Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9AFE NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0BF8 NtWriteVirtualMemory,TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A86C3 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0703 EnumWindows,NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A5F4C NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A95F4 NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A5224 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A52C4 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4AE1 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A5310 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9B14 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9B30 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9B58 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4B5F NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9B54 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9B76 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A538C NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9BB0 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4BB4 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A53E8 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9BE0 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A5003 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A601C NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4834 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A6074 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A508A NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4880 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A50C0 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A60F4 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4907 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A5110 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A6138 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A5168 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4970 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A51B0 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A49FC NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4E38 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A463C NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9E6C NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4E78 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4698 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4EA7 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4ED0 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A46E0 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4F2C NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A8726 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A473C NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4F55 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4F79 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A5F80 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4FAC NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A47DA NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9C08 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9C18 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4C44 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9C50 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9C6C NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1C7E NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9C88 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9C98 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4CA4 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9CB4 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9CDC NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A44FF NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9CFC NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A5510 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9D20 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4D36 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4554 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4D90 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A95AF NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A8DBB NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9DBC NtMapViewOfSection, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4DD4 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A45F2 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569AFE NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560BF8 NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005695F4 NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00565F4C NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00566074 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056601C NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005660F4 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00566138 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569B54 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569B58 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569B76 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569B14 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569B30 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569BE0 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569BB0 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569C50 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569C6C NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569C18 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569C08 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569CDC NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569CFC NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569C98 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569C88 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569CB4 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569D20 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056158E NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005615BC NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569DBC NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005695AF NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561670 NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569E6C NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561604 NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00565F80 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9AFE NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0BF8 NtWriteVirtualMemory,TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F86C3 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0703 EnumWindows,NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F5F4C NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F95F4 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F5224 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F52C4 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4AE1 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9B14 NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F5310 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9B30 NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4B5F NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9B58 NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9B54 NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9B76 NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F538C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4BB4 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9BB0 NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F53E8 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9BE0 NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F601C NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F5003 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4834 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F6074 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F508A NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4880 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F50C0 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F60F4 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F5110 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4907 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F6138 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4970 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F5168 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F51B0 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F49FC NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F463C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4E38 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4E78 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9E6C NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4698 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4EA7 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4ED0 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F46E0 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F473C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4F2C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F8726 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4F55 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4F79 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F5F80 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4FAC NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F47DA NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9C18 NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9C08 NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9C50 NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4C44 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1C7E NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9C6C NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9C98 NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9C88 NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9CB4 NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4CA4 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9CDC NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F44FF NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9CFC NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F5510 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4D36 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9D20 NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4554 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4D90 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9DBC NtResumeThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F8DBB NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F95AF NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4DD4 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F45F2 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49AFE NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40BF8 NtWriteVirtualMemory,TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B486C3 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40703 EnumWindows,NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B45F4C NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B495F4 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44AE1 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B452C4 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B45224 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44BB4 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49BB0 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4538C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49BE0 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B453E8 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49B30 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49B14 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B45310 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49B76 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49B54 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44B5F NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49B58 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44880 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4508A NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B460F4 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B450C0 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44834 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4601C NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B45003 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B46074 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B451B0 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B449FC NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B46138 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B45110 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44907 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44970 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B45168 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44EA7 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44698 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B446E0 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44ED0 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4463C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44E38 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44E78 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49E6C NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44FAC NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B45F80 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B447DA NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4473C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B48726 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44F2C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44F79 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44F55 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49CB4 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44CA4 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49C98 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49C88 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49CFC NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B444FF NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49CDC NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49C18 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49C08 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41C7E NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49C6C NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49C50 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44C44 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49DBC NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B48DBB NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B495AF NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44D90 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B445F2 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44DD4 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44D36 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49D20 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B45510 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44554 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9AFE NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A0BF8 NtWriteVirtualMemory,TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A86C3 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A0703 EnumWindows,NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A5F4C NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A95F4 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A5224 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A52C4 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4AE1 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A5310 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9B14 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9B30 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9B58 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4B5F NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9B54 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9B76 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A538C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9BB0 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4BB4 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A53E8 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9BE0 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A5003 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A601C NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4834 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A6074 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A508A NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4880 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A50C0 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A60F4 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4907 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A5110 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A6138 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A5168 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4970 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A51B0 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A49FC NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4E38 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A463C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9E6C NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4E78 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4698 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4EA7 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4ED0 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A46E0 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4F2C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A8726 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A473C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4F55 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4F79 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A5F80 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4FAC NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A47DA NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9C08 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9C18 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4C44 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9C50 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9C6C NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A1C7E NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9C88 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9C98 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4CA4 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9CB4 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9CDC NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A44FF NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9CFC NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A5510 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9D20 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4D36 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4554 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4D90 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A95AF NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A8DBB NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A9DBC NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4DD4 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A45F2 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569AFE NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00560BF8 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_005695F4 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00565F4C NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00566074 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_0056601C NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_005660F4 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00566138 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569B54 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569B58 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569B76 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569B14 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569B30 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569BE0 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569BB0 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569C50 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569C6C NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569C18 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569C08 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569CDC NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569CFC NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569C98 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569C88 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569CB4 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569D20 NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_0056158E NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_005615BC NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569DBC NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_005695AF NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00561670 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00569E6C NtSetInformationThread, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00561604 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00565F80 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00560BF8 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_005695F4 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00565F4C NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00566074 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_0056601C NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_005660F4 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00566138 NtAllocateVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_0056158E NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_005615BC NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_005695AF NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00561670 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00561604 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00565F80 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9AFE |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0BF8 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A86C3 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0703 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A5F4C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1210 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A5224 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A3A49 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1259 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2A5D |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2A50 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A3A80 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1286 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A12A4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2AC0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A52C4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A92D4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A3AEC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A12E0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4AE1 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2AF4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A131B |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A5310 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9B14 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9B30 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1331 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2B34 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0335 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1348 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A3B44 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9B58 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4B5F |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A135C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9B54 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0378 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9B76 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A538C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2B84 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A03A8 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A3BA0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9BB0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A13B4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4BB4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2BD4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A53E8 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9BE0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A03E4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A3BF8 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A5003 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9018 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A101C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A082F |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A083C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4834 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9048 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A305C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9056 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1078 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A508A |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0880 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4880 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A109C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A50C0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A08D0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4907 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A5110 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4116 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0924 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1124 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A113F |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A5168 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1163 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4970 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A19A9 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A19BC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A51B0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A49FC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A69F7 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0E24 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4E38 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A463C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A664C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A8E54 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4E78 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0E70 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4698 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2E96 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A6694 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A36AA |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4EA7 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A8EB0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4ED0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A66EC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A46E0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0F04 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2F18 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4F2C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A8726 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A473C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A8F34 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0F50 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4F55 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4F79 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A8F7C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0F74 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A3F88 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2F80 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A5F80 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4FAC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0FB8 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A47DA |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2FDC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A77EC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9C08 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9C18 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2C24 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0430 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0C4C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A6442 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4C44 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9C50 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A646C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9C6C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1C7E |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A3C7C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9C88 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9C98 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4CA4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9CB4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A64D8 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9CDC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0CEC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A44FF |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9CFC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A8D1B |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A6520 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A9D20 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4D36 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A6537 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0D40 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4554 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4D90 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A65A0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A8DBB |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0DB4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A8DD0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4DD4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A65EC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0DE4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A3DFC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A45F2 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00563A49 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569AFE |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560BF8 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00566442 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005686C3 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00565F4C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560703 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569056 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056305C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569048 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561078 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056101C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569018 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00565003 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564834 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056083C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056082F |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005608D0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005650C0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056109C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560880 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564880 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056508A |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564970 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561163 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00565168 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564116 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00565110 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564907 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056113F |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560924 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561124 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005669F7 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005649FC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005651B0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562A50 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562A5D |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561259 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00565224 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005692D4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005652C4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562AC0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562AF4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005612E0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564AE1 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00563AEC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00563A80 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005612A4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569B54 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564B5F |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056135C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569B58 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00563B44 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569B76 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560378 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569B14 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00565310 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056131B |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562B34 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560335 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569B30 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562BD4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00563BF8 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005603E4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569BE0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005653E8 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562B84 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056538C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005613B4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564BB4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569BB0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00563BA0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005603A8 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569C50 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564C44 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560C4C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561C7E |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00563C7C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056646C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569C6C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569C18 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569C08 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560430 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562C24 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569CDC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005664D8 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005644FF |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569CFC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560CEC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569C98 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569C88 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569CB4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564CA4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564554 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560D40 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00568D1B |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564D36 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00566537 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00566520 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00569D20 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564DD4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00568DD0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005645F2 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00563DFC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560DE4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005665EC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564D90 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056158E |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560DB4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005615BC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00568DBB |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005665A0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00568E54 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056664C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561670 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560E70 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564E78 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561604 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056463C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564E38 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560E24 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005646E0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005666EC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562E96 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00566694 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564698 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00568EB0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005636AA |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560F50 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560F74 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564F73 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00568F7C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562F18 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560F04 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00568F34 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056473C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00568726 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564F2C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562FDC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005647DA |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005677EC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562F80 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00565F80 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560FB8 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564FAC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9AFE |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0BF8 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F86C3 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0703 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F5F4C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1210 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F5224 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2A5D |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1259 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2A50 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F3A49 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1286 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F3A80 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F12A4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F92D4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F52C4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2AC0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2AF4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F3AEC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4AE1 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F12E0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F131B |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9B14 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F5310 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0335 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2B34 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1331 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9B30 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4B5F |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F135C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9B58 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9B54 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1348 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F3B44 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0378 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9B76 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F538C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2B84 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F13B4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4BB4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9BB0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F03A8 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F3BA0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2BD4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F3BF8 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F53E8 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F03E4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9BE0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F101C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9018 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F5003 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F083C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4834 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F082F |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F305C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9056 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9048 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1078 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F109C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F508A |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0880 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4880 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F08D0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F50C0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4116 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F5110 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4907 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F113F |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0924 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1124 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4970 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F5168 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1163 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F19BC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F51B0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F19A9 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F49FC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F69F7 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F463C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4E38 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0E24 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F8E54 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F664C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4E78 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0E70 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4698 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2E96 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F6694 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F8EB0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F36AA |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4EA7 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4ED0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F66EC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F46E0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2F18 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0F04 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F473C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F8F34 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4F2C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F8726 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4F55 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0F50 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F8F7C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4F79 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0F74 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F3F88 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2F80 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F5F80 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0FB8 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4FAC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2FDC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F47DA |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F77EC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9C18 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9C08 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0430 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2C24 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9C50 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0C4C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4C44 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F6442 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1C7E |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F3C7C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F646C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9C6C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9C98 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9C88 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9CB4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4CA4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9CDC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F64D8 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F44FF |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9CFC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0CEC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F8D1B |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F6537 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4D36 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F6520 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F9D20 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4554 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0D40 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4D90 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F8DBB |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0DB4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F65A0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4DD4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F8DD0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F3DFC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F45F2 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F65EC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0DE4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49AFE |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40BF8 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B486C3 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40703 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B45F4C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B412A4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41286 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B43A80 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42AF4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B412E0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44AE1 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B43AEC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B492D4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B452C4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42AC0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B45224 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41210 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42A50 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42A5D |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41259 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B43A49 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B413B4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44BB4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49BB0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B43BA0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B403A8 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42B84 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4538C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B43BF8 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B403E4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49BE0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B453E8 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42BD4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42B34 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40335 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49B30 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41331 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49B14 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B45310 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4131B |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49B76 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40378 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49B54 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4135C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44B5F |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B49B58 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B43B44 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41348 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4109C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40880 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44880 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4508A |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B408D0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0BF8 NtWriteVirtualMemory,TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A86C3 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0703 EnumWindows,NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1210 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1259 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2A5D |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2A50 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1286 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A12A4 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2AC0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A12E0 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2AF4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A131B TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1331 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2B34 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1348 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A135C TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2B84 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A13B4 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2BD4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A13EC TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A101C TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4834 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1078 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4880 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A109C TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4907 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1124 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A113F TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1163 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4970 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A49FC NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0E24 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A463C NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0E70 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4698 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A46E0 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0F04 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A8726 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A473C NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0F50 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0F74 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0FB8 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A47DA NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1402 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1421 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2C24 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1430 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0C4C TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1C7E NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2C8C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A1484 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0CEC TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A2CE0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A44FF NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0D40 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A4554 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A8DBB NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0DB4 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A0DE4 TerminateProcess, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 0_2_020A45F2 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560BF8 NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005686C3 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561078 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056101C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564834 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056109C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564880 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564970 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561163 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564907 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056113F |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561124 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005649FC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562A50 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562A5D |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561259 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562AC0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562AF4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005612E0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005612A4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056135C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056131B |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562B34 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562BD4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005613EC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562B84 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005613B4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560C4C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561C7E |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561430 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562C24 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005644FF |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562CE0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560CEC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561484 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00562C8C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564554 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560D40 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005645F2 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560DE4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056158E NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560DB4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005615BC NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00568DBB |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561670 NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560E70 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00561604 NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056463C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560E24 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005646E0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00564698 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560F50 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560F74 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560F04 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_0056473C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00568726 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_005647DA |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | Code function: 7_2_00560FB8 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0BF8 NtWriteVirtualMemory,TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F86C3 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0703 EnumWindows,NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1210 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2A5D |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1259 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2A50 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1286 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F12A4 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2AC0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2AF4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F12E0 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F131B TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2B34 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1331 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F135C TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1348 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2B84 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F13B4 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2BD4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F13EC TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F101C TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4834 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1078 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F109C TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4880 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4907 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F113F TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1124 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4970 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1163 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F49FC NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F463C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0E24 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0E70 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4698 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F46E0 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0F04 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F473C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F8726 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0F50 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0F74 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0FB8 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F47DA NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1402 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1430 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2C24 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1421 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0C4C TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1C7E NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2C8C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F1484 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F44FF NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0CEC TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F2CE0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F4554 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0D40 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F8DBB NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0DB4 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F45F2 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 15_2_021F0DE4 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40BF8 NtWriteVirtualMemory,TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B486C3 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40703 EnumWindows,NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B412A4 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41286 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42AF4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B412E0 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42AC0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41210 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42A50 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42A5D |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41259 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B413B4 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42B84 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B413EC TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42BD4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42B34 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41331 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4131B TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4135C TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41348 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4109C TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44880 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44834 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4101C TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41078 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B449FC NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4113F TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41124 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44907 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44970 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41163 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44698 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B446E0 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4463C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40E24 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40E70 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40FB8 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B447DA NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B4473C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B48726 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40F04 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40F74 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40F50 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41484 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42C8C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B444FF NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42CE0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40CEC TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41430 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B42C24 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41421 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41402 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B41C7E NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40C4C TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40DB4 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B48DBB NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B445F2 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40DE4 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B44554 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 16_2_02B40D40 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A0BF8 NtWriteVirtualMemory,TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A86C3 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A0703 EnumWindows,NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A1210 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A1259 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A2A5D |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A2A50 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A1286 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A12A4 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A2AC0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A12E0 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A2AF4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A131B TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A1331 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A2B34 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A1348 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A135C TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A2B84 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A13B4 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A2BD4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A13EC TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A101C TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4834 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A1078 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4880 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A109C TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4907 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A1124 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A113F TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A1163 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4970 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A49FC NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A0E24 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A463C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A0E70 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4698 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A46E0 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A0F04 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A8726 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A473C NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A0F50 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A0F74 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A0FB8 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A47DA NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A1402 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A1421 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A2C24 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A1430 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A0C4C TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A1C7E NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A2C8C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A1484 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A0CEC TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A2CE0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A44FF NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A0D40 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A4554 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A8DBB NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A0DB4 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A0DE4 TerminateProcess, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 17_2_020A45F2 NtWriteVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00560BF8 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_005686C3 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00561078 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_0056101C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00564834 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_0056109C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00564880 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00564970 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00561163 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00564907 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_0056113F |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00561124 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_005649FC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00562A50 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00562A5D |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00561259 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00562AC0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00562AF4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_005612E0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_005612A4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_0056135C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_0056131B |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00562B34 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00562BD4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_005613EC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00562B84 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_005613B4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00560C4C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00561C7E |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00561430 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00562C24 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_005644FF |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00562CE0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00560CEC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00561484 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00562C8C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00564554 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00560D40 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_005645F2 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00560DE4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_0056158E NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00560DB4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_005615BC NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00568DBB |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00561670 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00560E70 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00561604 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_0056463C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00560E24 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_005646E0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00564698 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00560F50 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00560F74 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00560F04 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_0056473C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00568726 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_005647DA |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 21_2_00560FB8 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00560BF8 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_005686C3 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00561078 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_0056101C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00564834 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_0056109C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00564880 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00564970 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00561163 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00564907 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_0056113F |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00561124 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_005649FC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00562A50 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00562A5D |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00561259 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00562AC0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00562AF4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_005612E0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_005612A4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_0056135C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_0056131B |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00562B34 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00562BD4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_005613EC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00562B84 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_005613B4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00560C4C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00561C7E |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00561430 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00562C24 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_005644FF |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00562CE0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00560CEC |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00561484 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00562C8C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00564554 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00560D40 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_005645F2 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00560DE4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_0056158E NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00560DB4 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_005615BC NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00568DBB |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00561670 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00560E70 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00561604 NtProtectVirtualMemory, |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_0056463C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00560E24 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_005646E0 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00564698 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00560F50 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00560F74 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00560F04 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_0056473C |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00568726 |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_005647DA |
Source: C:\Users\user\AppData\Roaming\win.exe | Code function: 22_2_00560FB8 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | RDTSC instruction interceptor: First address: 00000000020A0153 second address: 00000000020A0297 instructions: 0x00000000 rdtsc 0x00000002 popad 0x00000003 jmp 00007F8D488E6046h 0x00000005 test dl, bl 0x00000007 mov dword ptr [ebp-29h], edi 0x0000000a mov edi, 0B6FB570h 0x0000000f sub edi, 3B5E49F8h 0x00000015 xor edi, 6B2CFFD1h 0x0000001b sub edi, BB3D91A9h 0x00000021 sub esp, edi 0x00000023 mov edi, dword ptr [ebp-29h] 0x00000026 jmp 00007F8D488E6042h 0x00000028 test cl, cl 0x0000002a jmp 00007F8D488E6042h 0x0000002c cld 0x0000002d jmp 00007F8D488E6042h 0x0000002f cmp edx, ebx 0x00000031 jmp 00007F8D488E6046h 0x00000033 test dl, bl 0x00000035 jmp 00007F8D488E6046h 0x00000037 test ch, bh 0x00000039 jmp 00007F8D488E6042h 0x0000003b cmp edx, edx 0x0000003d push ebp 0x0000003e jmp 00007F8D488E6046h 0x00000040 test ah, bh 0x00000042 jmp 00007F8D488E6042h 0x00000044 jmp 00007F8D488E6050h 0x00000046 mov ebp, esp 0x00000048 jmp 00007F8D488E6046h 0x0000004a cmp cl, cl 0x0000004c mov dword ptr [ebp+0000013Ch], 00000000h 0x00000056 jmp 00007F8D488E6046h 0x00000058 pushad 0x00000059 mov eax, 000000AEh 0x0000005e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | RDTSC instruction interceptor: First address: 00000000020A5F52 second address: 00000000020A6004 instructions: 0x00000000 rdtsc 0x00000002 lfence 0x00000005 shl edx, 20h 0x00000008 or edx, eax 0x0000000a popad 0x0000000b pushad 0x0000000c cmp dl, 0000005Fh 0x0000000f cmp dword ptr [ebp+0000013Ch], 00000000h 0x00000016 jne 00007F8D48A2841Bh 0x0000001c jmp 00007F8D48A28216h 0x0000001e test eax, eax 0x00000020 mov eax, 86EE1AF5h 0x00000025 test bl, bl 0x00000027 xor eax, BD4846E4h 0x0000002c xor eax, 21283749h 0x00000031 xor eax, 1A8E6E61h 0x00000036 cmp dx, cx 0x00000039 mov dword ptr [ebp+00000182h], edx 0x0000003f mov edx, 115ADCC7h 0x00000044 cmp edx, edx 0x00000046 test ebx, ecx 0x00000048 sub edx, D410C907h 0x0000004e xor edx, A788CB95h 0x00000054 jmp 00007F8D48A28216h 0x00000056 test cl, FFFFFF97h 0x00000059 xor edx, 9AC2D839h 0x0000005f push edx 0x00000060 cmp cl, bl 0x00000062 mov edx, dword ptr [ebp+00000182h] 0x00000068 mov dword ptr [ebp+00000177h], edi 0x0000006e mov edi, 5BE1273Ch 0x00000073 xor edi, 5A5059E2h 0x00000079 test cl, cl 0x0000007b xor edi, 6B9E11F2h 0x00000081 cmp ecx, eax 0x00000083 xor edi, 064B1B42h 0x00000089 pushad 0x0000008a rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | RDTSC instruction interceptor: First address: 00000000020A6004 second address: 00000000020A6004 instructions: |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | RDTSC instruction interceptor: First address: 00000000020A8DD5 second address: 00000000020A8DD5 instructions: |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | RDTSC instruction interceptor: First address: 00000000020A5EBF second address: 00000000020A5EBF instructions: |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | RDTSC instruction interceptor: First address: 00000000020A7A03 second address: 00000000020A7A03 instructions: 0x00000000 rdtsc 0x00000002 mov eax, 00000001h 0x00000007 cpuid 0x00000009 popad 0x0000000a cmp bx, dx 0x0000000d jne 00007F8D48A28187h 0x0000000f push dword ptr [esp+04h] 0x00000013 jmp 00007F8D48A28212h 0x00000015 cmp al, cl 0x00000017 call 00007F8D48A2864Ch 0x0000001c cmp cl, bl 0x0000001e mov ebx, dword ptr [esp+04h] 0x00000022 xor ecx, ecx 0x00000024 test ecx, DBADF924h 0x0000002a add ecx, 02h 0x0000002d cmp word ptr [ebx+ecx], 0000h 0x00000032 jne 00007F8D48A281F8h 0x00000034 add ecx, 02h 0x00000037 cmp word ptr [ebx+ecx], 0000h 0x0000003c jne 00007F8D48A281F8h 0x0000003e add ecx, 02h 0x00000041 cmp word ptr [ebx+ecx], 0000h 0x00000046 jne 00007F8D48A281F8h 0x00000048 add ecx, 02h 0x0000004b cmp word ptr [ebx+ecx], 0000h 0x00000050 jne 00007F8D48A281F8h 0x00000052 add ecx, 02h 0x00000055 cmp word ptr [ebx+ecx], 0000h 0x0000005a jne 00007F8D48A281F8h 0x0000005c add ecx, 02h 0x0000005f cmp word ptr [ebx+ecx], 0000h 0x00000064 jne 00007F8D48A281F8h 0x00000066 add ecx, 02h 0x00000069 cmp word ptr [ebx+ecx], 0000h 0x0000006e jne 00007F8D48A281F8h 0x00000070 test dx, dx 0x00000073 retn 0004h 0x00000076 jmp 00007F8D48A28212h 0x00000078 cmp dl, cl 0x0000007a sub ecx, 02h 0x0000007d add eax, 02h 0x00000080 jmp 00007F8D48A28216h 0x00000082 cmp ax, 0000C33Eh 0x00000086 mov bx, word ptr [eax+ecx] 0x0000008a mov dx, word ptr [esi+ecx] 0x0000008e jmp 00007F8D48A28212h 0x00000090 pushad 0x00000091 rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | RDTSC instruction interceptor: First address: 00000000020A59EB second address: 00000000020A59EB instructions: |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | RDTSC instruction interceptor: First address: 00000000020A559F second address: 00000000020A559F instructions: |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | RDTSC instruction interceptor: First address: 0000000000560153 second address: 0000000000560297 instructions: 0x00000000 rdtsc 0x00000002 popad 0x00000003 jmp 00007F8D488E6046h 0x00000005 test dl, bl 0x00000007 mov dword ptr [ebp-29h], edi 0x0000000a mov edi, 0B6FB570h 0x0000000f sub edi, 3B5E49F8h 0x00000015 xor edi, 6B2CFFD1h 0x0000001b sub edi, BB3D91A9h 0x00000021 sub esp, edi 0x00000023 mov edi, dword ptr [ebp-29h] 0x00000026 jmp 00007F8D488E6042h 0x00000028 test cl, cl 0x0000002a jmp 00007F8D488E6042h 0x0000002c cld 0x0000002d jmp 00007F8D488E6042h 0x0000002f cmp edx, ebx 0x00000031 jmp 00007F8D488E6046h 0x00000033 test dl, bl 0x00000035 jmp 00007F8D488E6046h 0x00000037 test ch, bh 0x00000039 jmp 00007F8D488E6042h 0x0000003b cmp edx, edx 0x0000003d push ebp 0x0000003e jmp 00007F8D488E6046h 0x00000040 test ah, bh 0x00000042 jmp 00007F8D488E6042h 0x00000044 jmp 00007F8D488E6050h 0x00000046 mov ebp, esp 0x00000048 jmp 00007F8D488E6046h 0x0000004a cmp cl, cl 0x0000004c mov dword ptr [ebp+0000013Ch], 00000000h 0x00000056 jmp 00007F8D488E6046h 0x00000058 pushad 0x00000059 mov eax, 000000AEh 0x0000005e rdtsc |
Source: C:\Users\user\Desktop\SecuriteInfo.com.__vbaHresultCheckObj.9138.exe | RDTSC instruction interceptor: First address: 0000000000561732 second address: 0000000000561732 instructions: 0x00000000 rdtsc 0x00000002 mov eax, 00000001h 0x00000007 cpuid 0x00000009 popad 0x0000000a mov byte ptr [eax+ecx-01h], 0000005Eh 0x0000000f cmp cx, dx 0x00000012 xor byte ptr [eax+ecx-01h], 00000026h 0x00000017 xor byte ptr [eax+ecx-01h], 00000076h 0x0000001c cmp bl, 0000005Bh 0x0000001f add byte ptr [eax+ecx-01h], FFFFFFF2h 0x00000024 dec ecx 0x00000025 cmp ecx, 00000000h 0x00000028 jne 00007F8D48A281D7h 0x0000002a pushad 0x0000002b rdtsc |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 00000000021F0153 second address: 00000000021F0297 instructions: 0x00000000 rdtsc 0x00000002 popad 0x00000003 jmp 00007F8D488E6046h 0x00000005 test dl, bl 0x00000007 mov dword ptr [ebp-29h], edi 0x0000000a mov edi, 0B6FB570h 0x0000000f sub edi, 3B5E49F8h 0x00000015 xor edi, 6B2CFFD1h 0x0000001b sub edi, BB3D91A9h 0x00000021 sub esp, edi 0x00000023 mov edi, dword ptr [ebp-29h] 0x00000026 jmp 00007F8D488E6042h 0x00000028 test cl, cl 0x0000002a jmp 00007F8D488E6042h 0x0000002c cld 0x0000002d jmp 00007F8D488E6042h 0x0000002f cmp edx, ebx 0x00000031 jmp 00007F8D488E6046h 0x00000033 test dl, bl 0x00000035 jmp 00007F8D488E6046h 0x00000037 test ch, bh 0x00000039 jmp 00007F8D488E6042h 0x0000003b cmp edx, edx 0x0000003d push ebp 0x0000003e jmp 00007F8D488E6046h 0x00000040 test ah, bh 0x00000042 jmp 00007F8D488E6042h 0x00000044 jmp 00007F8D488E6050h 0x00000046 mov ebp, esp 0x00000048 jmp 00007F8D488E6046h 0x0000004a cmp cl, cl 0x0000004c mov dword ptr [ebp+0000013Ch], 00000000h 0x00000056 jmp 00007F8D488E6046h 0x00000058 pushad 0x00000059 mov eax, 000000AEh 0x0000005e rdtsc |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 00000000021F5F52 second address: 00000000021F6004 instructions: 0x00000000 rdtsc 0x00000002 lfence 0x00000005 shl edx, 20h 0x00000008 or edx, eax 0x0000000a popad 0x0000000b pushad 0x0000000c cmp dl, 0000005Fh 0x0000000f cmp dword ptr [ebp+0000013Ch], 00000000h 0x00000016 jne 00007F8D48A2841Bh 0x0000001c jmp 00007F8D48A28216h 0x0000001e test eax, eax 0x00000020 mov eax, 86EE1AF5h 0x00000025 test bl, bl 0x00000027 xor eax, BD4846E4h 0x0000002c xor eax, 21283749h 0x00000031 xor eax, 1A8E6E61h 0x00000036 cmp dx, cx 0x00000039 mov dword ptr [ebp+00000182h], edx 0x0000003f mov edx, 115ADCC7h 0x00000044 cmp edx, edx 0x00000046 test ebx, ecx 0x00000048 sub edx, D410C907h 0x0000004e xor edx, A788CB95h 0x00000054 jmp 00007F8D48A28216h 0x00000056 test cl, FFFFFF97h 0x00000059 xor edx, 9AC2D839h 0x0000005f push edx 0x00000060 cmp cl, bl 0x00000062 mov edx, dword ptr [ebp+00000182h] 0x00000068 mov dword ptr [ebp+00000177h], edi 0x0000006e mov edi, 5BE1273Ch 0x00000073 xor edi, 5A5059E2h 0x00000079 test cl, cl 0x0000007b xor edi, 6B9E11F2h 0x00000081 cmp ecx, eax 0x00000083 xor edi, 064B1B42h 0x00000089 pushad 0x0000008a rdtsc |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 00000000021F6004 second address: 00000000021F6004 instructions: |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 0000000002B40153 second address: 0000000002B40297 instructions: 0x00000000 rdtsc 0x00000002 popad 0x00000003 jmp 00007F8D48A28216h 0x00000005 test dl, bl 0x00000007 mov dword ptr [ebp-29h], edi 0x0000000a mov edi, 0B6FB570h 0x0000000f sub edi, 3B5E49F8h 0x00000015 xor edi, 6B2CFFD1h 0x0000001b sub edi, BB3D91A9h 0x00000021 sub esp, edi 0x00000023 mov edi, dword ptr [ebp-29h] 0x00000026 jmp 00007F8D48A28212h 0x00000028 test cl, cl 0x0000002a jmp 00007F8D48A28212h 0x0000002c cld 0x0000002d jmp 00007F8D48A28212h 0x0000002f cmp edx, ebx 0x00000031 jmp 00007F8D48A28216h 0x00000033 test dl, bl 0x00000035 jmp 00007F8D48A28216h 0x00000037 test ch, bh 0x00000039 jmp 00007F8D48A28212h 0x0000003b cmp edx, edx 0x0000003d push ebp 0x0000003e jmp 00007F8D48A28216h 0x00000040 test ah, bh 0x00000042 jmp 00007F8D48A28212h 0x00000044 jmp 00007F8D48A28220h 0x00000046 mov ebp, esp 0x00000048 jmp 00007F8D48A28216h 0x0000004a cmp cl, cl 0x0000004c mov dword ptr [ebp+0000013Ch], 00000000h 0x00000056 jmp 00007F8D48A28216h 0x00000058 pushad 0x00000059 mov eax, 000000AEh 0x0000005e rdtsc |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 0000000002B45F52 second address: 0000000002B46004 instructions: 0x00000000 rdtsc 0x00000002 lfence 0x00000005 shl edx, 20h 0x00000008 or edx, eax 0x0000000a popad 0x0000000b pushad 0x0000000c cmp dl, 0000005Fh 0x0000000f cmp dword ptr [ebp+0000013Ch], 00000000h 0x00000016 jne 00007F8D488E624Bh 0x0000001c jmp 00007F8D488E6046h 0x0000001e test eax, eax 0x00000020 mov eax, 86EE1AF5h 0x00000025 test bl, bl 0x00000027 xor eax, BD4846E4h 0x0000002c xor eax, 21283749h 0x00000031 xor eax, 1A8E6E61h 0x00000036 cmp dx, cx 0x00000039 mov dword ptr [ebp+00000182h], edx 0x0000003f mov edx, 115ADCC7h 0x00000044 cmp edx, edx 0x00000046 test ebx, ecx 0x00000048 sub edx, D410C907h 0x0000004e xor edx, A788CB95h 0x00000054 jmp 00007F8D488E6046h 0x00000056 test cl, FFFFFF97h 0x00000059 xor edx, 9AC2D839h 0x0000005f push edx 0x00000060 cmp cl, bl 0x00000062 mov edx, dword ptr [ebp+00000182h] 0x00000068 mov dword ptr [ebp+00000177h], edi 0x0000006e mov edi, 5BE1273Ch 0x00000073 xor edi, 5A5059E2h 0x00000079 test cl, cl 0x0000007b xor edi, 6B9E11F2h 0x00000081 cmp ecx, eax 0x00000083 xor edi, 064B1B42h 0x00000089 pushad 0x0000008a rdtsc |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 0000000002B46004 second address: 0000000002B46004 instructions: |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 00000000020A0153 second address: 00000000020A0297 instructions: 0x00000000 rdtsc 0x00000002 popad 0x00000003 jmp 00007F8D488E6046h 0x00000005 test dl, bl 0x00000007 mov dword ptr [ebp-29h], edi 0x0000000a mov edi, 0B6FB570h 0x0000000f sub edi, 3B5E49F8h 0x00000015 xor edi, 6B2CFFD1h 0x0000001b sub edi, BB3D91A9h 0x00000021 sub esp, edi 0x00000023 mov edi, dword ptr [ebp-29h] 0x00000026 jmp 00007F8D488E6042h 0x00000028 test cl, cl 0x0000002a jmp 00007F8D488E6042h 0x0000002c cld 0x0000002d jmp 00007F8D488E6042h 0x0000002f cmp edx, ebx 0x00000031 jmp 00007F8D488E6046h 0x00000033 test dl, bl 0x00000035 jmp 00007F8D488E6046h 0x00000037 test ch, bh 0x00000039 jmp 00007F8D488E6042h 0x0000003b cmp edx, edx 0x0000003d push ebp 0x0000003e jmp 00007F8D488E6046h 0x00000040 test ah, bh 0x00000042 jmp 00007F8D488E6042h 0x00000044 jmp 00007F8D488E6050h 0x00000046 mov ebp, esp 0x00000048 jmp 00007F8D488E6046h 0x0000004a cmp cl, cl 0x0000004c mov dword ptr [ebp+0000013Ch], 00000000h 0x00000056 jmp 00007F8D488E6046h 0x00000058 pushad 0x00000059 mov eax, 000000AEh 0x0000005e rdtsc |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 00000000020A5F52 second address: 00000000020A6004 instructions: 0x00000000 rdtsc 0x00000002 lfence 0x00000005 shl edx, 20h 0x00000008 or edx, eax 0x0000000a popad 0x0000000b pushad 0x0000000c cmp dl, 0000005Fh 0x0000000f cmp dword ptr [ebp+0000013Ch], 00000000h 0x00000016 jne 00007F8D48A2841Bh 0x0000001c jmp 00007F8D48A28216h 0x0000001e test eax, eax 0x00000020 mov eax, 86EE1AF5h 0x00000025 test bl, bl 0x00000027 xor eax, BD4846E4h 0x0000002c xor eax, 21283749h 0x00000031 xor eax, 1A8E6E61h 0x00000036 cmp dx, cx 0x00000039 mov dword ptr [ebp+00000182h], edx 0x0000003f mov edx, 115ADCC7h 0x00000044 cmp edx, edx 0x00000046 test ebx, ecx 0x00000048 sub edx, D410C907h 0x0000004e xor edx, A788CB95h 0x00000054 jmp 00007F8D48A28216h 0x00000056 test cl, FFFFFF97h 0x00000059 xor edx, 9AC2D839h 0x0000005f push edx 0x00000060 cmp cl, bl 0x00000062 mov edx, dword ptr [ebp+00000182h] 0x00000068 mov dword ptr [ebp+00000177h], edi 0x0000006e mov edi, 5BE1273Ch 0x00000073 xor edi, 5A5059E2h 0x00000079 test cl, cl 0x0000007b xor edi, 6B9E11F2h 0x00000081 cmp ecx, eax 0x00000083 xor edi, 064B1B42h 0x00000089 pushad 0x0000008a rdtsc |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 00000000020A6004 second address: 00000000020A6004 instructions: |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 00000000021F8DD5 second address: 00000000021F8DD5 instructions: |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 00000000021F5EBF second address: 00000000021F5EBF instructions: |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 00000000021F7A03 second address: 00000000021F7A03 instructions: 0x00000000 rdtsc 0x00000002 mov eax, 00000001h 0x00000007 cpuid 0x00000009 popad 0x0000000a cmp bx, dx 0x0000000d jne 00007F8D48A28187h 0x0000000f push dword ptr [esp+04h] 0x00000013 jmp 00007F8D48A28212h 0x00000015 cmp al, cl 0x00000017 call 00007F8D48A2864Ch 0x0000001c cmp cl, bl 0x0000001e mov ebx, dword ptr [esp+04h] 0x00000022 xor ecx, ecx 0x00000024 test ecx, DBADF924h 0x0000002a add ecx, 02h 0x0000002d cmp word ptr [ebx+ecx], 0000h 0x00000032 jne 00007F8D48A281F8h 0x00000034 add ecx, 02h 0x00000037 cmp word ptr [ebx+ecx], 0000h 0x0000003c jne 00007F8D48A281F8h 0x0000003e add ecx, 02h 0x00000041 cmp word ptr [ebx+ecx], 0000h 0x00000046 jne 00007F8D48A281F8h 0x00000048 add ecx, 02h 0x0000004b cmp word ptr [ebx+ecx], 0000h 0x00000050 jne 00007F8D48A281F8h 0x00000052 add ecx, 02h 0x00000055 cmp word ptr [ebx+ecx], 0000h 0x0000005a jne 00007F8D48A281F8h 0x0000005c add ecx, 02h 0x0000005f cmp word ptr [ebx+ecx], 0000h 0x00000064 jne 00007F8D48A281F8h 0x00000066 add ecx, 02h 0x00000069 cmp word ptr [ebx+ecx], 0000h 0x0000006e jne 00007F8D48A281F8h 0x00000070 test dx, dx 0x00000073 retn 0004h 0x00000076 jmp 00007F8D48A28212h 0x00000078 cmp dl, cl 0x0000007a sub ecx, 02h 0x0000007d add eax, 02h 0x00000080 jmp 00007F8D48A28216h 0x00000082 cmp ax, 0000C33Eh 0x00000086 mov bx, word ptr [eax+ecx] 0x0000008a mov dx, word ptr [esi+ecx] 0x0000008e jmp 00007F8D48A28212h 0x00000090 pushad 0x00000091 rdtsc |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 00000000021F59EB second address: 00000000021F59EB instructions: |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 00000000021F559F second address: 00000000021F559F instructions: |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 0000000000560153 second address: 0000000000560297 instructions: 0x00000000 rdtsc 0x00000002 popad 0x00000003 jmp 00007F8D488E6046h 0x00000005 test dl, bl 0x00000007 mov dword ptr [ebp-29h], edi 0x0000000a mov edi, 0B6FB570h 0x0000000f sub edi, 3B5E49F8h 0x00000015 xor edi, 6B2CFFD1h 0x0000001b sub edi, BB3D91A9h 0x00000021 sub esp, edi 0x00000023 mov edi, dword ptr [ebp-29h] 0x00000026 jmp 00007F8D488E6042h 0x00000028 test cl, cl 0x0000002a jmp 00007F8D488E6042h 0x0000002c cld 0x0000002d jmp 00007F8D488E6042h 0x0000002f cmp edx, ebx 0x00000031 jmp 00007F8D488E6046h 0x00000033 test dl, bl 0x00000035 jmp 00007F8D488E6046h 0x00000037 test ch, bh 0x00000039 jmp 00007F8D488E6042h 0x0000003b cmp edx, edx 0x0000003d push ebp 0x0000003e jmp 00007F8D488E6046h 0x00000040 test ah, bh 0x00000042 jmp 00007F8D488E6042h 0x00000044 jmp 00007F8D488E6050h 0x00000046 mov ebp, esp 0x00000048 jmp 00007F8D488E6046h 0x0000004a cmp cl, cl 0x0000004c mov dword ptr [ebp+0000013Ch], 00000000h 0x00000056 jmp 00007F8D488E6046h 0x00000058 pushad 0x00000059 mov eax, 000000AEh 0x0000005e rdtsc |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 0000000002B48DD5 second address: 0000000002B48DD5 instructions: |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 0000000002B45EBF second address: 0000000002B45EBF instructions: |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 0000000002B47A03 second address: 0000000002B47A03 instructions: 0x00000000 rdtsc 0x00000002 mov eax, 00000001h 0x00000007 cpuid 0x00000009 popad 0x0000000a cmp bx, dx 0x0000000d jne 00007F8D48A28187h 0x0000000f push dword ptr [esp+04h] 0x00000013 jmp 00007F8D48A28212h 0x00000015 cmp al, cl 0x00000017 call 00007F8D48A2864Ch 0x0000001c cmp cl, bl 0x0000001e mov ebx, dword ptr [esp+04h] 0x00000022 xor ecx, ecx 0x00000024 test ecx, DBADF924h 0x0000002a add ecx, 02h 0x0000002d cmp word ptr [ebx+ecx], 0000h 0x00000032 jne 00007F8D48A281F8h 0x00000034 add ecx, 02h 0x00000037 cmp word ptr [ebx+ecx], 0000h 0x0000003c jne 00007F8D48A281F8h 0x0000003e add ecx, 02h 0x00000041 cmp word ptr [ebx+ecx], 0000h 0x00000046 jne 00007F8D48A281F8h 0x00000048 add ecx, 02h 0x0000004b cmp word ptr [ebx+ecx], 0000h 0x00000050 jne 00007F8D48A281F8h 0x00000052 add ecx, 02h 0x00000055 cmp word ptr [ebx+ecx], 0000h 0x0000005a jne 00007F8D48A281F8h 0x0000005c add ecx, 02h 0x0000005f cmp word ptr [ebx+ecx], 0000h 0x00000064 jne 00007F8D48A281F8h 0x00000066 add ecx, 02h 0x00000069 cmp word ptr [ebx+ecx], 0000h 0x0000006e jne 00007F8D48A281F8h 0x00000070 test dx, dx 0x00000073 retn 0004h 0x00000076 jmp 00007F8D48A28212h 0x00000078 cmp dl, cl 0x0000007a sub ecx, 02h 0x0000007d add eax, 02h 0x00000080 jmp 00007F8D48A28216h 0x00000082 cmp ax, 0000C33Eh 0x00000086 mov bx, word ptr [eax+ecx] 0x0000008a mov dx, word ptr [esi+ecx] 0x0000008e jmp 00007F8D48A28212h 0x00000090 pushad 0x00000091 rdtsc |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 0000000002B459EB second address: 0000000002B459EB instructions: |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 0000000002B4559F second address: 0000000002B4559F instructions: |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 00000000020A8DD5 second address: 00000000020A8DD5 instructions: |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 00000000020A5EBF second address: 00000000020A5EBF instructions: |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 00000000020A7A03 second address: 00000000020A7A03 instructions: 0x00000000 rdtsc 0x00000002 mov eax, 00000001h 0x00000007 cpuid 0x00000009 popad 0x0000000a cmp bx, dx 0x0000000d jne 00007F8D48A28187h 0x0000000f push dword ptr [esp+04h] 0x00000013 jmp 00007F8D48A28212h 0x00000015 cmp al, cl 0x00000017 call 00007F8D48A2864Ch 0x0000001c cmp cl, bl 0x0000001e mov ebx, dword ptr [esp+04h] 0x00000022 xor ecx, ecx 0x00000024 test ecx, DBADF924h 0x0000002a add ecx, 02h 0x0000002d cmp word ptr [ebx+ecx], 0000h 0x00000032 jne 00007F8D48A281F8h 0x00000034 add ecx, 02h 0x00000037 cmp word ptr [ebx+ecx], 0000h 0x0000003c jne 00007F8D48A281F8h 0x0000003e add ecx, 02h 0x00000041 cmp word ptr [ebx+ecx], 0000h 0x00000046 jne 00007F8D48A281F8h 0x00000048 add ecx, 02h 0x0000004b cmp word ptr [ebx+ecx], 0000h 0x00000050 jne 00007F8D48A281F8h 0x00000052 add ecx, 02h 0x00000055 cmp word ptr [ebx+ecx], 0000h 0x0000005a jne 00007F8D48A281F8h 0x0000005c add ecx, 02h 0x0000005f cmp word ptr [ebx+ecx], 0000h 0x00000064 jne 00007F8D48A281F8h 0x00000066 add ecx, 02h 0x00000069 cmp word ptr [ebx+ecx], 0000h 0x0000006e jne 00007F8D48A281F8h 0x00000070 test dx, dx 0x00000073 retn 0004h 0x00000076 jmp 00007F8D48A28212h 0x00000078 cmp dl, cl 0x0000007a sub ecx, 02h 0x0000007d add eax, 02h 0x00000080 jmp 00007F8D48A28216h 0x00000082 cmp ax, 0000C33Eh 0x00000086 mov bx, word ptr [eax+ecx] 0x0000008a mov dx, word ptr [esi+ecx] 0x0000008e jmp 00007F8D48A28212h 0x00000090 pushad 0x00000091 rdtsc |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 00000000020A59EB second address: 00000000020A59EB instructions: |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 00000000020A559F second address: 00000000020A559F instructions: |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 0000000000561732 second address: 0000000000561732 instructions: 0x00000000 rdtsc 0x00000002 mov eax, 00000001h 0x00000007 cpuid 0x00000009 popad 0x0000000a mov byte ptr [eax+ecx-01h], 0000005Eh 0x0000000f cmp cx, dx 0x00000012 xor byte ptr [eax+ecx-01h], 00000026h 0x00000017 xor byte ptr [eax+ecx-01h], 00000076h 0x0000001c cmp bl, 0000005Bh 0x0000001f add byte ptr [eax+ecx-01h], FFFFFFF2h 0x00000024 dec ecx 0x00000025 cmp ecx, 00000000h 0x00000028 jne 00007F8D48A281D7h 0x0000002a pushad 0x0000002b rdtsc |
Source: C:\Users\user\AppData\Roaming\win.exe | RDTSC instruction interceptor: First address: 0000000000561732 second address: 0000000000561732 instructions: 0x00000000 rdtsc 0x00000002 mov eax, 00000001h 0x00000007 cpuid 0x00000009 popad 0x0000000a mov byte ptr [eax+ecx-01h], 0000005Eh 0x0000000f cmp cx, dx 0x00000012 xor byte ptr [eax+ecx-01h], 00000026h 0x00000017 xor byte ptr [eax+ecx-01h], 00000076h 0x0000001c cmp bl, 0000005Bh 0x0000001f add byte ptr [eax+ecx-01h], FFFFFFF2h 0x00000024 dec ecx 0x00000025 cmp ecx, 00000000h 0x00000028 jne 00007F8D488E6007h 0x0000002a pushad 0x0000002b rdtsc |