Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140034870 |
0_2_0000000140034870 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140035270 |
0_2_0000000140035270 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140048AC0 |
0_2_0000000140048AC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014005C340 |
0_2_000000014005C340 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140065B80 |
0_2_0000000140065B80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006A4B0 |
0_2_000000014006A4B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400524B0 |
0_2_00000001400524B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140026CC0 |
0_2_0000000140026CC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014004BD40 |
0_2_000000014004BD40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400495B0 |
0_2_00000001400495B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140036F30 |
0_2_0000000140036F30 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140069010 |
0_2_0000000140069010 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140001010 |
0_2_0000000140001010 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140066020 |
0_2_0000000140066020 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002F840 |
0_2_000000014002F840 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014005D850 |
0_2_000000014005D850 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140064080 |
0_2_0000000140064080 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140010880 |
0_2_0000000140010880 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400688A0 |
0_2_00000001400688A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002D0D0 |
0_2_000000014002D0D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400018D0 |
0_2_00000001400018D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140016100 |
0_2_0000000140016100 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014001D100 |
0_2_000000014001D100 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002A110 |
0_2_000000014002A110 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014001D910 |
0_2_000000014001D910 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140015120 |
0_2_0000000140015120 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014000B120 |
0_2_000000014000B120 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014004F940 |
0_2_000000014004F940 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140039140 |
0_2_0000000140039140 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140023140 |
0_2_0000000140023140 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140057950 |
0_2_0000000140057950 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014001E170 |
0_2_000000014001E170 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140002980 |
0_2_0000000140002980 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400611A0 |
0_2_00000001400611A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400389A0 |
0_2_00000001400389A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400381A0 |
0_2_00000001400381A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002E1B0 |
0_2_000000014002E1B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400139D0 |
0_2_00000001400139D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400319F0 |
0_2_00000001400319F0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002EA00 |
0_2_000000014002EA00 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140022A00 |
0_2_0000000140022A00 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014003B220 |
0_2_000000014003B220 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140067A40 |
0_2_0000000140067A40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140069A50 |
0_2_0000000140069A50 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140007A60 |
0_2_0000000140007A60 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014003AAC0 |
0_2_000000014003AAC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014003A2E0 |
0_2_000000014003A2E0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140062B00 |
0_2_0000000140062B00 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140018300 |
0_2_0000000140018300 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002FB20 |
0_2_000000014002FB20 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140031340 |
0_2_0000000140031340 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140022340 |
0_2_0000000140022340 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140017B40 |
0_2_0000000140017B40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014000BB40 |
0_2_000000014000BB40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014004EB60 |
0_2_000000014004EB60 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140005370 |
0_2_0000000140005370 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002CB80 |
0_2_000000014002CB80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B390 |
0_2_000000014006B390 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140054BA0 |
0_2_0000000140054BA0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140033BB0 |
0_2_0000000140033BB0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400263C0 |
0_2_00000001400263C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400123C0 |
0_2_00000001400123C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140063BD0 |
0_2_0000000140063BD0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400663F0 |
0_2_00000001400663F0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140023BF0 |
0_2_0000000140023BF0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B41B |
0_2_000000014006B41B |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B424 |
0_2_000000014006B424 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B42D |
0_2_000000014006B42D |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B436 |
0_2_000000014006B436 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B43D |
0_2_000000014006B43D |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140024440 |
0_2_0000000140024440 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140005C40 |
0_2_0000000140005C40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B446 |
0_2_000000014006B446 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014005F490 |
0_2_000000014005F490 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140022D00 |
0_2_0000000140022D00 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140035520 |
0_2_0000000140035520 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140019D20 |
0_2_0000000140019D20 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140030530 |
0_2_0000000140030530 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140023530 |
0_2_0000000140023530 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140031540 |
0_2_0000000140031540 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140033540 |
0_2_0000000140033540 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014007BD50 |
0_2_000000014007BD50 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140078570 |
0_2_0000000140078570 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140019580 |
0_2_0000000140019580 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400205A0 |
0_2_00000001400205A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140025DB0 |
0_2_0000000140025DB0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140071DC0 |
0_2_0000000140071DC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014000C5C0 |
0_2_000000014000C5C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002DDE0 |
0_2_000000014002DDE0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140031DF0 |
0_2_0000000140031DF0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014000DDF0 |
0_2_000000014000DDF0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140001620 |
0_2_0000000140001620 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140018630 |
0_2_0000000140018630 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140032650 |
0_2_0000000140032650 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140064E80 |
0_2_0000000140064E80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140016E80 |
0_2_0000000140016E80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140007EA0 |
0_2_0000000140007EA0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400286B0 |
0_2_00000001400286B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140006EB0 |
0_2_0000000140006EB0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400276C0 |
0_2_00000001400276C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002FEC0 |
0_2_000000014002FEC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002EED0 |
0_2_000000014002EED0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002B6E0 |
0_2_000000014002B6E0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140053F20 |
0_2_0000000140053F20 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140022730 |
0_2_0000000140022730 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140029780 |
0_2_0000000140029780 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140018F80 |
0_2_0000000140018F80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014003EFB0 |
0_2_000000014003EFB0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400067B0 |
0_2_00000001400067B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400667D0 |
0_2_00000001400667D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140060FE0 |
0_2_0000000140060FE0 |
Source: C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe |
Code function: 27_2_00007FF77B972EF4 |
27_2_00007FF77B972EF4 |
Source: C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe |
Code function: 27_2_00007FF77B988850 |
27_2_00007FF77B988850 |
Source: C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe |
Code function: 27_2_00007FF77B988E2C |
27_2_00007FF77B988E2C |
Source: C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe |
Code function: 27_2_00007FF77B97139C |
27_2_00007FF77B97139C |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647F74938 |
35_2_00007FF647F74938 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FB7CE0 |
35_2_00007FF647FB7CE0 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FBAD98 |
35_2_00007FF647FBAD98 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FB8DD8 |
35_2_00007FF647FB8DD8 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647F73ED4 |
35_2_00007FF647F73ED4 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FBDEC8 |
35_2_00007FF647FBDEC8 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FB9F70 |
35_2_00007FF647FB9F70 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647F81FC0 |
35_2_00007FF647F81FC0 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647F94FE0 |
35_2_00007FF647F94FE0 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647F88168 |
35_2_00007FF647F88168 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FBB274 |
35_2_00007FF647FBB274 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647F92324 |
35_2_00007FF647F92324 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FB53A0 |
35_2_00007FF647FB53A0 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FC650D |
35_2_00007FF647FC650D |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FC0634 |
35_2_00007FF647FC0634 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647F9B640 |
35_2_00007FF647F9B640 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FB563C |
35_2_00007FF647FB563C |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FB67F0 |
35_2_00007FF647FB67F0 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FC17EC |
35_2_00007FF647FC17EC |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FC5875 |
35_2_00007FF647FC5875 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140046C90 NtClose, |
0_2_0000000140046C90 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006A4B0 NtQuerySystemInformation, |
0_2_000000014006A4B0 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FBBA40 NtQuerySystemInformation, |
35_2_00007FF647FBBA40 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FB0C64 RtlInitUnicodeString,memset,NtOpenSymbolicLinkObject,memset,NtQuerySymbolicLinkObject,_wcsnicmp,NtClose,NtClose,_CxxThrowException, |
35_2_00007FF647FB0C64 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FBAD98 memset,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,FindFirstFileW,GetLastError,GetLastError,_wcsicmp,_wcsicmp,GetLastError,GetCurrentThread,NtQueryInformationThread,FindNextFileW,GetLastError,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,FindClose,SetLastError, |
35_2_00007FF647FBAD98 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FB8DD8 memset,NtWriteFile,NtReadFile,NtWriteFile,NtWriteFile,NtWriteFile, |
35_2_00007FF647FB8DD8 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FB9DF8 NtReadFile, |
35_2_00007FF647FB9DF8 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FB9E3C memset,CreateFileW,NtClose, |
35_2_00007FF647FB9E3C |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FB9F70 GetLastError,GetLastError,GetLastError,GetProcessHeap,HeapFree,GetLastError,GetLastError,GetLastError,RtlImageNtHeader,GetLastError,GetLastError,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetLastError,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,CreateFileW,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,GetProcessHeap,HeapAlloc,memset,WriteFile,GetLastError,GetProcessHeap,HeapFree,NtClose,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,SetLastError,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,SetLastError, |
35_2_00007FF647FB9F70 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FB50C8 NtClose, |
35_2_00007FF647FB50C8 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FB90D8 RtlInitUnicodeString,NtOpenFile,NtCreateEvent,NtDeviceIoControlFile,NtWaitForSingleObject,NtClose,NtClose, |
35_2_00007FF647FB90D8 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647F990E8 memset,NtQuerySystemInformation,_CxxThrowException, |
35_2_00007FF647F990E8 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647F993BC CreateFileW,NtQueryVolumeInformationFile,CloseHandle,_CxxThrowException,_CxxThrowException, |
35_2_00007FF647F993BC |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FB94F0 CreateFileW,GetLastError,GetProcessHeap,HeapAlloc,NtQueryInformationFile,NtOpenProcess,NtQueryInformationProcess,GetProcessHeap,HeapAlloc,NtQueryInformationProcess,NtClose,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,CloseHandle,GetProcessHeap,HeapFree, |
35_2_00007FF647FB94F0 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FC17EC GetFileAttributesW,SetFileAttributesW,CreateFileW,GetFileInformationByHandle,GetModuleHandleW,GetProcAddress,GetProcAddress,memset,GetFullPathNameW,HeapAlloc,RtlDeleteBoundaryDescriptor,_wcsicmp,FindClose,GetProcessHeap,HeapFree,GetLastError,GetLastError,NtSetInformationFile,RtlNtStatusToDosError,CloseHandle,SetFileAttributesW,GetProcessHeap,HeapFree,GetLastError,GetLastError,GetProcessHeap,HeapFree,SetLastError, |
35_2_00007FF647FC17EC |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Code function: 35_2_00007FF647FB97EC GetCurrentThread,NtQueryInformationThread,GetCurrentThread,NtSetInformationThread, |
35_2_00007FF647FB97EC |
Source: unknown |
Process created: C:\Windows\System32\loaddll64.exe loaddll64.exe 'C:\Users\user\Desktop\3PgaI7gtQn.dll' |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\3PgaI7gtQn.dll',#1 |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,CopyPropVariant |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\3PgaI7gtQn.dll',#1 |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,CreatePropVariant |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,CreatePropertyStore |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,DestroyPropVariant |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,FormatTagFromWfx |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,GetAMSubtypeFromD3DFormat |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,GetD3DFormatFromMFSubtype |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAddPeriodicCallback |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAllocateSerialWorkQueue |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAllocateWorkQueue |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAllocateWorkQueueEx |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAppendCollection |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAverageTimePerFrameToFrameRate |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginCreateFile |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\bdeunlock.exe C:\Windows\system32\bdeunlock.exe |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginGetHostByName |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginRegisterWorkQueueWithMMCSS |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\CameraSettingsUIHost.exe C:\Windows\system32\CameraSettingsUIHost.exe |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginRegisterWorkQueueWithMMCSSEx |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\43ip\CameraSettingsUIHost.exe C:\Users\user\AppData\Local\43ip\CameraSettingsUIHost.exe |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginUnregisterWorkQueueWithMMCSS |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\pwcreator.exe C:\Windows\system32\pwcreator.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFCalculateBitmapImageSize |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\lpksetup.exe C:\Windows\system32\lpksetup.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\fbMtwkN2S\lpksetup.exe C:\Users\user\AppData\Local\fbMtwkN2S\lpksetup.exe |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFCalculateImageSize |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\3PgaI7gtQn.dll',#1 |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,CopyPropVariant |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,CreatePropVariant |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,CreatePropertyStore |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,DestroyPropVariant |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,FormatTagFromWfx |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,GetAMSubtypeFromD3DFormat |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,GetD3DFormatFromMFSubtype |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAddPeriodicCallback |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAllocateSerialWorkQueue |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAllocateWorkQueue |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAllocateWorkQueueEx |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAppendCollection |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAverageTimePerFrameToFrameRate |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginCreateFile |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginGetHostByName |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginRegisterWorkQueueWithMMCSS |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginRegisterWorkQueueWithMMCSSEx |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginUnregisterWorkQueueWithMMCSS |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFCalculateBitmapImageSize |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFCalculateImageSize |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\3PgaI7gtQn.dll',#1 |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\bdeunlock.exe C:\Windows\system32\bdeunlock.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\CameraSettingsUIHost.exe C:\Windows\system32\CameraSettingsUIHost.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\43ip\CameraSettingsUIHost.exe C:\Users\user\AppData\Local\43ip\CameraSettingsUIHost.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\pwcreator.exe C:\Windows\system32\pwcreator.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\lpksetup.exe C:\Windows\system32\lpksetup.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\fbMtwkN2S\lpksetup.exe C:\Users\user\AppData\Local\fbMtwkN2S\lpksetup.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .qkm |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .cvjb |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .tlmkv |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .wucsxe |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .fltwtj |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .sfplio |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .rpg |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .bewzc |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .vksvaw |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .wmhg |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .kswemc |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .kaxfk |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .pjf |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .favk |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .vhtukj |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .hmbyox |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .djv |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .hpern |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .czzwqg |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .jxjvn |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .jfsnsk |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .nzvifv |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .tops |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .lrjye |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .qwdob |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .xcq |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .ifxvj |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .fgpyt |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .tgzhe |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .oocus |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .ybtor |
Source: 3PgaI7gtQn.dll |
Static PE information: section name: .gxixek |
Source: bdeunlock.exe.4.dr |
Static PE information: section name: .imrsiv |
Source: CameraSettingsUIHost.exe.4.dr |
Static PE information: section name: .imrsiv |
Source: mmc.exe.4.dr |
Static PE information: section name: .didat |
Source: DUI70.dll.4.dr |
Static PE information: section name: .qkm |
Source: DUI70.dll.4.dr |
Static PE information: section name: .cvjb |
Source: DUI70.dll.4.dr |
Static PE information: section name: .tlmkv |
Source: DUI70.dll.4.dr |
Static PE information: section name: .wucsxe |
Source: DUI70.dll.4.dr |
Static PE information: section name: .fltwtj |
Source: DUI70.dll.4.dr |
Static PE information: section name: .sfplio |
Source: DUI70.dll.4.dr |
Static PE information: section name: .rpg |
Source: DUI70.dll.4.dr |
Static PE information: section name: .bewzc |
Source: DUI70.dll.4.dr |
Static PE information: section name: .vksvaw |
Source: DUI70.dll.4.dr |
Static PE information: section name: .wmhg |
Source: DUI70.dll.4.dr |
Static PE information: section name: .kswemc |
Source: DUI70.dll.4.dr |
Static PE information: section name: .kaxfk |
Source: DUI70.dll.4.dr |
Static PE information: section name: .pjf |
Source: DUI70.dll.4.dr |
Static PE information: section name: .favk |
Source: DUI70.dll.4.dr |
Static PE information: section name: .vhtukj |
Source: DUI70.dll.4.dr |
Static PE information: section name: .hmbyox |
Source: DUI70.dll.4.dr |
Static PE information: section name: .djv |
Source: DUI70.dll.4.dr |
Static PE information: section name: .hpern |
Source: DUI70.dll.4.dr |
Static PE information: section name: .czzwqg |
Source: DUI70.dll.4.dr |
Static PE information: section name: .jxjvn |
Source: DUI70.dll.4.dr |
Static PE information: section name: .jfsnsk |
Source: DUI70.dll.4.dr |
Static PE information: section name: .nzvifv |
Source: DUI70.dll.4.dr |
Static PE information: section name: .tops |
Source: DUI70.dll.4.dr |
Static PE information: section name: .lrjye |
Source: DUI70.dll.4.dr |
Static PE information: section name: .qwdob |
Source: DUI70.dll.4.dr |
Static PE information: section name: .xcq |
Source: DUI70.dll.4.dr |
Static PE information: section name: .ifxvj |
Source: DUI70.dll.4.dr |
Static PE information: section name: .fgpyt |
Source: DUI70.dll.4.dr |
Static PE information: section name: .tgzhe |
Source: DUI70.dll.4.dr |
Static PE information: section name: .oocus |
Source: DUI70.dll.4.dr |
Static PE information: section name: .ybtor |
Source: DUI70.dll.4.dr |
Static PE information: section name: .gxixek |
Source: DUI70.dll.4.dr |
Static PE information: section name: .bcdsk |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .qkm |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .cvjb |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .tlmkv |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .wucsxe |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .fltwtj |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .sfplio |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .rpg |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .bewzc |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .vksvaw |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .wmhg |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .kswemc |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .kaxfk |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .pjf |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .favk |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .vhtukj |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .hmbyox |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .djv |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .hpern |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .czzwqg |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .jxjvn |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .jfsnsk |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .nzvifv |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .tops |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .lrjye |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .qwdob |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .xcq |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .ifxvj |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .fgpyt |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .tgzhe |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .oocus |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .ybtor |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .gxixek |
Source: DUI70.dll0.4.dr |
Static PE information: section name: .rupume |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .qkm |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .cvjb |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .tlmkv |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .wucsxe |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .fltwtj |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .sfplio |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .rpg |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .bewzc |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .vksvaw |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .wmhg |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .kswemc |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .kaxfk |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .pjf |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .favk |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .vhtukj |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .hmbyox |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .djv |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .hpern |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .czzwqg |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .jxjvn |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .jfsnsk |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .nzvifv |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .tops |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .lrjye |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .qwdob |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .xcq |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .ifxvj |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .fgpyt |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .tgzhe |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .oocus |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .ybtor |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .gxixek |
Source: WINBRAND.dll.4.dr |
Static PE information: section name: .bbmsy |
Source: dpx.dll.4.dr |
Static PE information: section name: .qkm |
Source: dpx.dll.4.dr |
Static PE information: section name: .cvjb |
Source: dpx.dll.4.dr |
Static PE information: section name: .tlmkv |
Source: dpx.dll.4.dr |
Static PE information: section name: .wucsxe |
Source: dpx.dll.4.dr |
Static PE information: section name: .fltwtj |
Source: dpx.dll.4.dr |
Static PE information: section name: .sfplio |
Source: dpx.dll.4.dr |
Static PE information: section name: .rpg |
Source: dpx.dll.4.dr |
Static PE information: section name: .bewzc |
Source: dpx.dll.4.dr |
Static PE information: section name: .vksvaw |
Source: dpx.dll.4.dr |
Static PE information: section name: .wmhg |
Source: dpx.dll.4.dr |
Static PE information: section name: .kswemc |
Source: dpx.dll.4.dr |
Static PE information: section name: .kaxfk |
Source: dpx.dll.4.dr |
Static PE information: section name: .pjf |
Source: dpx.dll.4.dr |
Static PE information: section name: .favk |
Source: dpx.dll.4.dr |
Static PE information: section name: .vhtukj |
Source: dpx.dll.4.dr |
Static PE information: section name: .hmbyox |
Source: dpx.dll.4.dr |
Static PE information: section name: .djv |
Source: dpx.dll.4.dr |
Static PE information: section name: .hpern |
Source: dpx.dll.4.dr |
Static PE information: section name: .czzwqg |
Source: dpx.dll.4.dr |
Static PE information: section name: .jxjvn |
Source: dpx.dll.4.dr |
Static PE information: section name: .jfsnsk |
Source: dpx.dll.4.dr |
Static PE information: section name: .nzvifv |
Source: dpx.dll.4.dr |
Static PE information: section name: .tops |
Source: dpx.dll.4.dr |
Static PE information: section name: .lrjye |
Source: dpx.dll.4.dr |
Static PE information: section name: .qwdob |
Source: dpx.dll.4.dr |
Static PE information: section name: .xcq |
Source: dpx.dll.4.dr |
Static PE information: section name: .ifxvj |
Source: dpx.dll.4.dr |
Static PE information: section name: .fgpyt |
Source: dpx.dll.4.dr |
Static PE information: section name: .tgzhe |
Source: dpx.dll.4.dr |
Static PE information: section name: .oocus |
Source: dpx.dll.4.dr |
Static PE information: section name: .ybtor |
Source: dpx.dll.4.dr |
Static PE information: section name: .gxixek |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .qkm |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .cvjb |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .tlmkv |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .wucsxe |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .fltwtj |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .sfplio |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .rpg |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .bewzc |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .vksvaw |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .wmhg |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .kswemc |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .kaxfk |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .pjf |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .favk |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .vhtukj |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .hmbyox |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .djv |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .hpern |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .czzwqg |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .jxjvn |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .jfsnsk |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .nzvifv |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .tops |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .lrjye |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .qwdob |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .xcq |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .ifxvj |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .fgpyt |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .tgzhe |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .oocus |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .ybtor |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .gxixek |
Source: MFC42u.dll.4.dr |
Static PE information: section name: .zlxpb |
Source: VERSION.dll.4.dr |
Static PE information: section name: .qkm |
Source: VERSION.dll.4.dr |
Static PE information: section name: .cvjb |
Source: VERSION.dll.4.dr |
Static PE information: section name: .tlmkv |
Source: VERSION.dll.4.dr |
Static PE information: section name: .wucsxe |
Source: VERSION.dll.4.dr |
Static PE information: section name: .fltwtj |
Source: VERSION.dll.4.dr |
Static PE information: section name: .sfplio |
Source: VERSION.dll.4.dr |
Static PE information: section name: .rpg |
Source: VERSION.dll.4.dr |
Static PE information: section name: .bewzc |
Source: VERSION.dll.4.dr |
Static PE information: section name: .vksvaw |
Source: VERSION.dll.4.dr |
Static PE information: section name: .wmhg |
Source: VERSION.dll.4.dr |
Static PE information: section name: .kswemc |
Source: VERSION.dll.4.dr |
Static PE information: section name: .kaxfk |
Source: VERSION.dll.4.dr |
Static PE information: section name: .pjf |
Source: VERSION.dll.4.dr |
Static PE information: section name: .favk |
Source: VERSION.dll.4.dr |
Static PE information: section name: .vhtukj |
Source: VERSION.dll.4.dr |
Static PE information: section name: .hmbyox |
Source: VERSION.dll.4.dr |
Static PE information: section name: .djv |
Source: VERSION.dll.4.dr |
Static PE information: section name: .hpern |
Source: VERSION.dll.4.dr |
Static PE information: section name: .czzwqg |
Source: VERSION.dll.4.dr |
Static PE information: section name: .jxjvn |
Source: VERSION.dll.4.dr |
Static PE information: section name: .jfsnsk |
Source: VERSION.dll.4.dr |
Static PE information: section name: .nzvifv |
Source: VERSION.dll.4.dr |
Static PE information: section name: .tops |
Source: VERSION.dll.4.dr |
Static PE information: section name: .lrjye |
Source: VERSION.dll.4.dr |
Static PE information: section name: .qwdob |
Source: VERSION.dll.4.dr |
Static PE information: section name: .xcq |
Source: VERSION.dll.4.dr |
Static PE information: section name: .ifxvj |
Source: VERSION.dll.4.dr |
Static PE information: section name: .fgpyt |
Source: VERSION.dll.4.dr |
Static PE information: section name: .tgzhe |
Source: VERSION.dll.4.dr |
Static PE information: section name: .oocus |
Source: VERSION.dll.4.dr |
Static PE information: section name: .ybtor |
Source: VERSION.dll.4.dr |
Static PE information: section name: .gxixek |
Source: VERSION.dll.4.dr |
Static PE information: section name: .yjlrz |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .qkm |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .cvjb |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .tlmkv |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .wucsxe |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .fltwtj |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .sfplio |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .rpg |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .bewzc |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .vksvaw |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .wmhg |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .kswemc |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .kaxfk |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .pjf |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .favk |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .vhtukj |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .hmbyox |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .djv |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .hpern |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .czzwqg |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .jxjvn |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .jfsnsk |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .nzvifv |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .tops |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .lrjye |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .qwdob |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .xcq |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .ifxvj |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .fgpyt |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .tgzhe |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .oocus |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .ybtor |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .gxixek |
Source: NETPLWIZ.dll.4.dr |
Static PE information: section name: .uwdayb |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .qkm |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .cvjb |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .tlmkv |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .wucsxe |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .fltwtj |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .sfplio |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .rpg |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .bewzc |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .vksvaw |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .wmhg |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .kswemc |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .kaxfk |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .pjf |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .favk |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .vhtukj |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .hmbyox |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .djv |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .hpern |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .czzwqg |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .jxjvn |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .jfsnsk |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .nzvifv |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .tops |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .lrjye |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .qwdob |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .xcq |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .ifxvj |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .fgpyt |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .tgzhe |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .oocus |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .ybtor |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .gxixek |
Source: XmlLite.dll.4.dr |
Static PE information: section name: .coe |
Source: C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe |
Code function: 27_2_00007FF77B972EF4 GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,memset,GetModuleHandleExW,GetProcAddress,GetProcessHeap,HeapFree,FreeLibrary,memset,memcpy,GetLastError,GetLastError,GetProcessHeap,HeapAlloc,GetCurrentThreadId,GetLastError,GetProcessHeap,HeapAlloc,wcscmp,wcscmp,GetCurrentProcess,GetProcessMitigationPolicy,LocalAlloc,~SyncLockT,FreeLibrary,memset,memcpy,~SyncLockT,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,memcpy,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetModuleFileNameW,GetLastError,GetLastError,GetProcessHeap,HeapAlloc,memcpy,memcpy,memcpy,GetProcessHeap,HeapAlloc,memcpy,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,memcpy,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,memcpy,memcpy,memcpy,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetModuleHandleExW,GetLastError,GetProcAddress,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,memcpy,memset,memset,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,memset,GetModuleHandleExW,GetProcAddress,GetProcessHeap,HeapFree,FreeLibrary,memset,memcpy,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,memset,GetModuleHandleExW,GetProcAddress,GetProcessHeap,HeapFree,FreeLibrary,memset,memcpy,memset,GetLastError,GetLastError,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetLastError,GetProcessHeap,HeapFree,GetLastError,memset,memset,GetLastError,GetLastError,memset,GetLastError,memset,GetLastError,memset,memset,FreeLibrary,memset,memcpy,memset,memset,memset,memset,GetLastError,memset,GetLastError,memset,memset,memset,memset,GetLastError,GetLastError,memset,GetLastError,memset,memset,memset,GetLastError,memset,GetLastError,memset |