Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Code function: 0_2_0040C898 | 0_2_0040C898 |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Code function: 0_2_0040E950 | 0_2_0040E950 |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Code function: 0_2_00410910 | 0_2_00410910 |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Code function: 0_2_004109D9 | 0_2_004109D9 |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Code function: 0_2_004105E0 | 0_2_004105E0 |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Code function: 0_2_00411580 | 0_2_00411580 |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Code function: 0_2_00410993 | 0_2_00410993 |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Code function: 0_2_00410600 | 0_2_00410600 |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Code function: 0_2_0040B347 | 0_2_0040B347 |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Code function: 0_2_0040F3C8 | 0_2_0040F3C8 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014001E300 | 5_2_000000014001E300 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014001EB20 | 5_2_000000014001EB20 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014000CF40 | 5_2_000000014000CF40 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140005220 | 5_2_0000000140005220 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014001F2F0 | 5_2_000000014001F2F0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014001F909 | 5_2_000000014001F909 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140055940 | 5_2_0000000140055940 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140001B0C | 5_2_0000000140001B0C |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014001FD0E | 5_2_000000014001FD0E |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140124000 | 5_2_0000000140124000 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014007C02F | 5_2_000000014007C02F |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140070050 | 5_2_0000000140070050 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400D8064 | 5_2_00000001400D8064 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140028110 | 5_2_0000000140028110 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014000A110 | 5_2_000000014000A110 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140050125 | 5_2_0000000140050125 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014005C130 | 5_2_000000014005C130 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014004C150 | 5_2_000000014004C150 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140058190 | 5_2_0000000140058190 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400741B0 | 5_2_00000001400741B0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400761F0 | 5_2_00000001400761F0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140080220 | 5_2_0000000140080220 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014005E240 | 5_2_000000014005E240 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014009824C | 5_2_000000014009824C |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014002A2B0 | 5_2_000000014002A2B0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400A82E0 | 5_2_00000001400A82E0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140088350 | 5_2_0000000140088350 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014006E370 | 5_2_000000014006E370 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140050394 | 5_2_0000000140050394 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400523A0 | 5_2_00000001400523A0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140040400 | 5_2_0000000140040400 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140048480 | 5_2_0000000140048480 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400BA52B | 5_2_00000001400BA52B |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014000A530 | 5_2_000000014000A530 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014007A560 | 5_2_000000014007A560 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400CE58C | 5_2_00000001400CE58C |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014008E5A0 | 5_2_000000014008E5A0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400605A9 | 5_2_00000001400605A9 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400DC5EC | 5_2_00000001400DC5EC |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140058650 | 5_2_0000000140058650 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400BC660 | 5_2_00000001400BC660 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140074670 | 5_2_0000000140074670 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140020670 | 5_2_0000000140020670 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140032671 | 5_2_0000000140032671 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140098691 | 5_2_0000000140098691 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400466B0 | 5_2_00000001400466B0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014008C6B3 | 5_2_000000014008C6B3 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140054720 | 5_2_0000000140054720 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014004A730 | 5_2_000000014004A730 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400BA750 | 5_2_00000001400BA750 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400D07A0 | 5_2_00000001400D07A0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400027BB | 5_2_00000001400027BB |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400507C0 | 5_2_00000001400507C0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014007E820 | 5_2_000000014007E820 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400448C0 | 5_2_00000001400448C0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014007A8D0 | 5_2_000000014007A8D0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014006C8E0 | 5_2_000000014006C8E0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400A28F0 | 5_2_00000001400A28F0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140064940 | 5_2_0000000140064940 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014009899D | 5_2_000000014009899D |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400929B0 | 5_2_00000001400929B0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140034A05 | 5_2_0000000140034A05 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014008EA10 | 5_2_000000014008EA10 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140018A10 | 5_2_0000000140018A10 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140062A50 | 5_2_0000000140062A50 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140012A80 | 5_2_0000000140012A80 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140070AC0 | 5_2_0000000140070AC0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014005AB60 | 5_2_000000014005AB60 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140060B70 | 5_2_0000000140060B70 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140014B90 | 5_2_0000000140014B90 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014003EBB0 | 5_2_000000014003EBB0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400DCBD0 | 5_2_00000001400DCBD0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140084BF0 | 5_2_0000000140084BF0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400D4C08 | 5_2_00000001400D4C08 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014009CC40 | 5_2_000000014009CC40 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140006C50 | 5_2_0000000140006C50 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014008CC80 | 5_2_000000014008CC80 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014005CC80 | 5_2_000000014005CC80 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140034C95 | 5_2_0000000140034C95 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400B0CC0 | 5_2_00000001400B0CC0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014004ECC0 | 5_2_000000014004ECC0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140056CD0 | 5_2_0000000140056CD0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140010CE0 | 5_2_0000000140010CE0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014009ECF0 | 5_2_000000014009ECF0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014005ED20 | 5_2_000000014005ED20 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140058D60 | 5_2_0000000140058D60 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140016D80 | 5_2_0000000140016D80 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014004ADB0 | 5_2_000000014004ADB0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400AEE20 | 5_2_00000001400AEE20 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140038E1C | 5_2_0000000140038E1C |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014007CE38 | 5_2_000000014007CE38 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140070E5D | 5_2_0000000140070E5D |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140050E80 | 5_2_0000000140050E80 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140062EC0 | 5_2_0000000140062EC0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014008EF6D | 5_2_000000014008EF6D |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014008EF7C | 5_2_000000014008EF7C |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014008EF98 | 5_2_000000014008EF98 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014008EFBA | 5_2_000000014008EFBA |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014008EFDB | 5_2_000000014008EFDB |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014005EFF0 | 5_2_000000014005EFF0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014008EFE7 | 5_2_000000014008EFE7 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014008F00D | 5_2_000000014008F00D |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140073040 | 5_2_0000000140073040 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140099038 | 5_2_0000000140099038 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014008F04E | 5_2_000000014008F04E |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140087081 | 5_2_0000000140087081 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014005B0A0 | 5_2_000000014005B0A0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400B70D0 | 5_2_00000001400B70D0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400910F8 | 5_2_00000001400910F8 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014003F120 | 5_2_000000014003F120 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014007B13E | 5_2_000000014007B13E |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140025144 | 5_2_0000000140025144 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140089170 | 5_2_0000000140089170 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140065170 | 5_2_0000000140065170 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400531A0 | 5_2_00000001400531A0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400431A0 | 5_2_00000001400431A0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400031B4 | 5_2_00000001400031B4 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014006F1C0 | 5_2_000000014006F1C0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014004D1F0 | 5_2_000000014004D1F0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400C7210 | 5_2_00000001400C7210 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140019220 | 5_2_0000000140019220 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140069240 | 5_2_0000000140069240 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400352D6 | 5_2_00000001400352D6 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400972F0 | 5_2_00000001400972F0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140099315 | 5_2_0000000140099315 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400AB380 | 5_2_00000001400AB380 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014001B400 | 5_2_000000014001B400 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400AD410 | 5_2_00000001400AD410 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140017450 | 5_2_0000000140017450 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014003F4C0 | 5_2_000000014003F4C0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400394F0 | 5_2_00000001400394F0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014005D510 | 5_2_000000014005D510 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140085520 | 5_2_0000000140085520 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014004B540 | 5_2_000000014004B540 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400575A0 | 5_2_00000001400575A0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400D5594 | 5_2_00000001400D5594 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400315BC | 5_2_00000001400315BC |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400415C0 | 5_2_00000001400415C0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014008B6E0 | 5_2_000000014008B6E0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400516F0 | 5_2_00000001400516F0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400CD700 | 5_2_00000001400CD700 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014004F705 | 5_2_000000014004F705 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014006D720 | 5_2_000000014006D720 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400D1714 | 5_2_00000001400D1714 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400B1740 | 5_2_00000001400B1740 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140063740 | 5_2_0000000140063740 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014006B770 | 5_2_000000014006B770 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014004D770 | 5_2_000000014004D770 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400D57BC | 5_2_00000001400D57BC |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400937F0 | 5_2_00000001400937F0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014002B7F0 | 5_2_000000014002B7F0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014005F7F2 | 5_2_000000014005F7F2 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014003D830 | 5_2_000000014003D830 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014007D890 | 5_2_000000014007D890 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400498E0 | 5_2_00000001400498E0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014004B910 | 5_2_000000014004B910 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014000D9A0 | 5_2_000000014000D9A0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014004F9BC | 5_2_000000014004F9BC |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400619D0 | 5_2_00000001400619D0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014005B9D0 | 5_2_000000014005B9D0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400139F0 | 5_2_00000001400139F0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140033A78 | 5_2_0000000140033A78 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140039AE5 | 5_2_0000000140039AE5 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014004DB7B | 5_2_000000014004DB7B |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014002FBA0 | 5_2_000000014002FBA0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014000FBA0 | 5_2_000000014000FBA0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140095BCB | 5_2_0000000140095BCB |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140095BD9 | 5_2_0000000140095BD9 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014007FBF0 | 5_2_000000014007FBF0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140095BE4 | 5_2_0000000140095BE4 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140045C3B | 5_2_0000000140045C3B |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014007DC60 | 5_2_000000014007DC60 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140095CA0 | 5_2_0000000140095CA0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140049CB0 | 5_2_0000000140049CB0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014004BCB0 | 5_2_000000014004BCB0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140095CB9 | 5_2_0000000140095CB9 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140095CC1 | 5_2_0000000140095CC1 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140095CD7 | 5_2_0000000140095CD7 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140059D10 | 5_2_0000000140059D10 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140079DD0 | 5_2_0000000140079DD0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140097E20 | 5_2_0000000140097E20 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014009BE50 | 5_2_000000014009BE50 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140097F0B | 5_2_0000000140097F0B |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140045F5B | 5_2_0000000140045F5B |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140071F80 | 5_2_0000000140071F80 |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\USE INCASE OF A SEVERE FORKIE.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\mbr.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\meth.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\meth.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\meth.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\meth.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\meth.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\meth.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\meth.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\meth.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\meth.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: logoncontroller.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: windows.ui.logon.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wincorlib.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: windows.ui.xamlhost.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: mrmcorer.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: languageoverlayutil.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: bcp47mrm.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: windows.ui.xaml.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: windows.ui.immersive.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: d3d10warp.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: windows.globalization.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dxcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: d2d1.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: directmanipulation.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: windows.ui.xaml.controls.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: uiautomationcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: logoncontroller.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: logoncontroller.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: logoncontroller.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: logoncontroller.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\System32\LogonUI.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140050066 IsZoomed,IsIconic, | 5_2_0000000140050066 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140058650 GetCursorPos,GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,WindowFromPoint,EnumChildWindows,GetClassNameW,EnumChildWindows,malloc, | 5_2_0000000140058650 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140054720 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,GetSystemMetrics,GetSystemMetrics,wcsncpy,GetDC,DestroyIcon,DeleteObject,GetIconInfo,CreateCompatibleDC,DeleteObject,DeleteObject,CreateCompatibleDC,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,CreateCompatibleDC,malloc,ReleaseDC,DeleteObject,SelectObject,DeleteDC,DeleteObject,malloc, | 5_2_0000000140054720 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140096760 SetWindowTextW,IsZoomed,IsIconic,ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,IsWindowVisible,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,GetWindowLongW,GetWindowRect,GetClientRect,SystemParametersInfoW,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow,SetFocus, | 5_2_0000000140096760 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140096760 SetWindowTextW,IsZoomed,IsIconic,ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,IsWindowVisible,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,GetWindowLongW,GetWindowRect,GetClientRect,SystemParametersInfoW,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow,SetFocus, | 5_2_0000000140096760 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014009084D GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,IsWindowVisible,IsIconic,GetPropW,MapWindowPoints,GetWindowLongW,SendMessageW, | 5_2_000000014009084D |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014009085D MulDiv,GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,IsWindowVisible,IsIconic,GetPropW,MapWindowPoints,GetWindowLongW,SendMessageW, | 5_2_000000014009085D |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140090855 GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,IsWindowVisible,IsIconic,GetPropW,MapWindowPoints,GetWindowLongW,SendMessageW, | 5_2_0000000140090855 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014009086B MulDiv,GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,IsWindowVisible,IsIconic,GetPropW,MapWindowPoints,GetWindowLongW,SendMessageW, | 5_2_000000014009086B |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014009688B ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,IsWindowVisible,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow, | 5_2_000000014009688B |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140096881 ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,IsWindowVisible,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow, | 5_2_0000000140096881 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400908AF MulDiv,GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,IsWindowVisible,IsIconic,GetPropW,MapWindowPoints,GetWindowLongW,SendMessageW, | 5_2_00000001400908AF |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400448C0 IsWindow,DestroyWindow,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetDesktopWindow,GetWindowRect,GetCursorPos,GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,IsWindow,CreateWindowExW,SendMessageW,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetWindowRect,SendMessageW,SendMessageW, | 5_2_00000001400448C0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400968B6 ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,IsWindowVisible,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow, | 5_2_00000001400968B6 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400968E8 ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,IsWindowVisible,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow, | 5_2_00000001400968E8 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400908E7 GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,IsWindowVisible,IsIconic,GetPropW,MapWindowPoints,GetWindowLongW,SendMessageW, | 5_2_00000001400908E7 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400908F6 GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,IsWindowVisible,IsIconic,GetPropW,MapWindowPoints,GetWindowLongW,SendMessageW, | 5_2_00000001400908F6 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014009693A ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,IsWindowVisible,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow, | 5_2_000000014009693A |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014009698C ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,IsWindowVisible,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow, | 5_2_000000014009698C |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400569A0 SendMessageW,IsWindowVisible,ShowWindow,IsIconic,ShowWindow,GetForegroundWindow,SetForegroundWindow,SendMessageW, | 5_2_00000001400569A0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400929B0 GetWindowLongW,GetWindowLongW,SetWindowPos,EnableWindow,GetWindowRect,GetClientRect,MulDiv,MulDiv,GetWindowRect,GetClientRect,MulDiv,MulDiv,_wcstoi64,IsWindow,SetParent,SetWindowLongPtrW,SetParent,IsWindowVisible,IsIconic,SetWindowLongW,SetWindowLongW,SetWindowPos,InvalidateRect, | 5_2_00000001400929B0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400969B7 MulDiv,MulDiv,ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,IsWindowVisible,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow, | 5_2_00000001400969B7 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014008EA10 SendMessageW,MulDiv,MulDiv,COMRefPtr,MulDiv,GetDC,SelectObject,GetTextMetricsW,MulDiv,GetDC,SelectObject,GetTextMetricsW,GetSystemMetrics,GetDC,SelectObject,GetTextMetricsW,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,DrawTextW,DrawTextW,GetCharABCWidthsW,MulDiv,GetSystemMetrics,GetSystemMetrics,MulDiv,GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,IsWindowVisible,IsIconic,GetPropW,MapWindowPoints,GetWindowLongW,SendMessageW,SelectObject,ReleaseDC,SendMessageW,SendMessageW,GetClientRect,SetWindowLongW,SendMessageW,SetWindowLongW,MoveWindow,GetWindowRect,SendMessageW,GetWindowRect,MapWindowPoints,InvalidateRect,SetWindowPos,SetWindowPos,MapWindowPoints, | 5_2_000000014008EA10 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400B0AE0 GetForegroundWindow,IsWindowVisible,IsIconic,ShowWindow, | 5_2_00000001400B0AE0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_000000014009CC40 SendMessageW,GetWindowLongW,IsWindowVisible,IsIconic,GetFocus,GetWindowRect,GetPropW,ShowWindow,GetUpdateRect,SendMessageW,GetWindowLongW,ShowWindow,EnableWindow,GetWindowRect,PtInRect,PtInRect,SetFocus,SendMessageW,ShowWindow,SetFocus,InvalidateRect,MapWindowPoints,InvalidateRect, | 5_2_000000014009CC40 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400B0CC0 GetWindowThreadProcessId,GetForegroundWindow,IsIconic,ShowWindow,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,BringWindowToTop, | 5_2_00000001400B0CC0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140068FE0 GetTickCount,GetForegroundWindow,GetTickCount,GetWindowThreadProcessId,GetGUIThreadInfo,ClientToScreen,GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,_itow, | 5_2_0000000140068FE0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400531A0 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,GetDC,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,CreateCompatibleDC,malloc,ReleaseDC,SelectObject,DeleteDC,DeleteObject,malloc,GetPixel,ReleaseDC,malloc,malloc, | 5_2_00000001400531A0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400AD2F0 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen, | 5_2_00000001400AD2F0 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_00000001400A1410 CheckMenuItem,CheckMenuItem,GetCursorPos,GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,GetForegroundWindow,GetWindowThreadProcessId,SetForegroundWindow,SetForegroundWindow,TrackPopupMenuEx,PostMessageW,GetForegroundWindow,SetForegroundWindow, | 5_2_00000001400A1410 |
Source: C:\Users\user\AppData\Roaming\meth.exe | Code function: 5_2_0000000140079DD0 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,CreateDCW,GetDC,GetPixel,DeleteDC,ReleaseDC,malloc,malloc, | 5_2_0000000140079DD0 |