Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: 400000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: 400000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: 401000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: 414000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: 416000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: 418000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C940000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C940000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C941000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C954000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C956000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C958000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C960000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C960000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C961000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C974000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C976000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C978000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C980000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C980000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C981000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C994000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C996000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C998000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9A0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9A0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9A1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9B4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9B6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9B8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9C0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9C0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9C1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9D4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9D6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9D8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9E0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9E0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9E1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9F4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9F6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: C9F8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA00000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA00000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA01000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA14000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA16000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA18000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA20000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA20000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA21000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA34000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA36000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA38000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA40000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA40000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA41000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA54000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA56000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA58000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA60000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA60000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA61000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA74000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA76000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA78000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA80000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA80000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA81000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA94000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA96000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CA98000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAA0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAA0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAA1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAB4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAB6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAB8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAC0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAC0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAC1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAD4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAD6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAD8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAE0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAE0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAE1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAF4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAF6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CAF8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB00000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB00000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB01000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB14000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB16000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB18000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB20000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB20000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB21000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB34000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB36000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB38000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB40000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB40000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB41000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB54000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB56000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB58000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB60000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB60000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB61000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB74000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB76000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB78000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB80000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB80000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB81000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB94000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB96000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CB98000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBA0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBA0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBA1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBB4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBB6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBB8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBC0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBC0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBC1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBD4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBD6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBD8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBE0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBE0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBE1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBF4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBF6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CBF8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC00000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC00000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC01000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC14000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC16000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC18000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC20000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC20000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC21000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC34000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC36000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC38000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC40000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC40000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC41000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC54000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC56000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC58000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC60000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC60000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC61000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC74000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC76000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC78000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC80000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC80000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC81000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC94000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC96000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CC98000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCA0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCA0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCA1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCB4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCB6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCB8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCC0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCC0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCC1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCD4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCD6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCD8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCE0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCE0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCE1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCF4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCF6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CCF8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD00000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD00000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD01000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD14000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD16000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD18000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD20000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD20000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD21000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD34000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD36000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD38000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD40000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD40000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD41000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD54000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD56000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD58000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD60000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD60000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD61000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD74000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD76000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD78000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD80000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD80000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD81000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD94000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD96000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CD98000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDA0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDA0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDA1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDB4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDB6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDB8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDC0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDC0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDC1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDD4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDD6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDD8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDE0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDE0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDE1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDF4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDF6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CDF8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE00000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE00000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE01000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE14000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE16000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE18000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE20000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE20000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE21000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE34000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE36000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE38000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE40000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE40000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE41000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE54000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE56000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE58000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE60000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE60000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE61000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE74000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE76000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE78000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE80000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE80000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE81000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE94000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE96000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CE98000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CEA0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CEA0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CEA1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CEB4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CEB6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CEB8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CEC0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CEC0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CEC1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CED4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CED6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CED8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CEE0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CEE0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CEE1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CEF4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CEF6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CEF8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF00000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF00000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF01000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF14000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF16000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF18000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF20000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF20000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF21000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF34000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF36000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF38000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF40000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF40000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF41000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF54000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF56000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF58000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF60000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF60000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF61000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF74000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF76000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF78000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF80000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF80000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF81000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF94000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF96000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CF98000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFA0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFA0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFA1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFB4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFB6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFB8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFC0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFC0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFC1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFD4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFD6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFD8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFE0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFE0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFE1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFF4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFF6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: CFF8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D000000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D000000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D001000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D014000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D016000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D018000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D020000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D020000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D021000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D034000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D036000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D038000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D040000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D040000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D041000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D054000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D056000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D058000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D060000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D060000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D061000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D074000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D076000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D078000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D080000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D080000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D081000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D094000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D096000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D098000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0A0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0A0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0A1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0B4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0B6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0B8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0C0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0C0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0C1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0D4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0D6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0D8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0E0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0E0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0E1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0F4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0F6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D0F8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D100000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D100000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D101000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D114000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D116000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D118000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D120000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D120000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D121000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D134000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D136000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D138000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D140000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D140000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D141000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D154000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D156000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D158000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D160000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D160000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D161000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D174000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D176000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D178000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D180000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D180000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D181000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D194000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D196000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D198000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1A0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1A0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1A1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1B4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1B6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1B8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1C0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1C0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1C1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1D4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1D6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1D8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1E0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1E0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1E1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1F4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1F6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D1F8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D200000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D200000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D201000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D214000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D216000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D218000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D220000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D220000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D221000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D234000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D236000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D238000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D240000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D240000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D241000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D254000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D256000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D258000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D260000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D260000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D261000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D274000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D276000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D278000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D280000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D280000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D281000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D294000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D296000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D298000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2A0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2A0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2A1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2B4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2B6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2B8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2C0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2C0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2C1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2D4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2D6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2D8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2E0000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2E0000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2E1000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2F4000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2F6000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D2F8000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D300000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D300000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D301000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D314000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D316000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D318000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D320000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D320000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D321000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D334000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D336000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D338000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D340000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D340000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D341000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D354000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D356000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D358000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D360000 protect: page no access |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D360000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D361000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D374000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory allocated: C:\Windows\System32\winlogon.exe base: D376000 protect: page read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: 400000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: 401000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: 414000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: 416000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: 418000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C940000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C941000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C954000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C956000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C958000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C960000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C961000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C974000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C976000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C978000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C980000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C981000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C994000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C996000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C998000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C9A0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C9A1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C9B4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C9B6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C9B8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C9C0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C9C1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C9D4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C9D6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C9D8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C9E0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C9E1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C9F4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C9F6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: C9F8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA00000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA01000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA14000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA16000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA18000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA20000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA21000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA34000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA36000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA38000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA40000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA41000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA54000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA56000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA58000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA60000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA61000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA74000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA76000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA78000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA80000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA81000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA94000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA96000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CA98000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CAA0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CAA1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CAB4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CAB6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CAB8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CAC0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CAC1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CAD4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CAD6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CAD8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CAE0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CAE1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CAF4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CAF6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CAF8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB00000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB01000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB14000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB16000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB18000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB20000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB21000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB34000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB36000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB38000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB40000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB41000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB54000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB56000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB58000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB60000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB61000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB74000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB76000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB78000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB80000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB81000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB94000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB96000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CB98000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CBA0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CBA1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CBB4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CBB6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CBB8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CBC0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CBC1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CBD4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CBD6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CBD8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CBE0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CBE1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CBF4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CBF6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CBF8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC00000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC01000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC14000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC16000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC18000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC20000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC21000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC34000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC36000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC38000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC40000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC41000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC54000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC56000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC58000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC60000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC61000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC74000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC76000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC78000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC80000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC81000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC94000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC96000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CC98000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CCA0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CCA1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CCB4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CCB6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CCB8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CCC0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CCC1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CCD4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CCD6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CCD8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CCE0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CCE1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CCF4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CCF6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CCF8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD00000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD01000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD14000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD16000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD18000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD20000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD21000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD34000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD36000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD38000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD40000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD41000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD54000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD56000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD58000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD60000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD61000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD74000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD76000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD78000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD80000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD81000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD94000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD96000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CD98000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CDA0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CDA1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CDB4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CDB6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CDB8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CDC0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CDC1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CDD4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CDD6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CDD8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CDE0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CDE1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CDF4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CDF6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CDF8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE00000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE01000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE14000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE16000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE18000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE20000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE21000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE34000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE36000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE38000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE40000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE41000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE54000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE56000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE58000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE60000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE61000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE74000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE76000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE78000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE80000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE81000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE94000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE96000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CE98000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CEA0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CEA1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CEB4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CEB6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CEB8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CEC0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CEC1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CED4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CED6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CED8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CEE0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CEE1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CEF4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CEF6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CEF8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF00000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF01000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF14000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF16000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF18000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF20000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF21000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF34000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF36000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF38000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF40000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF41000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF54000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF56000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF58000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF60000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF61000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF74000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF76000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF78000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF80000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF81000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF94000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF96000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CF98000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CFA0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CFA1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CFB4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CFB6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CFB8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CFC0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CFC1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CFD4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CFD6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CFD8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CFE0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CFE1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CFF4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CFF6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: CFF8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D000000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D001000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D014000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D016000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D018000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D020000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D021000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D034000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D036000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D038000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D040000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D041000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D054000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D056000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D058000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D060000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D061000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D074000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D076000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D078000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D080000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D081000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D094000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D096000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D098000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D0A0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D0A1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D0B4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D0B6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D0B8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D0C0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D0C1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D0D4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D0D6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D0D8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D0E0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D0E1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D0F4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D0F6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D0F8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D100000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D101000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D114000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D116000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D118000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D120000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D121000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D134000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D136000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D138000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D140000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D141000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D154000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D156000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D158000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D160000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D161000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D174000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D176000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D178000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D180000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D181000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D194000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D196000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D198000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D1A0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D1A1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D1B4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D1B6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D1B8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D1C0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D1C1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D1D4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D1D6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D1D8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D1E0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D1E1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D1F4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D1F6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D1F8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D200000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D201000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D214000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D216000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D218000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D220000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D221000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D234000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D236000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D238000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D240000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D241000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D254000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D256000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D258000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D260000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D261000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D274000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D276000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D278000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D280000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D281000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D294000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D296000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D298000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D2A0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D2A1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D2B4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D2B6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D2B8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D2C0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D2C1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D2D4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D2D6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D2D8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D2E0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D2E1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D2F4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D2F6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D2F8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D300000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D301000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D314000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D316000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D318000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D320000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D321000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D334000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D336000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D338000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D340000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D341000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D354000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D356000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D358000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D360000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D361000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D374000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D376000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D378000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D380000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D381000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D394000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D396000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D398000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D3A0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D3A1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D3B4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D3B6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D3B8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D3C0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D3C1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D3D4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D3D6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D3D8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D3E0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D3E1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D3F4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D3F6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D3F8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D400000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D401000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D414000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D416000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D418000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D420000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D421000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D434000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D436000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D438000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D440000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D441000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D454000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D456000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D458000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D460000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D461000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D474000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D476000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D478000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D480000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D481000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D494000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D496000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D498000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D4A0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D4A1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D4B4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D4B6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D4B8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D4C0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D4C1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D4D4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D4D6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D4D8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D4E0000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D4E1000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D4F4000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D4F6000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D4F8000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D500000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D501000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D514000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D516000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D518000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D520000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D521000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D534000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D536000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D538000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D540000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D541000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D554000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D556000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D558000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D560000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D561000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D574000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D576000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D578000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D580000 protect: page readonly |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D581000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D594000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D596000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory protected: C:\Windows\System32\winlogon.exe base: D598000 protect: page execute and read and write |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: 400000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C940000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C960000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C980000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9A0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9C0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9E0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA00000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA20000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA40000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA60000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA80000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAA0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAC0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAE0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB00000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB20000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB40000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB60000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB80000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBA0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBC0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBE0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC00000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC20000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC40000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC60000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC80000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCA0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCC0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCE0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD00000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD20000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD40000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD60000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD80000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDA0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDC0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDE0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE00000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE20000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE40000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE60000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE80000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CEA0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CEC0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CEE0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF00000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF20000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF40000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF60000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF80000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFA0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFC0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFE0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D000000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D020000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D040000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D060000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D080000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0A0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0C0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0E0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D100000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D120000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D140000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D160000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D180000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1A0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1C0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1E0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D200000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D220000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D240000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D260000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D280000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2A0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2C0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2E0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D300000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D320000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D340000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D360000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D380000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3A0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3C0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3E0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D400000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D420000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D440000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D460000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D480000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4A0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4C0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4E0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D500000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D520000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D540000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D560000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D580000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D5A0000 value starts with: 4D5A |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: 400000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: 401000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: 414000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: 416000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: 418000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C940000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C941000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C954000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C956000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C958000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C960000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C961000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C974000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C976000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C978000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C980000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C981000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C994000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C996000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C998000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9A0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9A1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9B4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9B6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9B8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9C0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9C1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9D4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9D6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9D8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9E0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9E1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9F4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9F6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: C9F8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA00000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA01000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA14000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA16000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA18000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA20000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA21000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA34000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA36000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA38000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA40000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA41000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA54000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA56000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA58000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA60000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA61000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA74000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA76000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA78000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA80000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA81000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA94000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA96000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CA98000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAA0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAA1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAB4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAB6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAB8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAC0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAC1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAD4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAD6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAD8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAE0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAE1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAF4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAF6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CAF8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB00000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB01000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB14000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB16000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB18000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB20000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB21000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB34000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB36000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB38000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB40000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB41000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB54000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB56000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB58000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB60000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB61000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB74000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB76000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB78000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB80000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB81000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB94000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB96000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CB98000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBA0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBA1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBB4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBB6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBB8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBC0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBC1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBD4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBD6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBD8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBE0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBE1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBF4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBF6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CBF8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC00000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC01000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC14000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC16000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC18000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC20000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC21000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC34000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC36000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC38000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC40000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC41000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC54000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC56000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC58000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC60000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC61000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC74000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC76000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC78000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC80000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC81000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC94000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC96000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CC98000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCA0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCA1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCB4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCB6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCB8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCC0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCC1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCD4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCD6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCD8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCE0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCE1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCF4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCF6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CCF8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD00000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD01000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD14000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD16000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD18000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD20000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD21000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD34000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD36000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD38000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD40000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD41000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD54000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD56000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD58000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD60000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD61000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD74000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD76000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD78000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD80000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD81000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD94000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD96000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CD98000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDA0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDA1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDB4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDB6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDB8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDC0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDC1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDD4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDD6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDD8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDE0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDE1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDF4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDF6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CDF8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE00000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE01000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE14000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE16000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE18000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE20000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE21000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE34000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE36000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE38000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE40000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE41000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE54000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE56000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE58000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE60000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE61000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE74000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE76000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE78000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE80000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE81000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE94000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE96000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CE98000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CEA0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CEA1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CEB4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CEB6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CEB8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CEC0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CEC1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CED4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CED6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CED8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CEE0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CEE1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CEF4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CEF6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CEF8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF00000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF01000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF14000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF16000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF18000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF20000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF21000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF34000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF36000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF38000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF40000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF41000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF54000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF56000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF58000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF60000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF61000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF74000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF76000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF78000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF80000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF81000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF94000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF96000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CF98000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFA0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFA1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFB4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFB6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFB8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFC0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFC1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFD4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFD6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFD8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFE0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFE1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFF4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFF6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: CFF8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D000000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D001000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D014000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D016000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D018000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D020000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D021000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D034000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D036000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D038000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D040000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D041000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D054000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D056000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D058000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D060000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D061000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D074000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D076000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D078000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D080000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D081000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D094000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D096000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D098000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0A0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0A1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0B4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0B6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0B8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0C0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0C1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0D4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0D6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0D8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0E0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0E1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0F4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0F6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D0F8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D100000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D101000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D114000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D116000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D118000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D120000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D121000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D134000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D136000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D138000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D140000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D141000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D154000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D156000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D158000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D160000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D161000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D174000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D176000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D178000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D180000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D181000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D194000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D196000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D198000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1A0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1A1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1B4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1B6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1B8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1C0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1C1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1D4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1D6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1D8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1E0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1E1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1F4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1F6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D1F8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D200000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D201000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D214000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D216000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D218000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D220000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D221000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D234000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D236000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D238000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D240000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D241000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D254000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D256000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D258000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D260000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D261000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D274000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D276000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D278000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D280000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D281000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D294000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D296000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D298000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2A0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2A1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2B4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2B6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2B8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2C0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2C1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2D4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2D6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2D8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2E0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2E1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2F4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2F6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D2F8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D300000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D301000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D314000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D316000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D318000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D320000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D321000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D334000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D336000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D338000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D340000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D341000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D354000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D356000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D358000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D360000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D361000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D374000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D376000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D378000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D380000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D381000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D394000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D396000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D398000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3A0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3A1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3B4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3B6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3B8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3C0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3C1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3D4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3D6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3D8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3E0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3E1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3F4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3F6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D3F8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D400000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D401000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D414000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D416000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D418000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D420000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D421000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D434000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D436000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D438000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D440000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D441000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D454000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D456000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D458000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D460000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D461000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D474000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D476000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D478000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D480000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D481000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D494000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D496000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D498000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4A0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4A1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4B4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4B6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4B8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4C0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4C1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4D4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4D6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4D8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4E0000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4E1000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4F4000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4F6000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D4F8000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D500000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D501000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D514000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D516000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D518000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D520000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D521000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D534000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D536000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D538000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D540000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D541000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D554000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D556000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D558000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D560000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D561000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D574000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D576000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D578000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D580000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D581000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D594000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D596000 |
Source: C:\Users\user\Desktop\glGb1KYfX6.exe | Memory written: C:\Windows\System32\winlogon.exe base: D598000 |