendMessageW,SendMessageW,GetWindowLongW,IsWindowVisible,IsIconic,GetFocus,GetWindowRect,GetPropW,ShowWindow,GetUpdateRect,SendMessageW,GetWindowLongW,ShowWindow,EnableWindow,GetWindowRect,PtInRect,PtInRect,PtInRect,SetFocus,SendMessageW,SendMessageW,ShowWindow,SetFocus,InvalidateRect,InvalidateRect,InvalidateRect,MapWindowPoints,InvalidateRect, | 2_2_0046A590 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00466740 SetWindowTextW,IsZoomed,IsIconic,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,MulDiv,MulDiv,ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,GetWindowRect,GetWindowLongW,GetWindowRect,GetClientRect,IsWindowVisible,GetWindowLongW,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,SystemParametersInfoW,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow,GetDlgCtrlID,SetFocus, | 2_2_00466740 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00466740 SetWindowTextW,IsZoomed,IsIconic,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,__wcsnicmp,MulDiv,MulDiv,ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,GetWindowRect,GetWindowLongW,GetWindowRect,GetClientRect,IsWindowVisible,GetWindowLongW,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,SystemParametersInfoW,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow,GetDlgCtrlID,SetFocus, | 2_2_00466740 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0043A7A0 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,GetDC,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,ReleaseDC,SelectObject,DeleteDC,DeleteObject,_free,GetPixel,ReleaseDC, | 2_2_0043A7A0 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0043D800 GetCursorPos,GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,WindowFromPoint,EnumChildWindows,_memset,EnumChildWindows,GetClassNameW,EnumChildWindows, | 2_2_0043D800 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0043C970 SendMessageW,SendMessageW,SendMessageW,IsWindowVisible,ShowWindow,ShowWindow,IsIconic,ShowWindow,GetForegroundWindow,SetForegroundWindow,SendMessageW, | 2_2_0043C970 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00477AB0 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen, | 2_2_00477AB0 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_00477B10 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen, | 2_2_00477B10 |
Source: C:\Users\user\AppData\Local\Temp\bbb.exe | Code function: 2_2_0043AFB0 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,_wcsrchr,__wcsicoll,__wcsicoll,__wcsicoll,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,__wcsnicmp,__fassign,__wcsnicmp,_wcsncpy,__fassign,__fassign,__fassign,__fassign,GetDC,DestroyIcon,DeleteObject,DeleteObject,GetIconInfo,DeleteObject,DeleteObject,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,ReleaseDC,DeleteObject,SelectObject,DeleteDC,DeleteObject,_free,_free,_free, | 2_2_0043AFB0 |