Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140034870 | 0_2_0000000140034870 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140035270 | 0_2_0000000140035270 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140048AC0 | 0_2_0000000140048AC0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014005C340 | 0_2_000000014005C340 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140065B80 | 0_2_0000000140065B80 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014006A4B0 | 0_2_000000014006A4B0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400524B0 | 0_2_00000001400524B0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140026CC0 | 0_2_0000000140026CC0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014004BD40 | 0_2_000000014004BD40 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400495B0 | 0_2_00000001400495B0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140036F30 | 0_2_0000000140036F30 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140069010 | 0_2_0000000140069010 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140001010 | 0_2_0000000140001010 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140066020 | 0_2_0000000140066020 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014002F840 | 0_2_000000014002F840 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014005D850 | 0_2_000000014005D850 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140064080 | 0_2_0000000140064080 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140010880 | 0_2_0000000140010880 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400688A0 | 0_2_00000001400688A0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014002D0D0 | 0_2_000000014002D0D0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400018D0 | 0_2_00000001400018D0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140016100 | 0_2_0000000140016100 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014001D100 | 0_2_000000014001D100 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014002A110 | 0_2_000000014002A110 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014001D910 | 0_2_000000014001D910 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140015120 | 0_2_0000000140015120 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014000B120 | 0_2_000000014000B120 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014004F940 | 0_2_000000014004F940 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140039140 | 0_2_0000000140039140 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140023140 | 0_2_0000000140023140 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140057950 | 0_2_0000000140057950 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014001E170 | 0_2_000000014001E170 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140002980 | 0_2_0000000140002980 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400611A0 | 0_2_00000001400611A0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400389A0 | 0_2_00000001400389A0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400381A0 | 0_2_00000001400381A0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014002E1B0 | 0_2_000000014002E1B0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400139D0 | 0_2_00000001400139D0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400319F0 | 0_2_00000001400319F0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014002EA00 | 0_2_000000014002EA00 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140022A00 | 0_2_0000000140022A00 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014003B220 | 0_2_000000014003B220 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140067A40 | 0_2_0000000140067A40 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140069A50 | 0_2_0000000140069A50 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140007A60 | 0_2_0000000140007A60 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014003AAC0 | 0_2_000000014003AAC0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014003A2E0 | 0_2_000000014003A2E0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140062B00 | 0_2_0000000140062B00 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140018300 | 0_2_0000000140018300 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014002FB20 | 0_2_000000014002FB20 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140031340 | 0_2_0000000140031340 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140022340 | 0_2_0000000140022340 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140017B40 | 0_2_0000000140017B40 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014000BB40 | 0_2_000000014000BB40 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014004EB60 | 0_2_000000014004EB60 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140005370 | 0_2_0000000140005370 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014002CB80 | 0_2_000000014002CB80 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014006B390 | 0_2_000000014006B390 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140054BA0 | 0_2_0000000140054BA0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140033BB0 | 0_2_0000000140033BB0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400263C0 | 0_2_00000001400263C0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400123C0 | 0_2_00000001400123C0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140063BD0 | 0_2_0000000140063BD0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400663F0 | 0_2_00000001400663F0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140023BF0 | 0_2_0000000140023BF0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014006B41B | 0_2_000000014006B41B |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014006B424 | 0_2_000000014006B424 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014006B42D | 0_2_000000014006B42D |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014006B436 | 0_2_000000014006B436 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014006B43D | 0_2_000000014006B43D |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140024440 | 0_2_0000000140024440 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140005C40 | 0_2_0000000140005C40 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014006B446 | 0_2_000000014006B446 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014005F490 | 0_2_000000014005F490 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140022D00 | 0_2_0000000140022D00 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140035520 | 0_2_0000000140035520 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140019D20 | 0_2_0000000140019D20 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140030530 | 0_2_0000000140030530 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140023530 | 0_2_0000000140023530 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140031540 | 0_2_0000000140031540 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140033540 | 0_2_0000000140033540 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014007BD50 | 0_2_000000014007BD50 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140078570 | 0_2_0000000140078570 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140019580 | 0_2_0000000140019580 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400205A0 | 0_2_00000001400205A0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140025DB0 | 0_2_0000000140025DB0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140071DC0 | 0_2_0000000140071DC0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014000C5C0 | 0_2_000000014000C5C0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014002DDE0 | 0_2_000000014002DDE0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140031DF0 | 0_2_0000000140031DF0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014000DDF0 | 0_2_000000014000DDF0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140001620 | 0_2_0000000140001620 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140018630 | 0_2_0000000140018630 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140032650 | 0_2_0000000140032650 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140064E80 | 0_2_0000000140064E80 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140016E80 | 0_2_0000000140016E80 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140007EA0 | 0_2_0000000140007EA0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400286B0 | 0_2_00000001400286B0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140006EB0 | 0_2_0000000140006EB0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400276C0 | 0_2_00000001400276C0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014002FEC0 | 0_2_000000014002FEC0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014002EED0 | 0_2_000000014002EED0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014002B6E0 | 0_2_000000014002B6E0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140053F20 | 0_2_0000000140053F20 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140022730 | 0_2_0000000140022730 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140029780 | 0_2_0000000140029780 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140018F80 | 0_2_0000000140018F80 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014003EFB0 | 0_2_000000014003EFB0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400067B0 | 0_2_00000001400067B0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00000001400667D0 | 0_2_00000001400667D0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140060FE0 | 0_2_0000000140060FE0 |
Source: C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe | Code function: 27_2_00007FF77B972EF4 | 27_2_00007FF77B972EF4 |
Source: C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe | Code function: 27_2_00007FF77B988850 | 27_2_00007FF77B988850 |
Source: C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe | Code function: 27_2_00007FF77B988E2C | 27_2_00007FF77B988E2C |
Source: C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe | Code function: 27_2_00007FF77B97139C | 27_2_00007FF77B97139C |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647F74938 | 35_2_00007FF647F74938 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FB7CE0 | 35_2_00007FF647FB7CE0 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FBAD98 | 35_2_00007FF647FBAD98 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FB8DD8 | 35_2_00007FF647FB8DD8 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647F73ED4 | 35_2_00007FF647F73ED4 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FBDEC8 | 35_2_00007FF647FBDEC8 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FB9F70 | 35_2_00007FF647FB9F70 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647F81FC0 | 35_2_00007FF647F81FC0 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647F94FE0 | 35_2_00007FF647F94FE0 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647F88168 | 35_2_00007FF647F88168 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FBB274 | 35_2_00007FF647FBB274 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647F92324 | 35_2_00007FF647F92324 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FB53A0 | 35_2_00007FF647FB53A0 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FC650D | 35_2_00007FF647FC650D |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FC0634 | 35_2_00007FF647FC0634 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647F9B640 | 35_2_00007FF647F9B640 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FB563C | 35_2_00007FF647FB563C |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FB67F0 | 35_2_00007FF647FB67F0 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FC17EC | 35_2_00007FF647FC17EC |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FC5875 | 35_2_00007FF647FC5875 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_0000000140046C90 NtClose, | 0_2_0000000140046C90 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_000000014006A4B0 NtQuerySystemInformation, | 0_2_000000014006A4B0 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FBBA40 NtQuerySystemInformation, | 35_2_00007FF647FBBA40 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FB0C64 RtlInitUnicodeString,memset,NtOpenSymbolicLinkObject,memset,NtQuerySymbolicLinkObject,_wcsnicmp,NtClose,NtClose,_CxxThrowException, | 35_2_00007FF647FB0C64 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FBAD98 memset,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,FindFirstFileW,GetLastError,GetLastError,_wcsicmp,_wcsicmp,GetLastError,GetCurrentThread,NtQueryInformationThread,FindNextFileW,GetLastError,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,FindClose,SetLastError, | 35_2_00007FF647FBAD98 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FB8DD8 memset,NtWriteFile,NtReadFile,NtWriteFile,NtWriteFile,NtWriteFile, | 35_2_00007FF647FB8DD8 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FB9DF8 NtReadFile, | 35_2_00007FF647FB9DF8 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FB9E3C memset,CreateFileW,NtClose, | 35_2_00007FF647FB9E3C |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FB9F70 GetLastError,GetLastError,GetLastError,GetProcessHeap,HeapFree,GetLastError,GetLastError,GetLastError,RtlImageNtHeader,GetLastError,GetLastError,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetLastError,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,CreateFileW,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,GetProcessHeap,HeapAlloc,memset,WriteFile,GetLastError,GetProcessHeap,HeapFree,NtClose,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,SetLastError,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,SetLastError, | 35_2_00007FF647FB9F70 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FB50C8 NtClose, | 35_2_00007FF647FB50C8 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FB90D8 RtlInitUnicodeString,NtOpenFile,NtCreateEvent,NtDeviceIoControlFile,NtWaitForSingleObject,NtClose,NtClose, | 35_2_00007FF647FB90D8 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647F990E8 memset,NtQuerySystemInformation,_CxxThrowException, | 35_2_00007FF647F990E8 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647F993BC CreateFileW,NtQueryVolumeInformationFile,CloseHandle,_CxxThrowException,_CxxThrowException, | 35_2_00007FF647F993BC |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FB94F0 CreateFileW,GetLastError,GetProcessHeap,HeapAlloc,NtQueryInformationFile,NtOpenProcess,NtQueryInformationProcess,GetProcessHeap,HeapAlloc,NtQueryInformationProcess,NtClose,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,CloseHandle,GetProcessHeap,HeapFree, | 35_2_00007FF647FB94F0 |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FC17EC GetFileAttributesW,SetFileAttributesW,CreateFileW,GetFileInformationByHandle,GetModuleHandleW,GetProcAddress,GetProcAddress,memset,GetFullPathNameW,HeapAlloc,RtlDeleteBoundaryDescriptor,_wcsicmp,FindClose,GetProcessHeap,HeapFree,GetLastError,GetLastError,NtSetInformationFile,RtlNtStatusToDosError,CloseHandle,SetFileAttributesW,GetProcessHeap,HeapFree,GetLastError,GetLastError,GetProcessHeap,HeapFree,SetLastError, | 35_2_00007FF647FC17EC |
Source: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Code function: 35_2_00007FF647FB97EC GetCurrentThread,NtQueryInformationThread,GetCurrentThread,NtSetInformationThread, | 35_2_00007FF647FB97EC |
Source: unknown | Process created: C:\Windows\System32\loaddll64.exe loaddll64.exe 'C:\Users\user\Desktop\3PgaI7gtQn.dll' | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\3PgaI7gtQn.dll',#1 | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,CopyPropVariant | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\3PgaI7gtQn.dll',#1 | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,CreatePropVariant | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,CreatePropertyStore | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,DestroyPropVariant | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,FormatTagFromWfx | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,GetAMSubtypeFromD3DFormat | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,GetD3DFormatFromMFSubtype | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAddPeriodicCallback | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAllocateSerialWorkQueue | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAllocateWorkQueue | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAllocateWorkQueueEx | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAppendCollection | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAverageTimePerFrameToFrameRate | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginCreateFile | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\bdeunlock.exe C:\Windows\system32\bdeunlock.exe | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginGetHostByName | |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginRegisterWorkQueueWithMMCSS | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\CameraSettingsUIHost.exe C:\Windows\system32\CameraSettingsUIHost.exe | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginRegisterWorkQueueWithMMCSSEx | |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\43ip\CameraSettingsUIHost.exe C:\Users\user\AppData\Local\43ip\CameraSettingsUIHost.exe | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginUnregisterWorkQueueWithMMCSS | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\pwcreator.exe C:\Windows\system32\pwcreator.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFCalculateBitmapImageSize | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\lpksetup.exe C:\Windows\system32\lpksetup.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\fbMtwkN2S\lpksetup.exe C:\Users\user\AppData\Local\fbMtwkN2S\lpksetup.exe | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFCalculateImageSize | |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\3PgaI7gtQn.dll',#1 | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,CopyPropVariant | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,CreatePropVariant | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,CreatePropertyStore | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,DestroyPropVariant | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,FormatTagFromWfx | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,GetAMSubtypeFromD3DFormat | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,GetD3DFormatFromMFSubtype | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAddPeriodicCallback | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAllocateSerialWorkQueue | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAllocateWorkQueue | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAllocateWorkQueueEx | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAppendCollection | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFAverageTimePerFrameToFrameRate | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginCreateFile | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginGetHostByName | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginRegisterWorkQueueWithMMCSS | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginRegisterWorkQueueWithMMCSSEx | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFBeginUnregisterWorkQueueWithMMCSS | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFCalculateBitmapImageSize | Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\3PgaI7gtQn.dll,MFCalculateImageSize | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\3PgaI7gtQn.dll',#1 | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\bdeunlock.exe C:\Windows\system32\bdeunlock.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\CameraSettingsUIHost.exe C:\Windows\system32\CameraSettingsUIHost.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\43ip\CameraSettingsUIHost.exe C:\Users\user\AppData\Local\43ip\CameraSettingsUIHost.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\pwcreator.exe C:\Windows\system32\pwcreator.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe C:\Users\user\AppData\Local\NfgW4al\pwcreator.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\lpksetup.exe C:\Windows\system32\lpksetup.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: C:\Users\user\AppData\Local\fbMtwkN2S\lpksetup.exe C:\Users\user\AppData\Local\fbMtwkN2S\lpksetup.exe | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\explorer.exe | Process created: unknown unknown | Jump to behavior |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .qkm |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .cvjb |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .tlmkv |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .wucsxe |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .fltwtj |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .sfplio |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .rpg |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .bewzc |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .vksvaw |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .wmhg |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .kswemc |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .kaxfk |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .pjf |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .favk |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .vhtukj |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .hmbyox |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .djv |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .hpern |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .czzwqg |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .jxjvn |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .jfsnsk |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .nzvifv |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .tops |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .lrjye |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .qwdob |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .xcq |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .ifxvj |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .fgpyt |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .tgzhe |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .oocus |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .ybtor |
Source: 3PgaI7gtQn.dll | Static PE information: section name: .gxixek |
Source: bdeunlock.exe.4.dr | Static PE information: section name: .imrsiv |
Source: CameraSettingsUIHost.exe.4.dr | Static PE information: section name: .imrsiv |
Source: mmc.exe.4.dr | Static PE information: section name: .didat |
Source: DUI70.dll.4.dr | Static PE information: section name: .qkm |
Source: DUI70.dll.4.dr | Static PE information: section name: .cvjb |
Source: DUI70.dll.4.dr | Static PE information: section name: .tlmkv |
Source: DUI70.dll.4.dr | Static PE information: section name: .wucsxe |
Source: DUI70.dll.4.dr | Static PE information: section name: .fltwtj |
Source: DUI70.dll.4.dr | Static PE information: section name: .sfplio |
Source: DUI70.dll.4.dr | Static PE information: section name: .rpg |
Source: DUI70.dll.4.dr | Static PE information: section name: .bewzc |
Source: DUI70.dll.4.dr | Static PE information: section name: .vksvaw |
Source: DUI70.dll.4.dr | Static PE information: section name: .wmhg |
Source: DUI70.dll.4.dr | Static PE information: section name: .kswemc |
Source: DUI70.dll.4.dr | Static PE information: section name: .kaxfk |
Source: DUI70.dll.4.dr | Static PE information: section name: .pjf |
Source: DUI70.dll.4.dr | Static PE information: section name: .favk |
Source: DUI70.dll.4.dr | Static PE information: section name: .vhtukj |
Source: DUI70.dll.4.dr | Static PE information: section name: .hmbyox |
Source: DUI70.dll.4.dr | Static PE information: section name: .djv |
Source: DUI70.dll.4.dr | Static PE information: section name: .hpern |
Source: DUI70.dll.4.dr | Static PE information: section name: .czzwqg |
Source: DUI70.dll.4.dr | Static PE information: section name: .jxjvn |
Source: DUI70.dll.4.dr | Static PE information: section name: .jfsnsk |
Source: DUI70.dll.4.dr | Static PE information: section name: .nzvifv |
Source: DUI70.dll.4.dr | Static PE information: section name: .tops |
Source: DUI70.dll.4.dr | Static PE information: section name: .lrjye |
Source: DUI70.dll.4.dr | Static PE information: section name: .qwdob |
Source: DUI70.dll.4.dr | Static PE information: section name: .xcq |
Source: DUI70.dll.4.dr | Static PE information: section name: .ifxvj |
Source: DUI70.dll.4.dr | Static PE information: section name: .fgpyt |
Source: DUI70.dll.4.dr | Static PE information: section name: .tgzhe |
Source: DUI70.dll.4.dr | Static PE information: section name: .oocus |
Source: DUI70.dll.4.dr | Static PE information: section name: .ybtor |
Source: DUI70.dll.4.dr | Static PE information: section name: .gxixek |
Source: DUI70.dll.4.dr | Static PE information: section name: .bcdsk |
Source: DUI70.dll0.4.dr | Static PE information: section name: .qkm |
Source: DUI70.dll0.4.dr | Static PE information: section name: .cvjb |
Source: DUI70.dll0.4.dr | Static PE information: section name: .tlmkv |
Source: DUI70.dll0.4.dr | Static PE information: section name: .wucsxe |
Source: DUI70.dll0.4.dr | Static PE information: section name: .fltwtj |
Source: DUI70.dll0.4.dr | Static PE information: section name: .sfplio |
Source: DUI70.dll0.4.dr | Static PE information: section name: .rpg |
Source: DUI70.dll0.4.dr | Static PE information: section name: .bewzc |
Source: DUI70.dll0.4.dr | Static PE information: section name: .vksvaw |
Source: DUI70.dll0.4.dr | Static PE information: section name: .wmhg |
Source: DUI70.dll0.4.dr | Static PE information: section name: .kswemc |
Source: DUI70.dll0.4.dr | Static PE information: section name: .kaxfk |
Source: DUI70.dll0.4.dr | Static PE information: section name: .pjf |
Source: DUI70.dll0.4.dr | Static PE information: section name: .favk |
Source: DUI70.dll0.4.dr | Static PE information: section name: .vhtukj |
Source: DUI70.dll0.4.dr | Static PE information: section name: .hmbyox |
Source: DUI70.dll0.4.dr | Static PE information: section name: .djv |
Source: DUI70.dll0.4.dr | Static PE information: section name: .hpern |
Source: DUI70.dll0.4.dr | Static PE information: section name: .czzwqg |
Source: DUI70.dll0.4.dr | Static PE information: section name: .jxjvn |
Source: DUI70.dll0.4.dr | Static PE information: section name: .jfsnsk |
Source: DUI70.dll0.4.dr | Static PE information: section name: .nzvifv |
Source: DUI70.dll0.4.dr | Static PE information: section name: .tops |
Source: DUI70.dll0.4.dr | Static PE information: section name: .lrjye |
Source: DUI70.dll0.4.dr | Static PE information: section name: .qwdob |
Source: DUI70.dll0.4.dr | Static PE information: section name: .xcq |
Source: DUI70.dll0.4.dr | Static PE information: section name: .ifxvj |
Source: DUI70.dll0.4.dr | Static PE information: section name: .fgpyt |
Source: DUI70.dll0.4.dr | Static PE information: section name: .tgzhe |
Source: DUI70.dll0.4.dr | Static PE information: section name: .oocus |
Source: DUI70.dll0.4.dr | Static PE information: section name: .ybtor |
Source: DUI70.dll0.4.dr | Static PE information: section name: .gxixek |
Source: DUI70.dll0.4.dr | Static PE information: section name: .rupume |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .qkm |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .cvjb |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .tlmkv |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .wucsxe |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .fltwtj |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .sfplio |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .rpg |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .bewzc |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .vksvaw |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .wmhg |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .kswemc |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .kaxfk |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .pjf |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .favk |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .vhtukj |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .hmbyox |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .djv |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .hpern |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .czzwqg |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .jxjvn |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .jfsnsk |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .nzvifv |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .tops |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .lrjye |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .qwdob |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .xcq |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .ifxvj |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .fgpyt |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .tgzhe |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .oocus |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .ybtor |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .gxixek |
Source: WINBRAND.dll.4.dr | Static PE information: section name: .bbmsy |
Source: dpx.dll.4.dr | Static PE information: section name: .qkm |
Source: dpx.dll.4.dr | Static PE information: section name: .cvjb |
Source: dpx.dll.4.dr | Static PE information: section name: .tlmkv |
Source: dpx.dll.4.dr | Static PE information: section name: .wucsxe |
Source: dpx.dll.4.dr | Static PE information: section name: .fltwtj |
Source: dpx.dll.4.dr | Static PE information: section name: .sfplio |
Source: dpx.dll.4.dr | Static PE information: section name: .rpg |
Source: dpx.dll.4.dr | Static PE information: section name: .bewzc |
Source: dpx.dll.4.dr | Static PE information: section name: .vksvaw |
Source: dpx.dll.4.dr | Static PE information: section name: .wmhg |
Source: dpx.dll.4.dr | Static PE information: section name: .kswemc |
Source: dpx.dll.4.dr | Static PE information: section name: .kaxfk |
Source: dpx.dll.4.dr | Static PE information: section name: .pjf |
Source: dpx.dll.4.dr | Static PE information: section name: .favk |
Source: dpx.dll.4.dr | Static PE information: section name: .vhtukj |
Source: dpx.dll.4.dr | Static PE information: section name: .hmbyox |
Source: dpx.dll.4.dr | Static PE information: section name: .djv |
Source: dpx.dll.4.dr | Static PE information: section name: .hpern |
Source: dpx.dll.4.dr | Static PE information: section name: .czzwqg |
Source: dpx.dll.4.dr | Static PE information: section name: .jxjvn |
Source: dpx.dll.4.dr | Static PE information: section name: .jfsnsk |
Source: dpx.dll.4.dr | Static PE information: section name: .nzvifv |
Source: dpx.dll.4.dr | Static PE information: section name: .tops |
Source: dpx.dll.4.dr | Static PE information: section name: .lrjye |
Source: dpx.dll.4.dr | Static PE information: section name: .qwdob |
Source: dpx.dll.4.dr | Static PE information: section name: .xcq |
Source: dpx.dll.4.dr | Static PE information: section name: .ifxvj |
Source: dpx.dll.4.dr | Static PE information: section name: .fgpyt |
Source: dpx.dll.4.dr | Static PE information: section name: .tgzhe |
Source: dpx.dll.4.dr | Static PE information: section name: .oocus |
Source: dpx.dll.4.dr | Static PE information: section name: .ybtor |
Source: dpx.dll.4.dr | Static PE information: section name: .gxixek |
Source: MFC42u.dll.4.dr | Static PE information: section name: .qkm |
Source: MFC42u.dll.4.dr | Static PE information: section name: .cvjb |
Source: MFC42u.dll.4.dr | Static PE information: section name: .tlmkv |
Source: MFC42u.dll.4.dr | Static PE information: section name: .wucsxe |
Source: MFC42u.dll.4.dr | Static PE information: section name: .fltwtj |
Source: MFC42u.dll.4.dr | Static PE information: section name: .sfplio |
Source: MFC42u.dll.4.dr | Static PE information: section name: .rpg |
Source: MFC42u.dll.4.dr | Static PE information: section name: .bewzc |
Source: MFC42u.dll.4.dr | Static PE information: section name: .vksvaw |
Source: MFC42u.dll.4.dr | Static PE information: section name: .wmhg |
Source: MFC42u.dll.4.dr | Static PE information: section name: .kswemc |
Source: MFC42u.dll.4.dr | Static PE information: section name: .kaxfk |
Source: MFC42u.dll.4.dr | Static PE information: section name: .pjf |
Source: MFC42u.dll.4.dr | Static PE information: section name: .favk |
Source: MFC42u.dll.4.dr | Static PE information: section name: .vhtukj |
Source: MFC42u.dll.4.dr | Static PE information: section name: .hmbyox |
Source: MFC42u.dll.4.dr | Static PE information: section name: .djv |
Source: MFC42u.dll.4.dr | Static PE information: section name: .hpern |
Source: MFC42u.dll.4.dr | Static PE information: section name: .czzwqg |
Source: MFC42u.dll.4.dr | Static PE information: section name: .jxjvn |
Source: MFC42u.dll.4.dr | Static PE information: section name: .jfsnsk |
Source: MFC42u.dll.4.dr | Static PE information: section name: .nzvifv |
Source: MFC42u.dll.4.dr | Static PE information: section name: .tops |
Source: MFC42u.dll.4.dr | Static PE information: section name: .lrjye |
Source: MFC42u.dll.4.dr | Static PE information: section name: .qwdob |
Source: MFC42u.dll.4.dr | Static PE information: section name: .xcq |
Source: MFC42u.dll.4.dr | Static PE information: section name: .ifxvj |
Source: MFC42u.dll.4.dr | Static PE information: section name: .fgpyt |
Source: MFC42u.dll.4.dr | Static PE information: section name: .tgzhe |
Source: MFC42u.dll.4.dr | Static PE information: section name: .oocus |
Source: MFC42u.dll.4.dr | Static PE information: section name: .ybtor |
Source: MFC42u.dll.4.dr | Static PE information: section name: .gxixek |
Source: MFC42u.dll.4.dr | Static PE information: section name: .zlxpb |
Source: VERSION.dll.4.dr | Static PE information: section name: .qkm |
Source: VERSION.dll.4.dr | Static PE information: section name: .cvjb |
Source: VERSION.dll.4.dr | Static PE information: section name: .tlmkv |
Source: VERSION.dll.4.dr | Static PE information: section name: .wucsxe |
Source: VERSION.dll.4.dr | Static PE information: section name: .fltwtj |
Source: VERSION.dll.4.dr | Static PE information: section name: .sfplio |
Source: VERSION.dll.4.dr | Static PE information: section name: .rpg |
Source: VERSION.dll.4.dr | Static PE information: section name: .bewzc |
Source: VERSION.dll.4.dr | Static PE information: section name: .vksvaw |
Source: VERSION.dll.4.dr | Static PE information: section name: .wmhg |
Source: VERSION.dll.4.dr | Static PE information: section name: .kswemc |
Source: VERSION.dll.4.dr | Static PE information: section name: .kaxfk |
Source: VERSION.dll.4.dr | Static PE information: section name: .pjf |
Source: VERSION.dll.4.dr | Static PE information: section name: .favk |
Source: VERSION.dll.4.dr | Static PE information: section name: .vhtukj |
Source: VERSION.dll.4.dr | Static PE information: section name: .hmbyox |
Source: VERSION.dll.4.dr | Static PE information: section name: .djv |
Source: VERSION.dll.4.dr | Static PE information: section name: .hpern |
Source: VERSION.dll.4.dr | Static PE information: section name: .czzwqg |
Source: VERSION.dll.4.dr | Static PE information: section name: .jxjvn |
Source: VERSION.dll.4.dr | Static PE information: section name: .jfsnsk |
Source: VERSION.dll.4.dr | Static PE information: section name: .nzvifv |
Source: VERSION.dll.4.dr | Static PE information: section name: .tops |
Source: VERSION.dll.4.dr | Static PE information: section name: .lrjye |
Source: VERSION.dll.4.dr | Static PE information: section name: .qwdob |
Source: VERSION.dll.4.dr | Static PE information: section name: .xcq |
Source: VERSION.dll.4.dr | Static PE information: section name: .ifxvj |
Source: VERSION.dll.4.dr | Static PE information: section name: .fgpyt |
Source: VERSION.dll.4.dr | Static PE information: section name: .tgzhe |
Source: VERSION.dll.4.dr | Static PE information: section name: .oocus |
Source: VERSION.dll.4.dr | Static PE information: section name: .ybtor |
Source: VERSION.dll.4.dr | Static PE information: section name: .gxixek |
Source: VERSION.dll.4.dr | Static PE information: section name: .yjlrz |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .qkm |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .cvjb |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .tlmkv |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .wucsxe |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .fltwtj |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .sfplio |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .rpg |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .bewzc |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .vksvaw |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .wmhg |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .kswemc |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .kaxfk |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .pjf |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .favk |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .vhtukj |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .hmbyox |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .djv |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .hpern |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .czzwqg |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .jxjvn |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .jfsnsk |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .nzvifv |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .tops |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .lrjye |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .qwdob |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .xcq |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .ifxvj |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .fgpyt |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .tgzhe |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .oocus |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .ybtor |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .gxixek |
Source: NETPLWIZ.dll.4.dr | Static PE information: section name: .uwdayb |
Source: XmlLite.dll.4.dr | Static PE information: section name: .qkm |
Source: XmlLite.dll.4.dr | Static PE information: section name: .cvjb |
Source: XmlLite.dll.4.dr | Static PE information: section name: .tlmkv |
Source: XmlLite.dll.4.dr | Static PE information: section name: .wucsxe |
Source: XmlLite.dll.4.dr | Static PE information: section name: .fltwtj |
Source: XmlLite.dll.4.dr | Static PE information: section name: .sfplio |
Source: XmlLite.dll.4.dr | Static PE information: section name: .rpg |
Source: XmlLite.dll.4.dr | Static PE information: section name: .bewzc |
Source: XmlLite.dll.4.dr | Static PE information: section name: .vksvaw |
Source: XmlLite.dll.4.dr | Static PE information: section name: .wmhg |
Source: XmlLite.dll.4.dr | Static PE information: section name: .kswemc |
Source: XmlLite.dll.4.dr | Static PE information: section name: .kaxfk |
Source: XmlLite.dll.4.dr | Static PE information: section name: .pjf |
Source: XmlLite.dll.4.dr | Static PE information: section name: .favk |
Source: XmlLite.dll.4.dr | Static PE information: section name: .vhtukj |
Source: XmlLite.dll.4.dr | Static PE information: section name: .hmbyox |
Source: XmlLite.dll.4.dr | Static PE information: section name: .djv |
Source: XmlLite.dll.4.dr | Static PE information: section name: .hpern |
Source: XmlLite.dll.4.dr | Static PE information: section name: .czzwqg |
Source: XmlLite.dll.4.dr | Static PE information: section name: .jxjvn |
Source: XmlLite.dll.4.dr | Static PE information: section name: .jfsnsk |
Source: XmlLite.dll.4.dr | Static PE information: section name: .nzvifv |
Source: XmlLite.dll.4.dr | Static PE information: section name: .tops |
Source: XmlLite.dll.4.dr | Static PE information: section name: .lrjye |
Source: XmlLite.dll.4.dr | Static PE information: section name: .qwdob |
Source: XmlLite.dll.4.dr | Static PE information: section name: .xcq |
Source: XmlLite.dll.4.dr | Static PE information: section name: .ifxvj |
Source: XmlLite.dll.4.dr | Static PE information: section name: .fgpyt |
Source: XmlLite.dll.4.dr | Static PE information: section name: .tgzhe |
Source: XmlLite.dll.4.dr | Static PE information: section name: .oocus |
Source: XmlLite.dll.4.dr | Static PE information: section name: .ybtor |
Source: XmlLite.dll.4.dr | Static PE information: section name: .gxixek |
Source: XmlLite.dll.4.dr | Static PE information: section name: .coe |
Source: C:\Users\user\AppData\Local\bnfeSWnf\bdeunlock.exe | Code function: 27_2_00007FF77B972EF4 GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,memset,GetModuleHandleExW,GetProcAddress,GetProcessHeap,HeapFree,FreeLibrary,memset,memcpy,GetLastError,GetLastError,GetProcessHeap,HeapAlloc,GetCurrentThreadId,GetLastError,GetProcessHeap,HeapAlloc,wcscmp,wcscmp,GetCurrentProcess,GetProcessMitigationPolicy,LocalAlloc,~SyncLockT,FreeLibrary,memset,memcpy,~SyncLockT,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,memcpy,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetModuleFileNameW,GetLastError,GetLastError,GetProcessHeap,HeapAlloc,memcpy,memcpy,memcpy,GetProcessHeap,HeapAlloc,memcpy,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,memcpy,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,memcpy,memcpy,memcpy,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetModuleHandleExW,GetLastError,GetProcAddress,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,memcpy,memset,memset,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,memset,GetModuleHandleExW,GetProcAddress,GetProcessHeap,HeapFree,FreeLibrary,memset,memcpy,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,memset,GetModuleHandleExW,GetProcAddress,GetProcessHeap,HeapFree,FreeLibrary,memset,memcpy,memset,GetLastError,GetLastError,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetLastError,GetProcessHeap,HeapFree,GetLastError,memset,memset,GetLastError,GetLastError,memset,GetLastError,memset,GetLastError,memset,memset,FreeLibrary,memset,memcpy,memset,memset,memset,memset,GetLastError,memset,GetLastError,memset,memset,memset,memset,GetLastError,GetLastError,memset,GetLastError,memset,memset,memset,GetLastError,memset,GetLastError,memset,memset,memset,memse |