Source: C:\Users\user\Desktop\kayx.exe |
Code function: 1_2_05C4AAF0 NtUnmapViewOfSection, |
1_2_05C4AAF0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 1_2_05C4AAE8 NtUnmapViewOfSection, |
1_2_05C4AAE8 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00417B90 NtCreateFile, |
17_2_00417B90 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00417C40 NtReadFile, |
17_2_00417C40 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00417CC0 NtClose, |
17_2_00417CC0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00417D70 NtAllocateVirtualMemory, |
17_2_00417D70 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00417B4A NtCreateFile, |
17_2_00417B4A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00417BE2 NtCreateFile, |
17_2_00417BE2 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00417B8A NtCreateFile, |
17_2_00417B8A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00417CBF NtClose, |
17_2_00417CBF |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E498F0 NtReadVirtualMemory,LdrInitializeThunk, |
17_2_00E498F0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49860 NtQuerySystemInformation,LdrInitializeThunk, |
17_2_00E49860 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49840 NtDelayExecution,LdrInitializeThunk, |
17_2_00E49840 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E499A0 NtCreateSection,LdrInitializeThunk, |
17_2_00E499A0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49910 NtAdjustPrivilegesToken,LdrInitializeThunk, |
17_2_00E49910 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49A50 NtCreateFile,LdrInitializeThunk, |
17_2_00E49A50 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49A20 NtResumeThread,LdrInitializeThunk, |
17_2_00E49A20 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49A00 NtProtectVirtualMemory,LdrInitializeThunk, |
17_2_00E49A00 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E495D0 NtClose,LdrInitializeThunk, |
17_2_00E495D0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49540 NtReadFile,LdrInitializeThunk, |
17_2_00E49540 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E496E0 NtFreeVirtualMemory,LdrInitializeThunk, |
17_2_00E496E0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49660 NtAllocateVirtualMemory,LdrInitializeThunk, |
17_2_00E49660 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49FE0 NtCreateMutant,LdrInitializeThunk, |
17_2_00E49FE0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E497A0 NtUnmapViewOfSection,LdrInitializeThunk, |
17_2_00E497A0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49780 NtMapViewOfSection,LdrInitializeThunk, |
17_2_00E49780 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49710 NtQueryInformationToken,LdrInitializeThunk, |
17_2_00E49710 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E498A0 NtWriteVirtualMemory, |
17_2_00E498A0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E4B040 NtSuspendThread, |
17_2_00E4B040 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49820 NtEnumerateKey, |
17_2_00E49820 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E499D0 NtCreateProcessEx, |
17_2_00E499D0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49950 NtQueueApcThread, |
17_2_00E49950 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49A80 NtOpenDirectoryObject, |
17_2_00E49A80 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49A10 NtQuerySection, |
17_2_00E49A10 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E4A3B0 NtGetContextThread, |
17_2_00E4A3B0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49B00 NtSetValueKey, |
17_2_00E49B00 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E495F0 NtQueryInformationFile, |
17_2_00E495F0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49560 NtWriteFile, |
17_2_00E49560 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49520 NtWaitForSingleObject, |
17_2_00E49520 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E4AD30 NtSetContextThread, |
17_2_00E4AD30 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E496D0 NtCreateKey, |
17_2_00E496D0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49670 NtQueryInformationProcess, |
17_2_00E49670 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49650 NtQueryValueKey, |
17_2_00E49650 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49610 NtEnumerateValueKey, |
17_2_00E49610 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49760 NtOpenProcess, |
17_2_00E49760 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49770 NtSetInformationFile, |
17_2_00E49770 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E4A770 NtOpenThread, |
17_2_00E4A770 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E49730 NtQueryVirtualMemory, |
17_2_00E49730 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E4A710 NtOpenProcessToken, |
17_2_00E4A710 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_1_00417B90 NtCreateFile, |
17_1_00417B90 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_1_00417C40 NtReadFile, |
17_1_00417C40 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_1_00417CC0 NtClose, |
17_1_00417CC0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_1_00417D70 NtAllocateVirtualMemory, |
17_1_00417D70 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_1_00417B4A NtCreateFile, |
17_1_00417B4A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_1_00417BE2 NtCreateFile, |
17_1_00417BE2 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_1_00417B8A NtCreateFile, |
17_1_00417B8A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_1_00417CBF NtClose, |
17_1_00417CBF |
Source: 00000015.00000002.485444810.0000000002F00000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000015.00000002.485444810.0000000002F00000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000011.00000002.396099862.0000000000830000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000011.00000002.396099862.0000000000830000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000011.00000002.396027525.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000011.00000002.396027525.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000015.00000002.484279657.0000000000A00000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000015.00000002.484279657.0000000000A00000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000011.00000002.396259639.0000000000980000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000011.00000002.396259639.0000000000980000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000011.00000001.351516494.0000000000400000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000011.00000001.351516494.0000000000400000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000001.00000002.352630853.00000000041E1000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000001.00000002.352630853.00000000041E1000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 17.2.kayx.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 17.2.kayx.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 17.1.kayx.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 17.1.kayx.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 17.1.kayx.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 17.1.kayx.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 17.2.kayx.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 17.2.kayx.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\noteped\firefoxe.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\mstsc.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E040E1 mov eax, dword ptr fs:[00000030h] |
17_2_00E040E1 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E040E1 mov eax, dword ptr fs:[00000030h] |
17_2_00E040E1 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E040E1 mov eax, dword ptr fs:[00000030h] |
17_2_00E040E1 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E058EC mov eax, dword ptr fs:[00000030h] |
17_2_00E058EC |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E9B8D0 mov eax, dword ptr fs:[00000030h] |
17_2_00E9B8D0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E9B8D0 mov ecx, dword ptr fs:[00000030h] |
17_2_00E9B8D0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E9B8D0 mov eax, dword ptr fs:[00000030h] |
17_2_00E9B8D0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E9B8D0 mov eax, dword ptr fs:[00000030h] |
17_2_00E9B8D0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E9B8D0 mov eax, dword ptr fs:[00000030h] |
17_2_00E9B8D0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E9B8D0 mov eax, dword ptr fs:[00000030h] |
17_2_00E9B8D0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E320A0 mov eax, dword ptr fs:[00000030h] |
17_2_00E320A0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E320A0 mov eax, dword ptr fs:[00000030h] |
17_2_00E320A0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E320A0 mov eax, dword ptr fs:[00000030h] |
17_2_00E320A0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E320A0 mov eax, dword ptr fs:[00000030h] |
17_2_00E320A0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E320A0 mov eax, dword ptr fs:[00000030h] |
17_2_00E320A0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E320A0 mov eax, dword ptr fs:[00000030h] |
17_2_00E320A0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E490AF mov eax, dword ptr fs:[00000030h] |
17_2_00E490AF |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3F0BF mov ecx, dword ptr fs:[00000030h] |
17_2_00E3F0BF |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3F0BF mov eax, dword ptr fs:[00000030h] |
17_2_00E3F0BF |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3F0BF mov eax, dword ptr fs:[00000030h] |
17_2_00E3F0BF |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E09080 mov eax, dword ptr fs:[00000030h] |
17_2_00E09080 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E83884 mov eax, dword ptr fs:[00000030h] |
17_2_00E83884 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E83884 mov eax, dword ptr fs:[00000030h] |
17_2_00E83884 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED1074 mov eax, dword ptr fs:[00000030h] |
17_2_00ED1074 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC2073 mov eax, dword ptr fs:[00000030h] |
17_2_00EC2073 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E20050 mov eax, dword ptr fs:[00000030h] |
17_2_00E20050 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E20050 mov eax, dword ptr fs:[00000030h] |
17_2_00E20050 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E1B02A mov eax, dword ptr fs:[00000030h] |
17_2_00E1B02A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E1B02A mov eax, dword ptr fs:[00000030h] |
17_2_00E1B02A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E1B02A mov eax, dword ptr fs:[00000030h] |
17_2_00E1B02A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E1B02A mov eax, dword ptr fs:[00000030h] |
17_2_00E1B02A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3002D mov eax, dword ptr fs:[00000030h] |
17_2_00E3002D |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3002D mov eax, dword ptr fs:[00000030h] |
17_2_00E3002D |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3002D mov eax, dword ptr fs:[00000030h] |
17_2_00E3002D |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3002D mov eax, dword ptr fs:[00000030h] |
17_2_00E3002D |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3002D mov eax, dword ptr fs:[00000030h] |
17_2_00E3002D |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2A830 mov eax, dword ptr fs:[00000030h] |
17_2_00E2A830 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2A830 mov eax, dword ptr fs:[00000030h] |
17_2_00E2A830 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2A830 mov eax, dword ptr fs:[00000030h] |
17_2_00E2A830 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2A830 mov eax, dword ptr fs:[00000030h] |
17_2_00E2A830 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED4015 mov eax, dword ptr fs:[00000030h] |
17_2_00ED4015 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED4015 mov eax, dword ptr fs:[00000030h] |
17_2_00ED4015 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E87016 mov eax, dword ptr fs:[00000030h] |
17_2_00E87016 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E87016 mov eax, dword ptr fs:[00000030h] |
17_2_00E87016 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E87016 mov eax, dword ptr fs:[00000030h] |
17_2_00E87016 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E0B1E1 mov eax, dword ptr fs:[00000030h] |
17_2_00E0B1E1 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E0B1E1 mov eax, dword ptr fs:[00000030h] |
17_2_00E0B1E1 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E0B1E1 mov eax, dword ptr fs:[00000030h] |
17_2_00E0B1E1 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E941E8 mov eax, dword ptr fs:[00000030h] |
17_2_00E941E8 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E361A0 mov eax, dword ptr fs:[00000030h] |
17_2_00E361A0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E361A0 mov eax, dword ptr fs:[00000030h] |
17_2_00E361A0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC49A4 mov eax, dword ptr fs:[00000030h] |
17_2_00EC49A4 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC49A4 mov eax, dword ptr fs:[00000030h] |
17_2_00EC49A4 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC49A4 mov eax, dword ptr fs:[00000030h] |
17_2_00EC49A4 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC49A4 mov eax, dword ptr fs:[00000030h] |
17_2_00EC49A4 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E869A6 mov eax, dword ptr fs:[00000030h] |
17_2_00E869A6 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E851BE mov eax, dword ptr fs:[00000030h] |
17_2_00E851BE |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E851BE mov eax, dword ptr fs:[00000030h] |
17_2_00E851BE |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E851BE mov eax, dword ptr fs:[00000030h] |
17_2_00E851BE |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E851BE mov eax, dword ptr fs:[00000030h] |
17_2_00E851BE |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2C182 mov eax, dword ptr fs:[00000030h] |
17_2_00E2C182 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3A185 mov eax, dword ptr fs:[00000030h] |
17_2_00E3A185 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E32990 mov eax, dword ptr fs:[00000030h] |
17_2_00E32990 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E0C962 mov eax, dword ptr fs:[00000030h] |
17_2_00E0C962 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E0B171 mov eax, dword ptr fs:[00000030h] |
17_2_00E0B171 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E0B171 mov eax, dword ptr fs:[00000030h] |
17_2_00E0B171 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2B944 mov eax, dword ptr fs:[00000030h] |
17_2_00E2B944 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2B944 mov eax, dword ptr fs:[00000030h] |
17_2_00E2B944 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E24120 mov eax, dword ptr fs:[00000030h] |
17_2_00E24120 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E24120 mov eax, dword ptr fs:[00000030h] |
17_2_00E24120 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E24120 mov eax, dword ptr fs:[00000030h] |
17_2_00E24120 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E24120 mov eax, dword ptr fs:[00000030h] |
17_2_00E24120 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E24120 mov ecx, dword ptr fs:[00000030h] |
17_2_00E24120 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3513A mov eax, dword ptr fs:[00000030h] |
17_2_00E3513A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3513A mov eax, dword ptr fs:[00000030h] |
17_2_00E3513A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E09100 mov eax, dword ptr fs:[00000030h] |
17_2_00E09100 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E09100 mov eax, dword ptr fs:[00000030h] |
17_2_00E09100 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E09100 mov eax, dword ptr fs:[00000030h] |
17_2_00E09100 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E32AE4 mov eax, dword ptr fs:[00000030h] |
17_2_00E32AE4 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E32ACB mov eax, dword ptr fs:[00000030h] |
17_2_00E32ACB |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E052A5 mov eax, dword ptr fs:[00000030h] |
17_2_00E052A5 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E052A5 mov eax, dword ptr fs:[00000030h] |
17_2_00E052A5 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E052A5 mov eax, dword ptr fs:[00000030h] |
17_2_00E052A5 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E052A5 mov eax, dword ptr fs:[00000030h] |
17_2_00E052A5 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E052A5 mov eax, dword ptr fs:[00000030h] |
17_2_00E052A5 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E1AAB0 mov eax, dword ptr fs:[00000030h] |
17_2_00E1AAB0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E1AAB0 mov eax, dword ptr fs:[00000030h] |
17_2_00E1AAB0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3FAB0 mov eax, dword ptr fs:[00000030h] |
17_2_00E3FAB0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3D294 mov eax, dword ptr fs:[00000030h] |
17_2_00E3D294 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3D294 mov eax, dword ptr fs:[00000030h] |
17_2_00E3D294 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EBB260 mov eax, dword ptr fs:[00000030h] |
17_2_00EBB260 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EBB260 mov eax, dword ptr fs:[00000030h] |
17_2_00EBB260 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED8A62 mov eax, dword ptr fs:[00000030h] |
17_2_00ED8A62 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E4927A mov eax, dword ptr fs:[00000030h] |
17_2_00E4927A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E09240 mov eax, dword ptr fs:[00000030h] |
17_2_00E09240 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E09240 mov eax, dword ptr fs:[00000030h] |
17_2_00E09240 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E09240 mov eax, dword ptr fs:[00000030h] |
17_2_00E09240 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E09240 mov eax, dword ptr fs:[00000030h] |
17_2_00E09240 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ECEA55 mov eax, dword ptr fs:[00000030h] |
17_2_00ECEA55 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E94257 mov eax, dword ptr fs:[00000030h] |
17_2_00E94257 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E44A2C mov eax, dword ptr fs:[00000030h] |
17_2_00E44A2C |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E44A2C mov eax, dword ptr fs:[00000030h] |
17_2_00E44A2C |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2A229 mov eax, dword ptr fs:[00000030h] |
17_2_00E2A229 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2A229 mov eax, dword ptr fs:[00000030h] |
17_2_00E2A229 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2A229 mov eax, dword ptr fs:[00000030h] |
17_2_00E2A229 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2A229 mov eax, dword ptr fs:[00000030h] |
17_2_00E2A229 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2A229 mov eax, dword ptr fs:[00000030h] |
17_2_00E2A229 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2A229 mov eax, dword ptr fs:[00000030h] |
17_2_00E2A229 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2A229 mov eax, dword ptr fs:[00000030h] |
17_2_00E2A229 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2A229 mov eax, dword ptr fs:[00000030h] |
17_2_00E2A229 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2A229 mov eax, dword ptr fs:[00000030h] |
17_2_00E2A229 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E18A0A mov eax, dword ptr fs:[00000030h] |
17_2_00E18A0A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E05210 mov eax, dword ptr fs:[00000030h] |
17_2_00E05210 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E05210 mov ecx, dword ptr fs:[00000030h] |
17_2_00E05210 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E05210 mov eax, dword ptr fs:[00000030h] |
17_2_00E05210 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E05210 mov eax, dword ptr fs:[00000030h] |
17_2_00E05210 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E0AA16 mov eax, dword ptr fs:[00000030h] |
17_2_00E0AA16 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E0AA16 mov eax, dword ptr fs:[00000030h] |
17_2_00E0AA16 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ECAA16 mov eax, dword ptr fs:[00000030h] |
17_2_00ECAA16 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ECAA16 mov eax, dword ptr fs:[00000030h] |
17_2_00ECAA16 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E23A1C mov eax, dword ptr fs:[00000030h] |
17_2_00E23A1C |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E303E2 mov eax, dword ptr fs:[00000030h] |
17_2_00E303E2 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E303E2 mov eax, dword ptr fs:[00000030h] |
17_2_00E303E2 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E303E2 mov eax, dword ptr fs:[00000030h] |
17_2_00E303E2 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E303E2 mov eax, dword ptr fs:[00000030h] |
17_2_00E303E2 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E303E2 mov eax, dword ptr fs:[00000030h] |
17_2_00E303E2 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E303E2 mov eax, dword ptr fs:[00000030h] |
17_2_00E303E2 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2DBE9 mov eax, dword ptr fs:[00000030h] |
17_2_00E2DBE9 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E853CA mov eax, dword ptr fs:[00000030h] |
17_2_00E853CA |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E853CA mov eax, dword ptr fs:[00000030h] |
17_2_00E853CA |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED5BA5 mov eax, dword ptr fs:[00000030h] |
17_2_00ED5BA5 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E34BAD mov eax, dword ptr fs:[00000030h] |
17_2_00E34BAD |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E34BAD mov eax, dword ptr fs:[00000030h] |
17_2_00E34BAD |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E34BAD mov eax, dword ptr fs:[00000030h] |
17_2_00E34BAD |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC138A mov eax, dword ptr fs:[00000030h] |
17_2_00EC138A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EBD380 mov ecx, dword ptr fs:[00000030h] |
17_2_00EBD380 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E11B8F mov eax, dword ptr fs:[00000030h] |
17_2_00E11B8F |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E11B8F mov eax, dword ptr fs:[00000030h] |
17_2_00E11B8F |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3B390 mov eax, dword ptr fs:[00000030h] |
17_2_00E3B390 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E32397 mov eax, dword ptr fs:[00000030h] |
17_2_00E32397 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E0DB60 mov ecx, dword ptr fs:[00000030h] |
17_2_00E0DB60 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E33B7A mov eax, dword ptr fs:[00000030h] |
17_2_00E33B7A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E33B7A mov eax, dword ptr fs:[00000030h] |
17_2_00E33B7A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E0DB40 mov eax, dword ptr fs:[00000030h] |
17_2_00E0DB40 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED8B58 mov eax, dword ptr fs:[00000030h] |
17_2_00ED8B58 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E0F358 mov eax, dword ptr fs:[00000030h] |
17_2_00E0F358 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC131B mov eax, dword ptr fs:[00000030h] |
17_2_00EC131B |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC14FB mov eax, dword ptr fs:[00000030h] |
17_2_00EC14FB |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E86CF0 mov eax, dword ptr fs:[00000030h] |
17_2_00E86CF0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E86CF0 mov eax, dword ptr fs:[00000030h] |
17_2_00E86CF0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E86CF0 mov eax, dword ptr fs:[00000030h] |
17_2_00E86CF0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED8CD6 mov eax, dword ptr fs:[00000030h] |
17_2_00ED8CD6 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E1849B mov eax, dword ptr fs:[00000030h] |
17_2_00E1849B |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2746D mov eax, dword ptr fs:[00000030h] |
17_2_00E2746D |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3A44B mov eax, dword ptr fs:[00000030h] |
17_2_00E3A44B |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E9C450 mov eax, dword ptr fs:[00000030h] |
17_2_00E9C450 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E9C450 mov eax, dword ptr fs:[00000030h] |
17_2_00E9C450 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3BC2C mov eax, dword ptr fs:[00000030h] |
17_2_00E3BC2C |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED740D mov eax, dword ptr fs:[00000030h] |
17_2_00ED740D |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED740D mov eax, dword ptr fs:[00000030h] |
17_2_00ED740D |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED740D mov eax, dword ptr fs:[00000030h] |
17_2_00ED740D |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E86C0A mov eax, dword ptr fs:[00000030h] |
17_2_00E86C0A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E86C0A mov eax, dword ptr fs:[00000030h] |
17_2_00E86C0A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E86C0A mov eax, dword ptr fs:[00000030h] |
17_2_00E86C0A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E86C0A mov eax, dword ptr fs:[00000030h] |
17_2_00E86C0A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC1C06 mov eax, dword ptr fs:[00000030h] |
17_2_00EC1C06 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC1C06 mov eax, dword ptr fs:[00000030h] |
17_2_00EC1C06 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC1C06 mov eax, dword ptr fs:[00000030h] |
17_2_00EC1C06 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC1C06 mov eax, dword ptr fs:[00000030h] |
17_2_00EC1C06 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC1C06 mov eax, dword ptr fs:[00000030h] |
17_2_00EC1C06 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC1C06 mov eax, dword ptr fs:[00000030h] |
17_2_00EC1C06 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC1C06 mov eax, dword ptr fs:[00000030h] |
17_2_00EC1C06 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC1C06 mov eax, dword ptr fs:[00000030h] |
17_2_00EC1C06 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC1C06 mov eax, dword ptr fs:[00000030h] |
17_2_00EC1C06 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC1C06 mov eax, dword ptr fs:[00000030h] |
17_2_00EC1C06 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC1C06 mov eax, dword ptr fs:[00000030h] |
17_2_00EC1C06 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC1C06 mov eax, dword ptr fs:[00000030h] |
17_2_00EC1C06 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC1C06 mov eax, dword ptr fs:[00000030h] |
17_2_00EC1C06 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC1C06 mov eax, dword ptr fs:[00000030h] |
17_2_00EC1C06 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E1D5E0 mov eax, dword ptr fs:[00000030h] |
17_2_00E1D5E0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E1D5E0 mov eax, dword ptr fs:[00000030h] |
17_2_00E1D5E0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ECFDE2 mov eax, dword ptr fs:[00000030h] |
17_2_00ECFDE2 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ECFDE2 mov eax, dword ptr fs:[00000030h] |
17_2_00ECFDE2 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ECFDE2 mov eax, dword ptr fs:[00000030h] |
17_2_00ECFDE2 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ECFDE2 mov eax, dword ptr fs:[00000030h] |
17_2_00ECFDE2 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EB8DF1 mov eax, dword ptr fs:[00000030h] |
17_2_00EB8DF1 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E86DC9 mov eax, dword ptr fs:[00000030h] |
17_2_00E86DC9 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E86DC9 mov eax, dword ptr fs:[00000030h] |
17_2_00E86DC9 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E86DC9 mov eax, dword ptr fs:[00000030h] |
17_2_00E86DC9 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E86DC9 mov ecx, dword ptr fs:[00000030h] |
17_2_00E86DC9 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E86DC9 mov eax, dword ptr fs:[00000030h] |
17_2_00E86DC9 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E86DC9 mov eax, dword ptr fs:[00000030h] |
17_2_00E86DC9 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED05AC mov eax, dword ptr fs:[00000030h] |
17_2_00ED05AC |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED05AC mov eax, dword ptr fs:[00000030h] |
17_2_00ED05AC |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E335A1 mov eax, dword ptr fs:[00000030h] |
17_2_00E335A1 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E31DB5 mov eax, dword ptr fs:[00000030h] |
17_2_00E31DB5 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E31DB5 mov eax, dword ptr fs:[00000030h] |
17_2_00E31DB5 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E31DB5 mov eax, dword ptr fs:[00000030h] |
17_2_00E31DB5 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E32581 mov eax, dword ptr fs:[00000030h] |
17_2_00E32581 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E32581 mov eax, dword ptr fs:[00000030h] |
17_2_00E32581 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E32581 mov eax, dword ptr fs:[00000030h] |
17_2_00E32581 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E32581 mov eax, dword ptr fs:[00000030h] |
17_2_00E32581 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E02D8A mov eax, dword ptr fs:[00000030h] |
17_2_00E02D8A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E02D8A mov eax, dword ptr fs:[00000030h] |
17_2_00E02D8A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E02D8A mov eax, dword ptr fs:[00000030h] |
17_2_00E02D8A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E02D8A mov eax, dword ptr fs:[00000030h] |
17_2_00E02D8A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E02D8A mov eax, dword ptr fs:[00000030h] |
17_2_00E02D8A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3FD9B mov eax, dword ptr fs:[00000030h] |
17_2_00E3FD9B |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3FD9B mov eax, dword ptr fs:[00000030h] |
17_2_00E3FD9B |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2C577 mov eax, dword ptr fs:[00000030h] |
17_2_00E2C577 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2C577 mov eax, dword ptr fs:[00000030h] |
17_2_00E2C577 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E43D43 mov eax, dword ptr fs:[00000030h] |
17_2_00E43D43 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E83540 mov eax, dword ptr fs:[00000030h] |
17_2_00E83540 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EB3D40 mov eax, dword ptr fs:[00000030h] |
17_2_00EB3D40 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E27D50 mov eax, dword ptr fs:[00000030h] |
17_2_00E27D50 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E0AD30 mov eax, dword ptr fs:[00000030h] |
17_2_00E0AD30 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E13D34 mov eax, dword ptr fs:[00000030h] |
17_2_00E13D34 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E13D34 mov eax, dword ptr fs:[00000030h] |
17_2_00E13D34 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E13D34 mov eax, dword ptr fs:[00000030h] |
17_2_00E13D34 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E13D34 mov eax, dword ptr fs:[00000030h] |
17_2_00E13D34 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E13D34 mov eax, dword ptr fs:[00000030h] |
17_2_00E13D34 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E13D34 mov eax, dword ptr fs:[00000030h] |
17_2_00E13D34 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E13D34 mov eax, dword ptr fs:[00000030h] |
17_2_00E13D34 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E13D34 mov eax, dword ptr fs:[00000030h] |
17_2_00E13D34 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E13D34 mov eax, dword ptr fs:[00000030h] |
17_2_00E13D34 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E13D34 mov eax, dword ptr fs:[00000030h] |
17_2_00E13D34 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E13D34 mov eax, dword ptr fs:[00000030h] |
17_2_00E13D34 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E13D34 mov eax, dword ptr fs:[00000030h] |
17_2_00E13D34 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E13D34 mov eax, dword ptr fs:[00000030h] |
17_2_00E13D34 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ECE539 mov eax, dword ptr fs:[00000030h] |
17_2_00ECE539 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E34D3B mov eax, dword ptr fs:[00000030h] |
17_2_00E34D3B |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E34D3B mov eax, dword ptr fs:[00000030h] |
17_2_00E34D3B |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E34D3B mov eax, dword ptr fs:[00000030h] |
17_2_00E34D3B |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED8D34 mov eax, dword ptr fs:[00000030h] |
17_2_00ED8D34 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E8A537 mov eax, dword ptr fs:[00000030h] |
17_2_00E8A537 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E316E0 mov ecx, dword ptr fs:[00000030h] |
17_2_00E316E0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E176E2 mov eax, dword ptr fs:[00000030h] |
17_2_00E176E2 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E48EC7 mov eax, dword ptr fs:[00000030h] |
17_2_00E48EC7 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EBFEC0 mov eax, dword ptr fs:[00000030h] |
17_2_00EBFEC0 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E336CC mov eax, dword ptr fs:[00000030h] |
17_2_00E336CC |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED8ED6 mov eax, dword ptr fs:[00000030h] |
17_2_00ED8ED6 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED0EA5 mov eax, dword ptr fs:[00000030h] |
17_2_00ED0EA5 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED0EA5 mov eax, dword ptr fs:[00000030h] |
17_2_00ED0EA5 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED0EA5 mov eax, dword ptr fs:[00000030h] |
17_2_00ED0EA5 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E846A7 mov eax, dword ptr fs:[00000030h] |
17_2_00E846A7 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E9FE87 mov eax, dword ptr fs:[00000030h] |
17_2_00E9FE87 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E1766D mov eax, dword ptr fs:[00000030h] |
17_2_00E1766D |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2AE73 mov eax, dword ptr fs:[00000030h] |
17_2_00E2AE73 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2AE73 mov eax, dword ptr fs:[00000030h] |
17_2_00E2AE73 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2AE73 mov eax, dword ptr fs:[00000030h] |
17_2_00E2AE73 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2AE73 mov eax, dword ptr fs:[00000030h] |
17_2_00E2AE73 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2AE73 mov eax, dword ptr fs:[00000030h] |
17_2_00E2AE73 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E17E41 mov eax, dword ptr fs:[00000030h] |
17_2_00E17E41 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E17E41 mov eax, dword ptr fs:[00000030h] |
17_2_00E17E41 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E17E41 mov eax, dword ptr fs:[00000030h] |
17_2_00E17E41 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E17E41 mov eax, dword ptr fs:[00000030h] |
17_2_00E17E41 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E17E41 mov eax, dword ptr fs:[00000030h] |
17_2_00E17E41 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E17E41 mov eax, dword ptr fs:[00000030h] |
17_2_00E17E41 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ECAE44 mov eax, dword ptr fs:[00000030h] |
17_2_00ECAE44 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ECAE44 mov eax, dword ptr fs:[00000030h] |
17_2_00ECAE44 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E0E620 mov eax, dword ptr fs:[00000030h] |
17_2_00E0E620 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EBFE3F mov eax, dword ptr fs:[00000030h] |
17_2_00EBFE3F |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E0C600 mov eax, dword ptr fs:[00000030h] |
17_2_00E0C600 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E0C600 mov eax, dword ptr fs:[00000030h] |
17_2_00E0C600 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E0C600 mov eax, dword ptr fs:[00000030h] |
17_2_00E0C600 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E38E00 mov eax, dword ptr fs:[00000030h] |
17_2_00E38E00 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00EC1608 mov eax, dword ptr fs:[00000030h] |
17_2_00EC1608 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3A61C mov eax, dword ptr fs:[00000030h] |
17_2_00E3A61C |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3A61C mov eax, dword ptr fs:[00000030h] |
17_2_00E3A61C |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E437F5 mov eax, dword ptr fs:[00000030h] |
17_2_00E437F5 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E18794 mov eax, dword ptr fs:[00000030h] |
17_2_00E18794 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E87794 mov eax, dword ptr fs:[00000030h] |
17_2_00E87794 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E87794 mov eax, dword ptr fs:[00000030h] |
17_2_00E87794 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E87794 mov eax, dword ptr fs:[00000030h] |
17_2_00E87794 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E1FF60 mov eax, dword ptr fs:[00000030h] |
17_2_00E1FF60 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED8F6A mov eax, dword ptr fs:[00000030h] |
17_2_00ED8F6A |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E1EF40 mov eax, dword ptr fs:[00000030h] |
17_2_00E1EF40 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E04F2E mov eax, dword ptr fs:[00000030h] |
17_2_00E04F2E |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E04F2E mov eax, dword ptr fs:[00000030h] |
17_2_00E04F2E |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3E730 mov eax, dword ptr fs:[00000030h] |
17_2_00E3E730 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED070D mov eax, dword ptr fs:[00000030h] |
17_2_00ED070D |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00ED070D mov eax, dword ptr fs:[00000030h] |
17_2_00ED070D |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3A70E mov eax, dword ptr fs:[00000030h] |
17_2_00E3A70E |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E3A70E mov eax, dword ptr fs:[00000030h] |
17_2_00E3A70E |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E2F716 mov eax, dword ptr fs:[00000030h] |
17_2_00E2F716 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E9FF10 mov eax, dword ptr fs:[00000030h] |
17_2_00E9FF10 |
Source: C:\Users\user\Desktop\kayx.exe |
Code function: 17_2_00E9FF10 mov eax, dword ptr fs:[00000030h] |
17_2_00E9FF10 |