Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D86B3 NtSetInformationThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D0782 EnumWindows,NtSetInformationThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D0A8B NtSetInformationThread,NtWriteVirtualMemory,TerminateProcess, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D8E42 NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D365C NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D9440 NtResumeThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D23B6 NtSetInformationThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D80E3 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D082B NtSetInformationThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D085F NtSetInformationThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D08BB NtSetInformationThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D08FB NtSetInformationThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D0953 NtSetInformationThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D4C71 NtWriteVirtualMemory,LoadLibraryA, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D963B NtResumeThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D9607 NtResumeThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D96DB NtResumeThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D36D3 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D977B NtResumeThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D974B NtResumeThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D3754 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D37B8 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D97B0 NtResumeThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D9473 NtResumeThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D94D7 NtResumeThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D9567 NtResumeThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D3A90 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D3ADF NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D3B4C NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D983B NtResumeThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D3812 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D3873 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D98B4 NtResumeThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D38B3 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D3914 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D3978 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D99AF NtResumeThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D3C7F NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D3CD7 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D3D87 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9A20 NtResumeThread,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9A00 NtProtectVirtualMemory,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9660 NtAllocateVirtualMemory,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9A50 NtCreateFile,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E96E0 NtFreeVirtualMemory,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9710 NtQueryInformationToken,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E97A0 NtUnmapViewOfSection,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9780 NtMapViewOfSection,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9860 NtQuerySystemInformation,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9840 NtDelayExecution,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E98F0 NtReadVirtualMemory,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9910 NtAdjustPrivilegesToken,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9540 NtReadFile,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E99A0 NtCreateSection,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E95D0 NtClose,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9610 NtEnumerateValueKey, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9A10 NtQuerySection, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9670 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9650 NtQueryValueKey, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9A80 NtOpenDirectoryObject, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E96D0 NtCreateKey, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9730 NtQueryVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3EA710 NtOpenProcessToken, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9B00 NtSetValueKey, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9770 NtSetInformationFile, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3EA770 NtOpenThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9760 NtOpenProcess, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3EA3B0 NtGetContextThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9FE0 NtCreateMutant, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9820 NtEnumerateKey, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3EB040 NtSuspendThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E98A0 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3EAD30 NtSetContextThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9520 NtWaitForSingleObject, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9560 NtWriteFile, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E9950 NtQueueApcThread, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E95F0 NtQueryInformationFile, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E99D0 NtCreateProcessEx, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_00563104 TerminateThread,LdrInitializeThunk,NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_00563198 RtlAddVectoredExceptionHandler,NtProtectVirtualMemory,LdrInitializeThunk,NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_0056431B Sleep,NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_0056447A LdrInitializeThunk,NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_00568E42 NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_0056308C TerminateThread,LdrInitializeThunk,NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_0056318B LdrInitializeThunk,NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_005643C6 NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_00564461 LdrInitializeThunk,NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_00564469 LdrInitializeThunk,NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_005644EF LdrInitializeThunk,NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_005644B3 LdrInitializeThunk,NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_00564587 LdrInitializeThunk,NtProtectVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0015B42E NtOpenThreadToken,NtOpenProcessToken,NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_001584BE NtQueryVolumeInformationFile,GetFileInformationByHandleEx, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_001558A4 _setjmp3,NtQueryInformationProcess,NtSetInformationProcess,NtSetInformationProcess,longjmp, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0015B4C0 NtQueryInformationToken, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0015B4F8 NtQueryInformationToken,NtQueryInformationToken, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_00176D90 EnterCriticalSection,LeaveCriticalSection,fprintf,fflush,TryAcquireSRWLockExclusive,NtCancelSynchronousIoFile,ReleaseSRWLockExclusive,_get_osfhandle,FlushConsoleInputBuffer, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0017B5E0 SetLastError,CreateDirectoryW,CreateFileW,RtlDosPathNameToNtPathName_U,memset,memcpy,memcpy,NtFsControlFile,RtlNtStatusToDosError,SetLastError,CloseHandle,RtlFreeHeap,RemoveDirectoryW, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_00179AB4 NtSetInformationFile, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_001583F2 RtlDosPathNameToRelativeNtPathName_U_WithStatus,NtOpenFile,RtlReleaseRelativeName,RtlFreeUnicodeString,CloseHandle,DeleteFileW,GetLastError, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9710 NtQueryInformationToken,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9780 NtMapViewOfSection,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9FE0 NtCreateMutant,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9A50 NtCreateFile,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F96D0 NtCreateKey,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F96E0 NtFreeVirtualMemory,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9910 NtAdjustPrivilegesToken,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9540 NtReadFile,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F99A0 NtCreateSection,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F95D0 NtClose,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9840 NtDelayExecution,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9860 NtQuerySystemInformation,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9B00 NtSetValueKey, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030FA710 NtOpenProcessToken, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030EE730 NtQueryInformationProcess, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B9335 NtClose,NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9730 NtQueryVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F7742 NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9760 NtOpenProcess, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03137365 NtQuerySystemInformation, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0314176C NtWaitForSingleObject,NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0317FF69 NtQueryVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9770 NtSetInformationFile, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030FA770 NtOpenThread, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C8F87 NtProtectVirtualMemory,NtProtectVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0313FB88 NtProtectVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F97A0 NtUnmapViewOfSection, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BA7B0 NtClose,NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03185BA5 NtQueryInformationToken, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030FA3B0 NtGetContextThread, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0317AFDE NtFreeVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0317F7DD NtFreeVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BF7C0 NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03166BEA NtQueryVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BC600 NtQueryValueKey,NtQueryValueKey, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9A00 NtProtectVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F2E1C NtDelayExecution, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0317F209 NtFreeVirtualMemory,NtFreeVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9610 NtEnumerateValueKey, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9A10 NtQuerySection, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BE620 NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9A20 NtResumeThread, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0317EE22 NtFreeVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B9240 NtClose,NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03141242 NtUnmapViewOfSection,NtClose,NtClose,NtClose,NtClose,NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9650 NtQueryValueKey, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030EBE62 NtProtectVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9660 NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03137E63 NtProtectVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9670 NtQueryInformationProcess, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0316BE9B NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9A80 NtOpenDirectoryObject, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B2E9F NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030ED294 NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B52A5 NtClose,NtClose,NtClose,NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03180EA5 NtQueryVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03141AD6 NtFreeVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030D4120 NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9520 NtWaitForSingleObject, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0316FD22 NtQueryInformationProcess, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C9136 NtProtectVirtualMemory,NtProtectVirtualMemory,NtProtectVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030EC532 NtProtectVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030FAD30 NtSetContextThread, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030E0548 NtQueryVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03181D55 NtFreeVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03133540 NtQueryValueKey,NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9950 NtQueueApcThread, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03141570 NtQuerySystemInformation,NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9560 NtWriteFile, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B2D8A NtWaitForSingleObject, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030CDD80 NtQueryVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_031419C8 NtCreateSection,NtMapViewOfSection,NtUnmapViewOfSection,NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F99D0 NtCreateProcessEx, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0316BDFA NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F95F0 NtQueryInformationFile, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F9820 NtEnumerateKey, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0314C450 NtAdjustPrivilegesToken,NtClose,NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030FB040 NtSuspendThread, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03141C49 NtQueryInformationProcess, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030D746D NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03141C76 NtQueryInformationProcess, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03141879 NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03133884 NtQueryValueKey,NtQueryValueKey, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F98A0 NtWriteVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BDCA4 NtEnumerateKey,NtClose,NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030EF0BF NtClose,NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0314B8D0 NtAdjustPrivilegesToken,NtAdjustPrivilegesToken,NtClose,NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0317F8C5 NtFreeVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03137CF9 NtQueryVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03141CE4 NtQueryInformationProcess, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C80FC NtMapViewOfSection,NtUnmapViewOfSection, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F98F0 NtReadVirtualMemory, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_02F39E80 NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_02F39E00 NtReadFile, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_02F39D50 NtCreateFile, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_02F39E7B NtReadFile, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_02F39E7D NtClose, |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_02F39DA2 NtCreateFile, |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D86B3 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D23B6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D41B2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D86DF mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D874B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D878B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D2B4E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D2EF7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D2EC7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D6D7F mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 1_2_022D7955 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E4A2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E4A2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E434257 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3AE620 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3C3A1C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DA61C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DA61C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E45B260 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E45B260 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E478A62 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A5210 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A5210 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A5210 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A5210 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3AAA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3AAA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B8A0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3AC600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3AC600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3AC600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D8E00 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E927A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E461608 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3CAE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3CAE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3CAE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3CAE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3CAE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B766D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A9240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A9240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A9240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A9240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E45FE3F mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B7E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B7E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B7E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B7E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B7E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B7E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E45FEC0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3BAAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3BAAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DFAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E478ED6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A52A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A52A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A52A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A52A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A52A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DD294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DD294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E43FE87 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B76E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D2AE4 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D16E0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E470EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E470EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E470EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E4246A7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D36CC mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D2ACB mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E8EC7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DE730 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A4F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A4F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E478B58 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3CF716 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E478F6A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DA70E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DA70E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D3B7A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D3B7A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E47070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E47070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E43FF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E43FF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3ADB60 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3BFF60 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E46131B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3AF358 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3ADB40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3BEF40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E4253CA mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E4253CA mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D4BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D4BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D4BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D2397 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DB390 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B8794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B1B8F mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B1B8F mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E45D380 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E37F5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E46138A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3CDBE9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E427794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E427794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E427794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D03E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D03E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D03E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D03E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D03E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D03E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E475BA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3BB02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3BB02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3BB02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3BB02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DBC2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E43C450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E43C450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E471074 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E462073 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E461C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E461C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E461C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E461C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E461C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E461C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E461C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E461C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E461C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E461C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E461C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E461C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E461C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E461C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E426C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E426C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E426C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E426C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E47740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E47740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E47740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3C746D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E474015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E474015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E427016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E427016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E427016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3C0050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3C0050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DA44B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DF0BF mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DF0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DF0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E478CD6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E90AF mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E43B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E43B8D0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E43B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E43B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E43B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E43B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D20A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D20A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D20A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D20A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D20A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D20A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B849B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E426CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E426CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E426CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A9080 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E4614FB mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E423884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E423884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A58EC mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E423540 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D4D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D4D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D4D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3AAD30 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3B3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3C4120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3C4120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3C4120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3C4120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3C4120 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A9100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A9100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A9100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3AB171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3AB171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3CC577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3CC577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3AC962 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3C7D50 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E478D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E42A537 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3CB944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3CB944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3E3D43 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D1DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D1DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D1DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E426DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E426DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E426DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E426DC9 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E426DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E426DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D35A1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D61A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D61A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DFD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DFD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E4341E8 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D2990 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A2D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A2D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A2D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A2D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3A2D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E458DF1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3DA185 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D2581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D2581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D2581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3D2581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3CC182 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3AB1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3AB1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3AB1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3BD5E0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E3BD5E0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E4269A6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E4705AC mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E4705AC mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E4251BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E4251BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E4251BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_1E4251BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_005641AF mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_005686DF mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_005686B3 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_0056874B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_0056878B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_00567955 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\AWB# 9284730932.exe | Code function: 11_2_00566D7F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0017B5E0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0314FF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0314FF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0317131B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0318070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0318070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B4F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B4F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030EE730 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03188B58 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BDB40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030CEF40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BF358 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BDB60 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030CFF60 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03188F6A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030E3B7A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030E3B7A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C1B8F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C1B8F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03137794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03137794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03137794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0316D380 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0317138A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030EB390 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03185BA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BC600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BC600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BC600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030D3A1C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0316FE3F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BE620 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B9240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B9240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B9240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B9240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C7E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C7E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C7E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C7E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C7E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C7E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C766D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F927A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0316B260 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0316B260 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03188A62 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030DAE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030DAE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030DAE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030DAE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030DAE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0314FE87 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030ED294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030ED294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B52A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B52A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B52A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B52A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B52A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_031346A7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03180EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03180EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03180EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030EFAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030E36CC mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F8EC7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03188ED6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0316FEC0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030E16E0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C76E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B9100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B9100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B9100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03188D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030D4120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030D4120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030D4120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030D4120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030D4120 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030E513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030E513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030E4D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030E4D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030E4D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030C3D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BAD30 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030DB944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030DB944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F3D43 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03133540 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030D7D50 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BB171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BB171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030DC577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030DC577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B2D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B2D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B2D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B2D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B2D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030EA185 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030DC182 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030EFD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030EFD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030E35A1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03168DF1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BB1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BB1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030BB1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03137016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03137016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03137016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03184015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03184015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03171C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03171C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03171C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03171C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03171C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03171C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03171C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03171C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03171C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03171C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03171C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03171C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03171C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03171C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0318740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0318740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0318740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03136C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03136C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03136C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03136C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030EBC2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030CB02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030CB02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030CB02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030CB02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0314C450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0314C450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030D0050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030D0050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030D746D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03172073 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03181074 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030B9080 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03133884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03133884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030F90AF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030EF0BF mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030EF0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_030EF0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0314B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0314B8D0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0314B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0314B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0314B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_0314B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03188CD6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03136CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03136CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_03136CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\cmd.exe | Code function: 14_2_031714FB mov eax, dword ptr fs:[00000030h] |