Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022468CC NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_0224879F NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02248C82 NtSetInformationThread, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022454E5 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022442CD NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02241B1A NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02241B5F NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02244B8E NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022443F1 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02247036 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02244071 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02242958 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02241E2C NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02244785 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_0224341B NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02248CD5 NtSetInformationThread, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_0224251E NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02248D58 NtSetInformationThread, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022455AC NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189A00 NtProtectVirtualMemory,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189A20 NtResumeThread,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189A50 NtCreateFile,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189660 NtAllocateVirtualMemory,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1896E0 NtFreeVirtualMemory,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189710 NtQueryInformationToken,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189780 NtMapViewOfSection,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1897A0 NtUnmapViewOfSection,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189840 NtDelayExecution,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189860 NtQuerySystemInformation,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1898F0 NtReadVirtualMemory,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189910 NtAdjustPrivilegesToken,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189540 NtReadFile,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1899A0 NtCreateSection,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1895D0 NtClose,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189610 NtEnumerateValueKey, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189A10 NtQuerySection, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189650 NtQueryValueKey, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189670 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189A80 NtOpenDirectoryObject, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1896D0 NtCreateKey, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E18A710 NtOpenProcessToken, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189B00 NtSetValueKey, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189730 NtQueryVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189770 NtSetInformationFile, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E18A770 NtOpenThread, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189760 NtOpenProcess, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E18A3B0 NtGetContextThread, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189FE0 NtCreateMutant, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189820 NtEnumerateKey, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E18B040 NtSuspendThread, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1898A0 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E18AD30 NtSetContextThread, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189520 NtWaitForSingleObject, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189950 NtQueueApcThread, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E189560 NtWriteFile, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1899D0 NtCreateProcessEx, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1895F0 NtQueryInformationFile, |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022408FD |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022468CC |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022458C9 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02248C82 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022454E5 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022404CA |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022472C3 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022442CD |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02241B2D |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02241B1A |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02247B73 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02241B5F |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02248385 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02244B8E |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02243B9A |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022443F1 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02247036 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_0224100E |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_0224881D |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02244071 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02240845 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022408B3 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022408E2 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022420E3 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022458F8 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022480D4 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_0224790A |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02247153 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02242958 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022429B0 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022451BE |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02242183 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02241E2C |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02240610 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_0224767B |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02243E5E |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022476B2 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02243EC4 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02247F03 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02243F0C |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02247F6D |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02240FB5 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02244785 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02240C24 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_0224341B |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02248446 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02243C4E |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02243CF0 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022434C4 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02248CD5 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_0224350F |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_0224251E |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02247D52 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02248D58 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02240D83 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02240D9C |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02245DCA |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E166E30 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17EBB0 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E15841F |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E201002 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E15B090 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14F900 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E140D20 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E164120 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E211D55 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E15D5E0 |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 00000000022401BE second address: 00000000022401BE instructions: |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 00000000022470C1 second address: 00000000022470D5 instructions: 0x00000000 rdtsc 0x00000002 mov eax, 00000001h 0x00000007 cpuid 0x00000009 popad 0x0000000a add edx, ecx 0x0000000c neg ecx 0x0000000e pushad 0x0000000f mov edx, 000000D8h 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 0000000002248DB2 second address: 0000000002248DFF instructions: 0x00000000 rdtsc 0x00000002 mov eax, 00000001h 0x00000007 cpuid 0x00000009 popad 0x0000000a mov eax, edi 0x0000000c test dl, dl 0x0000000e add eax, 00003004h 0x00000013 mov dword ptr [edi+00003000h], eax 0x00000019 test eax, eax 0x0000001b mov ecx, 07CEBD8Ah 0x00000020 cmp ax, 0000BB7Bh 0x00000024 sub ecx, 04255BC2h 0x0000002a xor ecx, 17A2670Fh 0x00000030 cmp al, bl 0x00000032 sub ecx, 140B05FBh 0x00000038 test eax, ebx 0x0000003a test edx, ebx 0x0000003c mov byte ptr [eax+ecx], 00000000h 0x00000040 dec ecx 0x00000041 mov dword ptr [ebp+0000025Ch], edi 0x00000047 mov edi, 4BBAF831h 0x0000004c pushad 0x0000004d rdtsc |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 0000000002248DFF second address: 0000000002248DFF instructions: 0x00000000 rdtsc 0x00000002 mov eax, 00000001h 0x00000007 cpuid 0x00000009 popad 0x0000000a test dl, dl 0x0000000c xor edi, 940AC00Fh 0x00000012 test eax, eax 0x00000014 xor edi, A987D7D4h 0x0000001a cmp ax, 0000BFCEh 0x0000001e sub edi, 7637EFEAh 0x00000024 cmp al, bl 0x00000026 cmp ecx, edi 0x00000028 mov edi, dword ptr [ebp+0000025Ch] 0x0000002e jnl 00007FA2E4BBF2EFh 0x00000030 test edx, ebx 0x00000032 mov byte ptr [eax+ecx], 00000000h 0x00000036 dec ecx 0x00000037 mov dword ptr [ebp+0000025Ch], edi 0x0000003d mov edi, 4BBAF831h 0x00000042 pushad 0x00000043 rdtsc |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 0000000002247A0D second address: 0000000002247A0D instructions: |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 00000000022475BB second address: 00000000022475BB instructions: 0x00000000 rdtsc 0x00000002 lfence 0x00000005 shl edx, 20h 0x00000008 or edx, eax 0x0000000a ret 0x0000000b mov esi, edx 0x0000000d pushad 0x0000000e mov eax, 52600CA0h 0x00000013 xor eax, 275578A5h 0x00000018 xor eax, AF7E784Ah 0x0000001d xor eax, DA4B0C4Eh 0x00000022 cpuid 0x00000024 jmp 00007FA2E4BBF35Eh 0x00000026 test dl, dl 0x00000028 bt ecx, 1Fh 0x0000002c test dx, ax 0x0000002f jc 00007FA2E4BBF90Eh 0x00000035 test bx, bx 0x00000038 test eax, ebx 0x0000003a popad 0x0000003b call 00007FA2E4BBF45Ah 0x00000040 lfence 0x00000043 rdtsc |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 0000000002247D7F second address: 0000000002247D7F instructions: |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 0000000002248035 second address: 0000000002248035 instructions: |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 0000000002240ADA second address: 0000000002240ADA instructions: |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 0000000002240DB2 second address: 0000000002240DB2 instructions: |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 0000000002241092 second address: 0000000002241092 instructions: |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 000000000224110D second address: 000000000224110D instructions: |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 00000000005675BB second address: 00000000005675BB instructions: 0x00000000 rdtsc 0x00000002 lfence 0x00000005 shl edx, 20h 0x00000008 or edx, eax 0x0000000a ret 0x0000000b mov esi, edx 0x0000000d pushad 0x0000000e mov eax, 52600CA0h 0x00000013 xor eax, 275578A5h 0x00000018 xor eax, AF7E784Ah 0x0000001d xor eax, DA4B0C4Eh 0x00000022 cpuid 0x00000024 jmp 00007FA2E439A94Eh 0x00000026 test dl, dl 0x00000028 bt ecx, 1Fh 0x0000002c test dx, ax 0x0000002f jc 00007FA2E439AEFEh 0x00000035 test bx, bx 0x00000038 test eax, ebx 0x0000003a popad 0x0000003b call 00007FA2E439AA4Ah 0x00000040 lfence 0x00000043 rdtsc |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 0000000000566FB5 second address: 0000000000567020 instructions: 0x00000000 rdtsc 0x00000002 popad 0x00000003 mov ebx, 9A3693F5h 0x00000008 cmp cx, cx 0x0000000b sub ebx, C476974Ah 0x00000011 test ax, 00008AFBh 0x00000015 sub ebx, E4232D93h 0x0000001b add ebx, 0E643128h 0x00000021 mov bx, word ptr [edx+ebx] 0x00000025 mov ax, word ptr [eax] 0x00000028 cmp dl, FFFFFFB4h 0x0000002b xor ax, cx 0x0000002e cmp bx, cx 0x00000031 xor bx, ax 0x00000034 mov word ptr [ebp+00000275h], di 0x0000003b mov di, 3896h 0x0000003f xor di, 7DA2h 0x00000044 test dx, ax 0x00000047 xor di, 97D1h 0x0000004c cmp cx, cx 0x0000004f xor di, 88A8h 0x00000054 pushad 0x00000055 mov si, 5497h 0x00000059 cmp si, 5497h 0x0000005e jne 00007FA2E4BBEECAh 0x00000064 popad 0x00000065 pushad 0x00000066 mov edx, 000000DBh 0x0000006b rdtsc |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 0000000000567020 second address: 0000000000566FB5 instructions: 0x00000000 rdtsc 0x00000002 popad 0x00000003 cmp bx, di 0x00000006 mov di, word ptr [ebp+00000275h] 0x0000000d je 00007FA2E439A936h 0x0000000f inc cx 0x00000011 jmp 00007FA2E439A899h 0x00000016 test al, A3h 0x00000018 mov eax, dword ptr [ebp+64h] 0x0000001b pushad 0x0000001c mov edx, 00000063h 0x00000021 rdtsc |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 0000000000567062 second address: 000000000056707C instructions: 0x00000000 rdtsc 0x00000002 mov eax, 00000001h 0x00000007 cpuid 0x00000009 popad 0x0000000a add dword ptr [ebp+0000019Dh], 431ADB4Eh 0x00000014 pushad 0x00000015 mov edx, 0000008Fh 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 000000000056707C second address: 000000000056707C instructions: 0x00000000 rdtsc 0x00000002 popad 0x00000003 sub dword ptr [ebp+0000019Dh], 293F2C89h 0x0000000d sub dword ptr [ebp+0000019Dh], E4024E33h 0x00000017 pushad 0x00000018 mov bh, 30h 0x0000001a cmp bh, 00000030h 0x0000001d jne 00007FA2E4397793h 0x00000023 popad 0x00000024 cmp ebx, dword ptr [ebp+0000019Dh] 0x0000002a jnl 00007FA2E439A929h 0x0000002c add ebx, 02h 0x0000002f jmp 00007FA2E439A8BFh 0x00000031 test bh, 0000005Ch 0x00000034 xor word ptr [eax+ebx], cx 0x00000038 test dl, FFFFFF99h 0x0000003b mov dword ptr [ebp+0000019Dh], CA26A2BDh 0x00000045 test bx, ax 0x00000048 pushad 0x00000049 nop 0x0000004a nop 0x0000004b mov eax, 00000001h 0x00000050 cpuid 0x00000052 popad 0x00000053 add dword ptr [ebp+0000019Dh], 431ADB4Eh 0x0000005d pushad 0x0000005e mov edx, 0000008Fh 0x00000063 rdtsc |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 00000000004098E4 second address: 00000000004098EA instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | RDTSC instruction interceptor: First address: 0000000000409B4E second address: 0000000000409B54 instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02246B93 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022450CA mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02242958 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_022471A9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_0224341B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 1_2_02247D52 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14AA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14AA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E163A1C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17A61C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17A61C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E178E00 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E158A0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1FFE3F mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14E620 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E218A62 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1D4257 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E149240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E149240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E149240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E149240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E157E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E157E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E157E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E157E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E157E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E157E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E18927A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E16AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E16AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E16AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E16AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E16AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E15766D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1FB260 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1FB260 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17D294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17D294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E210EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E210EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E210EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1DFE87 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E15AAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E15AAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17FAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1452A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1452A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1452A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1452A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1452A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C46A7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1736CC mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1FFEC0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E188EC7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1716E0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E218ED6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1576E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E16F716 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1DFF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1DFF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17A70E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17A70E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17E730 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E21070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E21070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E144F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E144F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E20131B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E218F6A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14F358 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14DB40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E15EF40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E173B7A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E173B7A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14DB60 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E15FF60 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E218B58 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E158794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E215BA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17B390 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C7794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C7794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C7794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E151B8F mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E151B8F mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1FD380 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E20138A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1837F5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1703E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1703E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1703E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1703E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1703E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1703E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C7016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C7016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C7016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C6C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C6C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C6C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C6C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E201C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E201C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E201C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E201C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E201C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E201C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E201C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E201C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E201C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E201C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E201C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E201C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E201C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E201C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E21740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E21740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E21740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E214015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E214015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17BC2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E15B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E15B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E15B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E15B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E160050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E160050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1DC450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1DC450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E202073 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E211074 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17A44B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E16746D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E15849B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E149080 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C3884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C3884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17F0BF mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17F0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17F0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1890AF mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1DB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1DB8D0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1DB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1DB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1DB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1DB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E2014FB mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C6CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C6CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C6CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E218CD6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E149100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E149100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E149100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E218D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E153D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E153D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E153D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E153D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E153D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E153D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E153D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E153D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E153D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E153D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E153D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E153D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E153D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14AD30 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1CA537 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E174D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E174D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E174D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E164120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E164120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E164120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E164120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E164120 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E167D50 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E16B944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E16B944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E183D43 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C3540 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E16C577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E16C577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14B171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14B171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14C962 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17FD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17FD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E17A185 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E16C182 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E142D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E142D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E142D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E142D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E142D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E171DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E171DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E171DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1735A1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1761A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1761A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1C69A6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1F8DF1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E14B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E1D41E8 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E15D5E0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\ZGNX11JMSc.exe | Code function: 36_2_1E15D5E0 mov eax, dword ptr fs:[00000030h] |