Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014005D290 FindFirstFileExW, |
0_2_000000014005D290 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B2466334 #620,#624,#6050,#1040,#1040,#4436,#1122,#1040,#624,#1259,#1040,#626,FindFirstFileW,#624,#1259,#1262,#1122,#1040,#1040,#1040,_wcsicmp,SetFileAttributesW,DeleteFileW,FindNextFileW,FindClose,#624,#1259,#1040,FindFirstFileW,#622,#624,#624,#1259,#1259,#1040,#1040,#1040,#1040,#1040,FindNextFileW,FindClose,RemoveDirectoryW,#1040,#1040,#1040,#1040, |
33_2_00007FF7B2466334 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B24672AC #624,FindFirstFileW,FindClose,#6050,_wcsicmp,#1040,#1463,_wcsicmp,#624,CreateFileW,GetFileSize,ReadFile,CloseHandle,#1040,CreateFileW,#6886,CloseHandle,#6886,_wcsicmp,#626,#624,#1040,#624,#1122,SetupIterateCabinetW,#1040,#626,#626,RegOpenKeyExW,RegGetValueW,#1126,RegCloseKey,#1040,#1040,#1040,RegOpenKeyExW,#624,#2975,RegSetValueExW,#1122,RegCloseKey,#1040,RegCloseKey,#620,#620,#628,#1042,#1040,#1040,#622,#1259,#1122,#1040,#1040,#1284,#2783,#1040,#1040,#1040,#1042,#1040,#1040,#1040,#1040,#1040,#1040,GetLastError,#626,#626,#4473,#4473,#1287,#1287,MessageBoxW,#1040,#1040,#1040, |
33_2_00007FF7B24672AC |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B2465DE8 #626,#626,#1122,#624,#6050,#1040,#1040,#624,#1284,#1040,#1259,#1122,#1040,FindFirstFileW,#624,#1259,#1358,#1040,#1040,FindNextFileW,FindClose,#624,#1259,#1122,#1040,#1040,FindFirstFileW,#624,#1259,#1040,#1040,FindNextFileW,FindClose,#1040,#1040, |
33_2_00007FF7B2465DE8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140034870 |
0_2_0000000140034870 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140035270 |
0_2_0000000140035270 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140048AC0 |
0_2_0000000140048AC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014005C340 |
0_2_000000014005C340 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140065B80 |
0_2_0000000140065B80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006A4B0 |
0_2_000000014006A4B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400524B0 |
0_2_00000001400524B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140026CC0 |
0_2_0000000140026CC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014004BD40 |
0_2_000000014004BD40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400495B0 |
0_2_00000001400495B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140036F30 |
0_2_0000000140036F30 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140069010 |
0_2_0000000140069010 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140001010 |
0_2_0000000140001010 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140066020 |
0_2_0000000140066020 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002F840 |
0_2_000000014002F840 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014005D850 |
0_2_000000014005D850 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140064080 |
0_2_0000000140064080 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140010880 |
0_2_0000000140010880 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400688A0 |
0_2_00000001400688A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002D0D0 |
0_2_000000014002D0D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400018D0 |
0_2_00000001400018D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140016100 |
0_2_0000000140016100 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014001D100 |
0_2_000000014001D100 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002A110 |
0_2_000000014002A110 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014001D910 |
0_2_000000014001D910 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140015120 |
0_2_0000000140015120 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014000B120 |
0_2_000000014000B120 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014004F940 |
0_2_000000014004F940 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140039140 |
0_2_0000000140039140 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140023140 |
0_2_0000000140023140 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140057950 |
0_2_0000000140057950 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014001E170 |
0_2_000000014001E170 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140002980 |
0_2_0000000140002980 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400611A0 |
0_2_00000001400611A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400389A0 |
0_2_00000001400389A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400381A0 |
0_2_00000001400381A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002E1B0 |
0_2_000000014002E1B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400139D0 |
0_2_00000001400139D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400319F0 |
0_2_00000001400319F0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002EA00 |
0_2_000000014002EA00 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140022A00 |
0_2_0000000140022A00 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014003B220 |
0_2_000000014003B220 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140067A40 |
0_2_0000000140067A40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140069A50 |
0_2_0000000140069A50 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140007A60 |
0_2_0000000140007A60 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014003AAC0 |
0_2_000000014003AAC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014003A2E0 |
0_2_000000014003A2E0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140062B00 |
0_2_0000000140062B00 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140018300 |
0_2_0000000140018300 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002FB20 |
0_2_000000014002FB20 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140031340 |
0_2_0000000140031340 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140022340 |
0_2_0000000140022340 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140017B40 |
0_2_0000000140017B40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014000BB40 |
0_2_000000014000BB40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014004EB60 |
0_2_000000014004EB60 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140005370 |
0_2_0000000140005370 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002CB80 |
0_2_000000014002CB80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B390 |
0_2_000000014006B390 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140054BA0 |
0_2_0000000140054BA0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140033BB0 |
0_2_0000000140033BB0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400263C0 |
0_2_00000001400263C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400123C0 |
0_2_00000001400123C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140063BD0 |
0_2_0000000140063BD0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400663F0 |
0_2_00000001400663F0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140023BF0 |
0_2_0000000140023BF0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B41B |
0_2_000000014006B41B |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B424 |
0_2_000000014006B424 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B42D |
0_2_000000014006B42D |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B436 |
0_2_000000014006B436 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B43D |
0_2_000000014006B43D |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140024440 |
0_2_0000000140024440 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140005C40 |
0_2_0000000140005C40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B446 |
0_2_000000014006B446 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014005F490 |
0_2_000000014005F490 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140022D00 |
0_2_0000000140022D00 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140035520 |
0_2_0000000140035520 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140019D20 |
0_2_0000000140019D20 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140030530 |
0_2_0000000140030530 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140023530 |
0_2_0000000140023530 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140031540 |
0_2_0000000140031540 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140033540 |
0_2_0000000140033540 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014007BD50 |
0_2_000000014007BD50 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140078570 |
0_2_0000000140078570 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140019580 |
0_2_0000000140019580 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400205A0 |
0_2_00000001400205A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140025DB0 |
0_2_0000000140025DB0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140071DC0 |
0_2_0000000140071DC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014000C5C0 |
0_2_000000014000C5C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002DDE0 |
0_2_000000014002DDE0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140031DF0 |
0_2_0000000140031DF0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014000DDF0 |
0_2_000000014000DDF0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140001620 |
0_2_0000000140001620 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140018630 |
0_2_0000000140018630 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140032650 |
0_2_0000000140032650 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140064E80 |
0_2_0000000140064E80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140016E80 |
0_2_0000000140016E80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140007EA0 |
0_2_0000000140007EA0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400286B0 |
0_2_00000001400286B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140006EB0 |
0_2_0000000140006EB0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400276C0 |
0_2_00000001400276C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002FEC0 |
0_2_000000014002FEC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002EED0 |
0_2_000000014002EED0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002B6E0 |
0_2_000000014002B6E0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140053F20 |
0_2_0000000140053F20 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140022730 |
0_2_0000000140022730 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140029780 |
0_2_0000000140029780 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140018F80 |
0_2_0000000140018F80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014003EFB0 |
0_2_000000014003EFB0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400067B0 |
0_2_00000001400067B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400667D0 |
0_2_00000001400667D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140060FE0 |
0_2_0000000140060FE0 |
Source: C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe |
Code function: 22_2_00007FF6153D8310 |
22_2_00007FF6153D8310 |
Source: C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe |
Code function: 22_2_00007FF6153E4F10 |
22_2_00007FF6153E4F10 |
Source: C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe |
Code function: 22_2_00007FF6153E3718 |
22_2_00007FF6153E3718 |
Source: C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe |
Code function: 22_2_00007FF6153DA1A0 |
22_2_00007FF6153DA1A0 |
Source: C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe |
Code function: 22_2_00007FF6153D6218 |
22_2_00007FF6153D6218 |
Source: C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe |
Code function: 22_2_00007FF6153DA5C8 |
22_2_00007FF6153DA5C8 |
Source: C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe |
Code function: 22_2_00007FF6153D3080 |
22_2_00007FF6153D3080 |
Source: C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe |
Code function: 22_2_00007FF6153EB088 |
22_2_00007FF6153EB088 |
Source: C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe |
Code function: 22_2_00007FF6153E0CA8 |
22_2_00007FF6153E0CA8 |
Source: C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe |
Code function: 22_2_00007FF6153D3514 |
22_2_00007FF6153D3514 |
Source: C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe |
Code function: 22_2_00007FF6153EC4D0 |
22_2_00007FF6153EC4D0 |
Source: C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe |
Code function: 22_2_00007FF6153D44E8 |
22_2_00007FF6153D44E8 |
Source: C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe |
Code function: 22_2_00007FF6153E03A0 |
22_2_00007FF6153E03A0 |
Source: C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe |
Code function: 22_2_00007FF6153E2BD8 |
22_2_00007FF6153E2BD8 |
Source: C:\Users\user\AppData\Local\CsJaRZ\tabcal.exe |
Code function: 24_2_00007FF6FB1533E0 |
24_2_00007FF6FB1533E0 |
Source: C:\Users\user\AppData\Local\CsJaRZ\tabcal.exe |
Code function: 24_2_00007FF6FB1517E0 |
24_2_00007FF6FB1517E0 |
Source: C:\Users\user\AppData\Local\CsJaRZ\tabcal.exe |
Code function: 24_2_00007FF6FB1515D0 |
24_2_00007FF6FB1515D0 |
Source: C:\Users\user\AppData\Local\CsJaRZ\tabcal.exe |
Code function: 24_2_00007FF6FB155A18 |
24_2_00007FF6FB155A18 |
Source: C:\Users\user\AppData\Local\CsJaRZ\tabcal.exe |
Code function: 24_2_00007FF6FB1525FC |
24_2_00007FF6FB1525FC |
Source: C:\Users\user\AppData\Local\CsJaRZ\tabcal.exe |
Code function: 24_2_00007FF6FB154F00 |
24_2_00007FF6FB154F00 |
Source: C:\Users\user\AppData\Local\CsJaRZ\tabcal.exe |
Code function: 24_2_00007FF6FB151F10 |
24_2_00007FF6FB151F10 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A56BD6B0 |
28_2_00007FF6A56BD6B0 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A56A9A7C |
28_2_00007FF6A56A9A7C |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A56BB260 |
28_2_00007FF6A56BB260 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A5695B08 |
28_2_00007FF6A5695B08 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A56A92C0 |
28_2_00007FF6A56A92C0 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A56B4960 |
28_2_00007FF6A56B4960 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A56A4158 |
28_2_00007FF6A56A4158 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A569913C |
28_2_00007FF6A569913C |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A56A45BC |
28_2_00007FF6A56A45BC |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A569F0B4 |
28_2_00007FF6A569F0B4 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A569B868 |
28_2_00007FF6A569B868 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A56B9530 |
28_2_00007FF6A56B9530 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A56BA8E0 |
28_2_00007FF6A56BA8E0 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A56AECB8 |
28_2_00007FF6A56AECB8 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A56ACF68 |
28_2_00007FF6A56ACF68 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A56B9F38 |
28_2_00007FF6A56B9F38 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A56A1018 |
28_2_00007FF6A56A1018 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A56A8408 |
28_2_00007FF6A56A8408 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A56B7400 |
28_2_00007FF6A56B7400 |
Source: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Code function: 28_2_00007FF6A56B0800 |
28_2_00007FF6A56B0800 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B2459370 |
33_2_00007FF7B2459370 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B246BD00 |
33_2_00007FF7B246BD00 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B246B184 |
33_2_00007FF7B246B184 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B2462210 |
33_2_00007FF7B2462210 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B245C314 |
33_2_00007FF7B245C314 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B24672AC |
33_2_00007FF7B24672AC |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B246B7AC |
33_2_00007FF7B246B7AC |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B2460F98 |
33_2_00007FF7B2460F98 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B24608D8 |
33_2_00007FF7B24608D8 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B245B0E0 |
33_2_00007FF7B245B0E0 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B2467D98 |
33_2_00007FF7B2467D98 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B246A670 |
33_2_00007FF7B246A670 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B2459E90 |
33_2_00007FF7B2459E90 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B24666F8 |
33_2_00007FF7B24666F8 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B2468F04 |
33_2_00007FF7B2468F04 |
Source: C:\Users\user\AppData\Local\famGrLP\dpapimig.exe |
Code function: 35_2_00007FF6882C1F08 |
35_2_00007FF6882C1F08 |
Source: C:\Users\user\AppData\Local\y7FgRNmA\dpapimig.exe |
Code function: 38_2_00007FF675101F08 |
38_2_00007FF675101F08 |
Source: unknown |
Process created: C:\Windows\System32\loaddll64.exe loaddll64.exe 'C:\Users\user\Desktop\2qTIaOLW2o.dll' |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\2qTIaOLW2o.dll',#1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\2qTIaOLW2o.dll',#1 |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\2qTIaOLW2o.dll,??0?$PatternProvider@VExpandCollapseProvider@DirectUI@@UIExpandCollapseProvider@@$00@DirectUI@@QEAA@XZ |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\2qTIaOLW2o.dll,??0?$PatternProvider@VGridItemProvider@DirectUI@@UIGridItemProvider@@$01@DirectUI@@QEAA@XZ |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\2qTIaOLW2o.dll,??0?$PatternProvider@VGridProvider@DirectUI@@UIGridProvider@@$02@DirectUI@@QEAA@XZ |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\SndVol.exe C:\Windows\system32\SndVol.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\tabcal.exe C:\Windows\system32\tabcal.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\CsJaRZ\tabcal.exe C:\Users\user\AppData\Local\CsJaRZ\tabcal.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\ProximityUxHost.exe C:\Windows\system32\ProximityUxHost.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\msinfo32.exe C:\Windows\system32\msinfo32.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\dpapimig.exe C:\Windows\system32\dpapimig.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\famGrLP\dpapimig.exe C:\Users\user\AppData\Local\famGrLP\dpapimig.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\dpapimig.exe C:\Windows\system32\dpapimig.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\y7FgRNmA\dpapimig.exe C:\Users\user\AppData\Local\y7FgRNmA\dpapimig.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\SystemPropertiesPerformance.exe C:\Windows\system32\SystemPropertiesPerformance.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\hbyq\SystemPropertiesPerformance.exe C:\Users\user\AppData\Local\hbyq\SystemPropertiesPerformance.exe |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\2qTIaOLW2o.dll',#1 |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\2qTIaOLW2o.dll,??0?$PatternProvider@VExpandCollapseProvider@DirectUI@@UIExpandCollapseProvider@@$00@DirectUI@@QEAA@XZ |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\2qTIaOLW2o.dll,??0?$PatternProvider@VGridItemProvider@DirectUI@@UIGridItemProvider@@$01@DirectUI@@QEAA@XZ |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\2qTIaOLW2o.dll,??0?$PatternProvider@VGridProvider@DirectUI@@UIGridProvider@@$02@DirectUI@@QEAA@XZ |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\2qTIaOLW2o.dll',#1 |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\SndVol.exe C:\Windows\system32\SndVol.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe C:\Users\user\AppData\Local\cAlXLQGkN\SndVol.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\tabcal.exe C:\Windows\system32\tabcal.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\CsJaRZ\tabcal.exe C:\Users\user\AppData\Local\CsJaRZ\tabcal.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\ProximityUxHost.exe C:\Windows\system32\ProximityUxHost.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe C:\Users\user\AppData\Local\rPj\ProximityUxHost.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\msinfo32.exe C:\Windows\system32\msinfo32.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\dpapimig.exe C:\Windows\system32\dpapimig.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\famGrLP\dpapimig.exe C:\Users\user\AppData\Local\famGrLP\dpapimig.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\dpapimig.exe C:\Windows\system32\dpapimig.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\y7FgRNmA\dpapimig.exe C:\Users\user\AppData\Local\y7FgRNmA\dpapimig.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\SystemPropertiesPerformance.exe C:\Windows\system32\SystemPropertiesPerformance.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\hbyq\SystemPropertiesPerformance.exe C:\Users\user\AppData\Local\hbyq\SystemPropertiesPerformance.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .qkm |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .cvjb |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .tlmkv |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .wucsxe |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .wnx |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .weqy |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .yby |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .ormx |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .dhclu |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .xmiul |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .tlwcxe |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .get |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .hzrd |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .gfrpb |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .ymlijr |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .tntrb |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .rmvhl |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .ukcyi |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .knmra |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .wtn |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .kjnw |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .okpgp |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .oxbitk |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .dplkzo |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .psnue |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .lida |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .arovjd |
Source: 2qTIaOLW2o.dll |
Static PE information: section name: .xsnm |
Source: SndVol.exe.5.dr |
Static PE information: section name: .imrsiv |
Source: SndVol.exe.5.dr |
Static PE information: section name: .didat |
Source: tabcal.exe.5.dr |
Static PE information: section name: .didat |
Source: ProximityUxHost.exe.5.dr |
Static PE information: section name: .imrsiv |
Source: GamePanel.exe.5.dr |
Static PE information: section name: .imrsiv |
Source: GamePanel.exe.5.dr |
Static PE information: section name: .didat |
Source: rdpinit.exe.5.dr |
Static PE information: section name: .imrsiv |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .qkm |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .cvjb |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .tlmkv |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .wucsxe |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .wnx |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .weqy |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .yby |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .ormx |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .dhclu |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .xmiul |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .tlwcxe |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .get |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .hzrd |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .gfrpb |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .ymlijr |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .tntrb |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .rmvhl |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .ukcyi |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .knmra |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .wtn |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .kjnw |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .okpgp |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .oxbitk |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .dplkzo |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .psnue |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .lida |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .arovjd |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .xsnm |
Source: UxTheme.dll.5.dr |
Static PE information: section name: .kqfi |
Source: HID.DLL.5.dr |
Static PE information: section name: .qkm |
Source: HID.DLL.5.dr |
Static PE information: section name: .cvjb |
Source: HID.DLL.5.dr |
Static PE information: section name: .tlmkv |
Source: HID.DLL.5.dr |
Static PE information: section name: .wucsxe |
Source: HID.DLL.5.dr |
Static PE information: section name: .wnx |
Source: HID.DLL.5.dr |
Static PE information: section name: .weqy |
Source: HID.DLL.5.dr |
Static PE information: section name: .yby |
Source: HID.DLL.5.dr |
Static PE information: section name: .ormx |
Source: HID.DLL.5.dr |
Static PE information: section name: .dhclu |
Source: HID.DLL.5.dr |
Static PE information: section name: .xmiul |
Source: HID.DLL.5.dr |
Static PE information: section name: .tlwcxe |
Source: HID.DLL.5.dr |
Static PE information: section name: .get |
Source: HID.DLL.5.dr |
Static PE information: section name: .hzrd |
Source: HID.DLL.5.dr |
Static PE information: section name: .gfrpb |
Source: HID.DLL.5.dr |
Static PE information: section name: .ymlijr |
Source: HID.DLL.5.dr |
Static PE information: section name: .tntrb |
Source: HID.DLL.5.dr |
Static PE information: section name: .rmvhl |
Source: HID.DLL.5.dr |
Static PE information: section name: .ukcyi |
Source: HID.DLL.5.dr |
Static PE information: section name: .knmra |
Source: HID.DLL.5.dr |
Static PE information: section name: .wtn |
Source: HID.DLL.5.dr |
Static PE information: section name: .kjnw |
Source: HID.DLL.5.dr |
Static PE information: section name: .okpgp |
Source: HID.DLL.5.dr |
Static PE information: section name: .oxbitk |
Source: HID.DLL.5.dr |
Static PE information: section name: .dplkzo |
Source: HID.DLL.5.dr |
Static PE information: section name: .psnue |
Source: HID.DLL.5.dr |
Static PE information: section name: .lida |
Source: HID.DLL.5.dr |
Static PE information: section name: .arovjd |
Source: HID.DLL.5.dr |
Static PE information: section name: .xsnm |
Source: HID.DLL.5.dr |
Static PE information: section name: .suz |
Source: DUI70.dll.5.dr |
Static PE information: section name: .qkm |
Source: DUI70.dll.5.dr |
Static PE information: section name: .cvjb |
Source: DUI70.dll.5.dr |
Static PE information: section name: .tlmkv |
Source: DUI70.dll.5.dr |
Static PE information: section name: .wucsxe |
Source: DUI70.dll.5.dr |
Static PE information: section name: .wnx |
Source: DUI70.dll.5.dr |
Static PE information: section name: .weqy |
Source: DUI70.dll.5.dr |
Static PE information: section name: .yby |
Source: DUI70.dll.5.dr |
Static PE information: section name: .ormx |
Source: DUI70.dll.5.dr |
Static PE information: section name: .dhclu |
Source: DUI70.dll.5.dr |
Static PE information: section name: .xmiul |
Source: DUI70.dll.5.dr |
Static PE information: section name: .tlwcxe |
Source: DUI70.dll.5.dr |
Static PE information: section name: .get |
Source: DUI70.dll.5.dr |
Static PE information: section name: .hzrd |
Source: DUI70.dll.5.dr |
Static PE information: section name: .gfrpb |
Source: DUI70.dll.5.dr |
Static PE information: section name: .ymlijr |
Source: DUI70.dll.5.dr |
Static PE information: section name: .tntrb |
Source: DUI70.dll.5.dr |
Static PE information: section name: .rmvhl |
Source: DUI70.dll.5.dr |
Static PE information: section name: .ukcyi |
Source: DUI70.dll.5.dr |
Static PE information: section name: .knmra |
Source: DUI70.dll.5.dr |
Static PE information: section name: .wtn |
Source: DUI70.dll.5.dr |
Static PE information: section name: .kjnw |
Source: DUI70.dll.5.dr |
Static PE information: section name: .okpgp |
Source: DUI70.dll.5.dr |
Static PE information: section name: .oxbitk |
Source: DUI70.dll.5.dr |
Static PE information: section name: .dplkzo |
Source: DUI70.dll.5.dr |
Static PE information: section name: .psnue |
Source: DUI70.dll.5.dr |
Static PE information: section name: .lida |
Source: DUI70.dll.5.dr |
Static PE information: section name: .arovjd |
Source: DUI70.dll.5.dr |
Static PE information: section name: .xsnm |
Source: DUI70.dll.5.dr |
Static PE information: section name: .amc |
Source: SLC.dll.5.dr |
Static PE information: section name: .qkm |
Source: SLC.dll.5.dr |
Static PE information: section name: .cvjb |
Source: SLC.dll.5.dr |
Static PE information: section name: .tlmkv |
Source: SLC.dll.5.dr |
Static PE information: section name: .wucsxe |
Source: SLC.dll.5.dr |
Static PE information: section name: .wnx |
Source: SLC.dll.5.dr |
Static PE information: section name: .weqy |
Source: SLC.dll.5.dr |
Static PE information: section name: .yby |
Source: SLC.dll.5.dr |
Static PE information: section name: .ormx |
Source: SLC.dll.5.dr |
Static PE information: section name: .dhclu |
Source: SLC.dll.5.dr |
Static PE information: section name: .xmiul |
Source: SLC.dll.5.dr |
Static PE information: section name: .tlwcxe |
Source: SLC.dll.5.dr |
Static PE information: section name: .get |
Source: SLC.dll.5.dr |
Static PE information: section name: .hzrd |
Source: SLC.dll.5.dr |
Static PE information: section name: .gfrpb |
Source: SLC.dll.5.dr |
Static PE information: section name: .ymlijr |
Source: SLC.dll.5.dr |
Static PE information: section name: .tntrb |
Source: SLC.dll.5.dr |
Static PE information: section name: .rmvhl |
Source: SLC.dll.5.dr |
Static PE information: section name: .ukcyi |
Source: SLC.dll.5.dr |
Static PE information: section name: .knmra |
Source: SLC.dll.5.dr |
Static PE information: section name: .wtn |
Source: SLC.dll.5.dr |
Static PE information: section name: .kjnw |
Source: SLC.dll.5.dr |
Static PE information: section name: .okpgp |
Source: SLC.dll.5.dr |
Static PE information: section name: .oxbitk |
Source: SLC.dll.5.dr |
Static PE information: section name: .dplkzo |
Source: SLC.dll.5.dr |
Static PE information: section name: .psnue |
Source: SLC.dll.5.dr |
Static PE information: section name: .lida |
Source: SLC.dll.5.dr |
Static PE information: section name: .arovjd |
Source: SLC.dll.5.dr |
Static PE information: section name: .xsnm |
Source: SLC.dll.5.dr |
Static PE information: section name: .jsl |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .qkm |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .cvjb |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .tlmkv |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .wucsxe |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .wnx |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .weqy |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .yby |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .ormx |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .dhclu |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .xmiul |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .tlwcxe |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .get |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .hzrd |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .gfrpb |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .ymlijr |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .tntrb |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .rmvhl |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .ukcyi |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .knmra |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .wtn |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .kjnw |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .okpgp |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .oxbitk |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .dplkzo |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .psnue |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .lida |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .arovjd |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .xsnm |
Source: DUI70.dll0.5.dr |
Static PE information: section name: .jxxke |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .qkm |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .cvjb |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .tlmkv |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .wucsxe |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .wnx |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .weqy |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .yby |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .ormx |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .dhclu |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .xmiul |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .tlwcxe |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .get |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .hzrd |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .gfrpb |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .ymlijr |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .tntrb |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .rmvhl |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .ukcyi |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .knmra |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .wtn |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .kjnw |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .okpgp |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .oxbitk |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .dplkzo |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .psnue |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .lida |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .arovjd |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .xsnm |
Source: DUI70.dll1.5.dr |
Static PE information: section name: .ddia |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .qkm |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .cvjb |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .tlmkv |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .wucsxe |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .wnx |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .weqy |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .yby |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .ormx |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .dhclu |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .xmiul |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .tlwcxe |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .get |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .hzrd |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .gfrpb |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .ymlijr |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .tntrb |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .rmvhl |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .ukcyi |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .knmra |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .wtn |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .kjnw |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .okpgp |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .oxbitk |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .dplkzo |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .psnue |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .lida |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .arovjd |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .xsnm |
Source: SYSDM.CPL.5.dr |
Static PE information: section name: .cav |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .qkm |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .cvjb |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .tlmkv |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .wucsxe |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .wnx |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .weqy |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .yby |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .ormx |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .dhclu |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .xmiul |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .tlwcxe |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .get |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .hzrd |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .gfrpb |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .ymlijr |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .tntrb |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .rmvhl |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .ukcyi |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .knmra |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .wtn |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .kjnw |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .okpgp |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .oxbitk |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .dplkzo |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .psnue |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .lida |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .arovjd |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .xsnm |
Source: dwmapi.dll.5.dr |
Static PE information: section name: .ebzjsb |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .qkm |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .cvjb |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .tlmkv |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .wucsxe |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .wnx |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .weqy |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .yby |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .ormx |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .dhclu |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .xmiul |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .tlwcxe |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .get |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .hzrd |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .gfrpb |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .ymlijr |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .tntrb |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .rmvhl |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .ukcyi |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .knmra |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .wtn |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .kjnw |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .okpgp |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .oxbitk |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .dplkzo |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .psnue |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .lida |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .arovjd |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .xsnm |
Source: dwmapi.dll0.5.dr |
Static PE information: section name: .guwfpe |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .qkm |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .cvjb |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .tlmkv |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .wucsxe |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .wnx |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .weqy |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .yby |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .ormx |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .dhclu |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .xmiul |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .tlwcxe |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .get |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .hzrd |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .gfrpb |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .ymlijr |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .tntrb |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .rmvhl |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .ukcyi |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .knmra |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .wtn |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .kjnw |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .okpgp |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .oxbitk |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .dplkzo |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .psnue |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .lida |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .arovjd |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .xsnm |
Source: WTSAPI32.dll.5.dr |
Static PE information: section name: .ewk |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014005D290 FindFirstFileExW, |
0_2_000000014005D290 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B2466334 #620,#624,#6050,#1040,#1040,#4436,#1122,#1040,#624,#1259,#1040,#626,FindFirstFileW,#624,#1259,#1262,#1122,#1040,#1040,#1040,_wcsicmp,SetFileAttributesW,DeleteFileW,FindNextFileW,FindClose,#624,#1259,#1040,FindFirstFileW,#622,#624,#624,#1259,#1259,#1040,#1040,#1040,#1040,#1040,FindNextFileW,FindClose,RemoveDirectoryW,#1040,#1040,#1040,#1040, |
33_2_00007FF7B2466334 |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B24672AC #624,FindFirstFileW,FindClose,#6050,_wcsicmp,#1040,#1463,_wcsicmp,#624,CreateFileW,GetFileSize,ReadFile,CloseHandle,#1040,CreateFileW,#6886,CloseHandle,#6886,_wcsicmp,#626,#624,#1040,#624,#1122,SetupIterateCabinetW,#1040,#626,#626,RegOpenKeyExW,RegGetValueW,#1126,RegCloseKey,#1040,#1040,#1040,RegOpenKeyExW,#624,#2975,RegSetValueExW,#1122,RegCloseKey,#1040,RegCloseKey,#620,#620,#628,#1042,#1040,#1040,#622,#1259,#1122,#1040,#1040,#1284,#2783,#1040,#1040,#1040,#1042,#1040,#1040,#1040,#1040,#1040,#1040,GetLastError,#626,#626,#4473,#4473,#1287,#1287,MessageBoxW,#1040,#1040,#1040, |
33_2_00007FF7B24672AC |
Source: C:\Users\user\AppData\Local\52smNq1W\msinfo32.exe |
Code function: 33_2_00007FF7B2465DE8 #626,#626,#1122,#624,#6050,#1040,#1040,#624,#1284,#1040,#1259,#1122,#1040,FindFirstFileW,#624,#1259,#1358,#1040,#1040,FindNextFileW,FindClose,#624,#1259,#1122,#1040,#1040,FindFirstFileW,#624,#1259,#1040,#1040,FindNextFileW,FindClose,#1040,#1040, |
33_2_00007FF7B2465DE8 |