Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B699A NtAllocateVirtualMemory, |
0_2_022B699A |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B6A34 NtAllocateVirtualMemory, |
0_2_022B6A34 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B6A99 NtAllocateVirtualMemory, |
0_2_022B6A99 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B6AD4 NtAllocateVirtualMemory, |
0_2_022B6AD4 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B6B59 NtAllocateVirtualMemory, |
0_2_022B6B59 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B6BCC NtAllocateVirtualMemory, |
0_2_022B6BCC |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B6C02 NtAllocateVirtualMemory, |
0_2_022B6C02 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B69AE NtAllocateVirtualMemory, |
0_2_022B69AE |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B69E4 NtAllocateVirtualMemory, |
0_2_022B69E4 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_00405607 |
0_2_00405607 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_004032F5 |
0_2_004032F5 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B699A |
0_2_022B699A |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5627 |
0_2_022B5627 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B6A34 |
0_2_022B6A34 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B3209 |
0_2_022B3209 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BB608 |
0_2_022BB608 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BA614 |
0_2_022BA614 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5A68 |
0_2_022B5A68 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B3A62 |
0_2_022B3A62 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5278 |
0_2_022B5278 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B3249 |
0_2_022B3249 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BB650 |
0_2_022BB650 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BA6A0 |
0_2_022BA6A0 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5688 |
0_2_022B5688 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BB69C |
0_2_022BB69C |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B92EF |
0_2_022B92EF |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B3AF8 |
0_2_022B3AF8 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B4EF2 |
0_2_022B4EF2 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BA6F0 |
0_2_022BA6F0 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BA2D8 |
0_2_022BA2D8 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B2F27 |
0_2_022B2F27 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5B08 |
0_2_022B5B08 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5302 |
0_2_022B5302 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B3300 |
0_2_022B3300 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B4F1C |
0_2_022B4F1C |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5712 |
0_2_022B5712 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B9768 |
0_2_022B9768 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BA76C |
0_2_022BA76C |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5B58 |
0_2_022B5B58 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B33AC |
0_2_022B33AC |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B57A5 |
0_2_022B57A5 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B43B8 |
0_2_022B43B8 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B4F98 |
0_2_022B4F98 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5394 |
0_2_022B5394 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5BE7 |
0_2_022B5BE7 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BB3F8 |
0_2_022BB3F8 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BA7C7 |
0_2_022BA7C7 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B582E |
0_2_022B582E |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B4404 |
0_2_022B4404 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5004 |
0_2_022B5004 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5418 |
0_2_022B5418 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BB410 |
0_2_022BB410 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BA814 |
0_2_022BA814 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5069 |
0_2_022B5069 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5466 |
0_2_022B5466 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BB45D |
0_2_022BB45D |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B245C |
0_2_022B245C |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B2452 |
0_2_022B2452 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B4454 |
0_2_022B4454 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B58B8 |
0_2_022B58B8 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B44B2 |
0_2_022B44B2 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5C99 |
0_2_022B5C99 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BB493 |
0_2_022BB493 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BA890 |
0_2_022BA890 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B3895 |
0_2_022B3895 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BB4E0 |
0_2_022BB4E0 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B50F8 |
0_2_022B50F8 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B38FC |
0_2_022B38FC |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B54FC |
0_2_022B54FC |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BA4F1 |
0_2_022BA4F1 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B24C7 |
0_2_022B24C7 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B593E |
0_2_022B593E |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B4910 |
0_2_022B4910 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5578 |
0_2_022B5578 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B4544 |
0_2_022B4544 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B69AE |
0_2_022B69AE |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B39A0 |
0_2_022B39A0 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B3189 |
0_2_022B3189 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B4988 |
0_2_022B4988 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BB588 |
0_2_022BB588 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B5181 |
0_2_022B5181 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BA580 |
0_2_022BA580 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B9984 |
0_2_022B9984 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B39E8 |
0_2_022B39E8 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B69E4 |
0_2_022B69E4 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B51FA |
0_2_022B51FA |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BA5C8 |
0_2_022BA5C8 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B59CF |
0_2_022B59CF |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BB5CC |
0_2_022BB5CC |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B45D1 |
0_2_022B45D1 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
RDTSC instruction interceptor: First address: 00000000022B9BBF second address: 00000000022B9BBF instructions: 0x00000000 rdtsc 0x00000002 mov eax, 4A1014F8h 0x00000007 xor eax, 91CBACF6h 0x0000000c xor eax, 7F9DE2BDh 0x00000011 xor eax, A4465AB2h 0x00000016 cpuid 0x00000018 popad 0x00000019 call 00007F8D1C47F904h 0x0000001e lfence 0x00000021 mov edx, C49425E1h 0x00000026 xor edx, 40636495h 0x0000002c sub edx, D2D01692h 0x00000032 xor edx, CDD92AF6h 0x00000038 mov edx, dword ptr [edx] 0x0000003a lfence 0x0000003d jmp 00007F8D1C47F8F6h 0x0000003f test al, bl 0x00000041 cmp al, E3h 0x00000043 jmp 00007F8D1C47F8F6h 0x00000045 cmp ch, 0000006Dh 0x00000048 cmp bh, ah 0x0000004a ret 0x0000004b sub edx, esi 0x0000004d ret 0x0000004e add edi, edx 0x00000050 dec dword ptr [ebp+000000F8h] 0x00000056 cmp dword ptr [ebp+000000F8h], 00000000h 0x0000005d jne 00007F8D1C47F874h 0x0000005f jmp 00007F8D1C47F8F6h 0x00000061 test ah, ch 0x00000063 call 00007F8D1C47F8E6h 0x00000068 call 00007F8D1C47F925h 0x0000006d lfence 0x00000070 mov edx, C49425E1h 0x00000075 xor edx, 40636495h 0x0000007b sub edx, D2D01692h 0x00000081 xor edx, CDD92AF6h 0x00000087 mov edx, dword ptr [edx] 0x00000089 lfence 0x0000008c jmp 00007F8D1C47F8F6h 0x0000008e test al, bl 0x00000090 cmp al, E3h 0x00000092 jmp 00007F8D1C47F8F6h 0x00000094 cmp ch, 0000006Dh 0x00000097 cmp bh, ah 0x00000099 ret 0x0000009a mov esi, edx 0x0000009c pushad 0x0000009d rdtsc |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BA614 mov eax, dword ptr fs:[00000030h] |
0_2_022BA614 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B43B8 mov eax, dword ptr fs:[00000030h] |
0_2_022B43B8 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B3FB8 mov eax, dword ptr fs:[00000030h] |
0_2_022B3FB8 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B642D mov eax, dword ptr fs:[00000030h] |
0_2_022B642D |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B4404 mov eax, dword ptr fs:[00000030h] |
0_2_022B4404 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B9840 mov eax, dword ptr fs:[00000030h] |
0_2_022B9840 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B4454 mov eax, dword ptr fs:[00000030h] |
0_2_022B4454 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B3895 mov eax, dword ptr fs:[00000030h] |
0_2_022B3895 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BA4F1 mov eax, dword ptr fs:[00000030h] |
0_2_022BA4F1 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022B8D1F mov eax, dword ptr fs:[00000030h] |
0_2_022B8D1F |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BA580 mov eax, dword ptr fs:[00000030h] |
0_2_022BA580 |
Source: C:\Users\user\Desktop\vbc.exe.exe |
Code function: 0_2_022BA5C8 mov eax, dword ptr fs:[00000030h] |
0_2_022BA5C8 |
Source: vbc.exe.exe, 00000000.00000002.1279108448.0000000000D20000.00000002.00000001.sdmp |
Binary or memory string: Program Manager |
Source: vbc.exe.exe, 00000000.00000002.1279108448.0000000000D20000.00000002.00000001.sdmp |
Binary or memory string: Shell_TrayWnd |
Source: vbc.exe.exe, 00000000.00000002.1279108448.0000000000D20000.00000002.00000001.sdmp |
Binary or memory string: Progman |
Source: vbc.exe.exe, 00000000.00000002.1279108448.0000000000D20000.00000002.00000001.sdmp |
Binary or memory string: Progmanlock |