Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140034870 |
0_2_0000000140034870 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140035270 |
0_2_0000000140035270 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140048AC0 |
0_2_0000000140048AC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014005C340 |
0_2_000000014005C340 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140065B80 |
0_2_0000000140065B80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006A4B0 |
0_2_000000014006A4B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400524B0 |
0_2_00000001400524B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140026CC0 |
0_2_0000000140026CC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014004BD40 |
0_2_000000014004BD40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400495B0 |
0_2_00000001400495B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140036F30 |
0_2_0000000140036F30 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140069010 |
0_2_0000000140069010 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140001010 |
0_2_0000000140001010 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140066020 |
0_2_0000000140066020 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002F840 |
0_2_000000014002F840 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014005D850 |
0_2_000000014005D850 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140064080 |
0_2_0000000140064080 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140010880 |
0_2_0000000140010880 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400688A0 |
0_2_00000001400688A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002D0D0 |
0_2_000000014002D0D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400018D0 |
0_2_00000001400018D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140016100 |
0_2_0000000140016100 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014001D100 |
0_2_000000014001D100 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002A110 |
0_2_000000014002A110 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014001D910 |
0_2_000000014001D910 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140015120 |
0_2_0000000140015120 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014000B120 |
0_2_000000014000B120 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014004F940 |
0_2_000000014004F940 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140039140 |
0_2_0000000140039140 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140023140 |
0_2_0000000140023140 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140057950 |
0_2_0000000140057950 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014001E170 |
0_2_000000014001E170 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140002980 |
0_2_0000000140002980 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400611A0 |
0_2_00000001400611A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400389A0 |
0_2_00000001400389A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400381A0 |
0_2_00000001400381A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002E1B0 |
0_2_000000014002E1B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400139D0 |
0_2_00000001400139D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400319F0 |
0_2_00000001400319F0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002EA00 |
0_2_000000014002EA00 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140022A00 |
0_2_0000000140022A00 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014003B220 |
0_2_000000014003B220 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140067A40 |
0_2_0000000140067A40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140069A50 |
0_2_0000000140069A50 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140007A60 |
0_2_0000000140007A60 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014003AAC0 |
0_2_000000014003AAC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014003A2E0 |
0_2_000000014003A2E0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140062B00 |
0_2_0000000140062B00 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140018300 |
0_2_0000000140018300 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002FB20 |
0_2_000000014002FB20 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140031340 |
0_2_0000000140031340 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140022340 |
0_2_0000000140022340 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140017B40 |
0_2_0000000140017B40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014000BB40 |
0_2_000000014000BB40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014004EB60 |
0_2_000000014004EB60 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140005370 |
0_2_0000000140005370 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002CB80 |
0_2_000000014002CB80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B390 |
0_2_000000014006B390 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140054BA0 |
0_2_0000000140054BA0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140033BB0 |
0_2_0000000140033BB0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400263C0 |
0_2_00000001400263C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400123C0 |
0_2_00000001400123C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140063BD0 |
0_2_0000000140063BD0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400663F0 |
0_2_00000001400663F0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140023BF0 |
0_2_0000000140023BF0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B41B |
0_2_000000014006B41B |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B424 |
0_2_000000014006B424 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B42D |
0_2_000000014006B42D |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B436 |
0_2_000000014006B436 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B43D |
0_2_000000014006B43D |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140024440 |
0_2_0000000140024440 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140005C40 |
0_2_0000000140005C40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006B446 |
0_2_000000014006B446 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014005F490 |
0_2_000000014005F490 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140022D00 |
0_2_0000000140022D00 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140035520 |
0_2_0000000140035520 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140019D20 |
0_2_0000000140019D20 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140030530 |
0_2_0000000140030530 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140023530 |
0_2_0000000140023530 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140031540 |
0_2_0000000140031540 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140033540 |
0_2_0000000140033540 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014007BD50 |
0_2_000000014007BD50 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140078570 |
0_2_0000000140078570 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140019580 |
0_2_0000000140019580 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400205A0 |
0_2_00000001400205A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140025DB0 |
0_2_0000000140025DB0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140071DC0 |
0_2_0000000140071DC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014000C5C0 |
0_2_000000014000C5C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002DDE0 |
0_2_000000014002DDE0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140031DF0 |
0_2_0000000140031DF0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014000DDF0 |
0_2_000000014000DDF0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140001620 |
0_2_0000000140001620 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140018630 |
0_2_0000000140018630 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140032650 |
0_2_0000000140032650 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140064E80 |
0_2_0000000140064E80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140016E80 |
0_2_0000000140016E80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140007EA0 |
0_2_0000000140007EA0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400286B0 |
0_2_00000001400286B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140006EB0 |
0_2_0000000140006EB0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400276C0 |
0_2_00000001400276C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002FEC0 |
0_2_000000014002FEC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002EED0 |
0_2_000000014002EED0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014002B6E0 |
0_2_000000014002B6E0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140053F20 |
0_2_0000000140053F20 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140022730 |
0_2_0000000140022730 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140029780 |
0_2_0000000140029780 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140018F80 |
0_2_0000000140018F80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014003EFB0 |
0_2_000000014003EFB0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400067B0 |
0_2_00000001400067B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00000001400667D0 |
0_2_00000001400667D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140060FE0 |
0_2_0000000140060FE0 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3CAA8E0 |
22_2_00007FF7A3CAA8E0 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3C8F0B4 |
22_2_00007FF7A3C8F0B4 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3C9ECB8 |
22_2_00007FF7A3C9ECB8 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3C8B868 |
22_2_00007FF7A3C8B868 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3C91018 |
22_2_00007FF7A3C91018 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3C98408 |
22_2_00007FF7A3C98408 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3CA7400 |
22_2_00007FF7A3CA7400 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3CA0800 |
22_2_00007FF7A3CA0800 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3C9CF68 |
22_2_00007FF7A3C9CF68 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3CA9F38 |
22_2_00007FF7A3CA9F38 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3C85B08 |
22_2_00007FF7A3C85B08 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3CAD6B0 |
22_2_00007FF7A3CAD6B0 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3C992C0 |
22_2_00007FF7A3C992C0 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3CAB260 |
22_2_00007FF7A3CAB260 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3C99A7C |
22_2_00007FF7A3C99A7C |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3C945BC |
22_2_00007FF7A3C945BC |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3CA4960 |
22_2_00007FF7A3CA4960 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3C94158 |
22_2_00007FF7A3C94158 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3CA9530 |
22_2_00007FF7A3CA9530 |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3C8913C |
22_2_00007FF7A3C8913C |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB5E264 |
28_2_00007FF7EDB5E264 |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB57A6C |
28_2_00007FF7EDB57A6C |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB5F0E0 |
28_2_00007FF7EDB5F0E0 |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB59104 |
28_2_00007FF7EDB59104 |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB61CB0 |
28_2_00007FF7EDB61CB0 |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB53C70 |
28_2_00007FF7EDB53C70 |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB54890 |
28_2_00007FF7EDB54890 |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB58C24 |
28_2_00007FF7EDB58C24 |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB573E0 |
28_2_00007FF7EDB573E0 |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB527C4 |
28_2_00007FF7EDB527C4 |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB57770 |
28_2_00007FF7EDB57770 |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB5534C |
28_2_00007FF7EDB5534C |
Source: C:\Users\user\AppData\Local\nPqx0Ph\sessionmsg.exe |
Code function: 33_2_00007FF679361E94 |
33_2_00007FF679361E94 |
Source: C:\Users\user\AppData\Local\nPqx0Ph\sessionmsg.exe |
Code function: 33_2_00007FF6793644E0 |
33_2_00007FF6793644E0 |
Source: C:\Users\user\AppData\Local\nPqx0Ph\sessionmsg.exe |
Code function: 33_2_00007FF679361778 |
33_2_00007FF679361778 |
Source: C:\Users\user\AppData\Local\nPqx0Ph\sessionmsg.exe |
Code function: 33_2_00007FF679363B58 |
33_2_00007FF679363B58 |
Source: C:\Users\user\AppData\Local\nPqx0Ph\sessionmsg.exe |
Code function: 33_2_00007FF679363168 |
33_2_00007FF679363168 |
Source: C:\Users\user\AppData\Local\nPqx0Ph\sessionmsg.exe |
Code function: 33_2_00007FF679364A20 |
33_2_00007FF679364A20 |
Source: C:\Users\user\AppData\Local\buYWmbl3\WindowsActionDialog.exe |
Code function: 36_2_00007FF6A5E046D8 |
36_2_00007FF6A5E046D8 |
Source: C:\Users\user\AppData\Local\buYWmbl3\WindowsActionDialog.exe |
Code function: 36_2_00007FF6A5E03E8C |
36_2_00007FF6A5E03E8C |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A34534C |
38_2_00007FF65A34534C |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A347770 |
38_2_00007FF65A347770 |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A348C24 |
38_2_00007FF65A348C24 |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A3427C4 |
38_2_00007FF65A3427C4 |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A3473E0 |
38_2_00007FF65A3473E0 |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A344890 |
38_2_00007FF65A344890 |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A351CB0 |
38_2_00007FF65A351CB0 |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A343C70 |
38_2_00007FF65A343C70 |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A349104 |
38_2_00007FF65A349104 |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A34F0E0 |
38_2_00007FF65A34F0E0 |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A34E264 |
38_2_00007FF65A34E264 |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A347A6C |
38_2_00007FF65A347A6C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_0000000140046C90 NtClose, |
0_2_0000000140046C90 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_000000014006A4B0 NtQuerySystemInformation, |
0_2_000000014006A4B0 |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB585A0 RtlInitUnicodeString,NtCreateFile,SetWaitableTimer,socket,CancelIo,CloseHandle,NtDeviceIoControlFile,closesocket,CancelIo,CloseHandle,SetWaitableTimer,NtDeviceIoControlFile, |
28_2_00007FF7EDB585A0 |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB58994 NtDeviceIoControlFile,WaitForSingleObject,memset,MultiByteToWideChar,lstrlenW,Sleep,memset, |
28_2_00007FF7EDB58994 |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB58900 PostMessageW,NtDeviceIoControlFile, |
28_2_00007FF7EDB58900 |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB587B0 PostMessageW,NtDeviceIoControlFile,closesocket,CloseHandle,SetWaitableTimer, |
28_2_00007FF7EDB587B0 |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A3487B0 PostMessageW,NtDeviceIoControlFile,closesocket,CloseHandle,SetWaitableTimer, |
38_2_00007FF65A3487B0 |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A348900 PostMessageW,NtDeviceIoControlFile, |
38_2_00007FF65A348900 |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A348994 NtDeviceIoControlFile,WaitForSingleObject,memset,MultiByteToWideChar,lstrlenW,Sleep,memset, |
38_2_00007FF65A348994 |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A3485A0 RtlInitUnicodeString,NtCreateFile,SetWaitableTimer,socket,CancelIo,CloseHandle,NtDeviceIoControlFile,closesocket,CancelIo,CloseHandle,SetWaitableTimer,NtDeviceIoControlFile, |
38_2_00007FF65A3485A0 |
Source: irftp.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe0.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe0.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe0.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe0.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe0.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe0.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe0.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe0.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe0.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: irftp.exe0.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: PresentationHost.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: PresentationHost.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: PresentationHost.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: PresentationHost.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: PresentationHost.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: PresentationHost.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: PresentationHost.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: PresentationHost.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: PresentationHost.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: PresentationHost.exe.8.dr |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: unknown |
Process created: C:\Windows\System32\loaddll64.exe loaddll64.exe 'C:\Users\user\Desktop\1zdJLxxTnh.dll' |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\1zdJLxxTnh.dll',#1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\1zdJLxxTnh.dll',#1 |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\1zdJLxxTnh.dll,??0?$PatternProvider@VExpandCollapseProvider@DirectUI@@UIExpandCollapseProvider@@$00@DirectUI@@QEAA@XZ |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\1zdJLxxTnh.dll,??0?$PatternProvider@VGridItemProvider@DirectUI@@UIGridItemProvider@@$01@DirectUI@@QEAA@XZ |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\1zdJLxxTnh.dll,??0?$PatternProvider@VGridProvider@DirectUI@@UIGridProvider@@$02@DirectUI@@QEAA@XZ |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\ProximityUxHost.exe C:\Windows\system32\ProximityUxHost.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\rstrui.exe C:\Windows\system32\rstrui.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\irftp.exe C:\Windows\system32\irftp.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\SystemPropertiesComputerName.exe C:\Windows\system32\SystemPropertiesComputerName.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\sessionmsg.exe C:\Windows\system32\sessionmsg.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\nPqx0Ph\sessionmsg.exe C:\Users\user\AppData\Local\nPqx0Ph\sessionmsg.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\WindowsActionDialog.exe C:\Windows\system32\WindowsActionDialog.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\buYWmbl3\WindowsActionDialog.exe C:\Users\user\AppData\Local\buYWmbl3\WindowsActionDialog.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\irftp.exe C:\Windows\system32\irftp.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\hJiut\irftp.exe C:\Users\user\AppData\Local\hJiut\irftp.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\osk.exe C:\Windows\system32\osk.exe |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\1zdJLxxTnh.dll',#1 |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\1zdJLxxTnh.dll,??0?$PatternProvider@VExpandCollapseProvider@DirectUI@@UIExpandCollapseProvider@@$00@DirectUI@@QEAA@XZ |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\1zdJLxxTnh.dll,??0?$PatternProvider@VGridItemProvider@DirectUI@@UIGridItemProvider@@$01@DirectUI@@QEAA@XZ |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\1zdJLxxTnh.dll,??0?$PatternProvider@VGridProvider@DirectUI@@UIGridProvider@@$02@DirectUI@@QEAA@XZ |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\1zdJLxxTnh.dll',#1 |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\ProximityUxHost.exe C:\Windows\system32\ProximityUxHost.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\rstrui.exe C:\Windows\system32\rstrui.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\irftp.exe C:\Windows\system32\irftp.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\SystemPropertiesComputerName.exe C:\Windows\system32\SystemPropertiesComputerName.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\sessionmsg.exe C:\Windows\system32\sessionmsg.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\nPqx0Ph\sessionmsg.exe C:\Users\user\AppData\Local\nPqx0Ph\sessionmsg.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\WindowsActionDialog.exe C:\Windows\system32\WindowsActionDialog.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\buYWmbl3\WindowsActionDialog.exe C:\Users\user\AppData\Local\buYWmbl3\WindowsActionDialog.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\irftp.exe C:\Windows\system32\irftp.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\hJiut\irftp.exe C:\Users\user\AppData\Local\hJiut\irftp.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\osk.exe C:\Windows\system32\osk.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .qkm |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .cvjb |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .tlmkv |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .wucsxe |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .fltwtj |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .tblq |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .hcmjm |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .nagyk |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .jrucz |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .rnr |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .rdc |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .umrigl |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .nepl |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .akkqh |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .cvbwr |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .ftrk |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .ubbf |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .ulwqi |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .imcflb |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .hgmkm |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .cnoij |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .qgdv |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .hsbye |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .cdn |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .hte |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .vcnknm |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .thfe |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .tat |
Source: 1zdJLxxTnh.dll |
Static PE information: section name: .xqltbd |
Source: ProximityUxHost.exe.8.dr |
Static PE information: section name: .imrsiv |
Source: sessionmsg.exe.8.dr |
Static PE information: section name: .imrsiv |
Source: WindowsActionDialog.exe.8.dr |
Static PE information: section name: .imrsiv |
Source: CameraSettingsUIHost.exe.8.dr |
Static PE information: section name: .imrsiv |
Source: DUI70.dll.8.dr |
Static PE information: section name: .qkm |
Source: DUI70.dll.8.dr |
Static PE information: section name: .cvjb |
Source: DUI70.dll.8.dr |
Static PE information: section name: .tlmkv |
Source: DUI70.dll.8.dr |
Static PE information: section name: .wucsxe |
Source: DUI70.dll.8.dr |
Static PE information: section name: .fltwtj |
Source: DUI70.dll.8.dr |
Static PE information: section name: .tblq |
Source: DUI70.dll.8.dr |
Static PE information: section name: .hcmjm |
Source: DUI70.dll.8.dr |
Static PE information: section name: .nagyk |
Source: DUI70.dll.8.dr |
Static PE information: section name: .jrucz |
Source: DUI70.dll.8.dr |
Static PE information: section name: .rnr |
Source: DUI70.dll.8.dr |
Static PE information: section name: .rdc |
Source: DUI70.dll.8.dr |
Static PE information: section name: .umrigl |
Source: DUI70.dll.8.dr |
Static PE information: section name: .nepl |
Source: DUI70.dll.8.dr |
Static PE information: section name: .akkqh |
Source: DUI70.dll.8.dr |
Static PE information: section name: .cvbwr |
Source: DUI70.dll.8.dr |
Static PE information: section name: .ftrk |
Source: DUI70.dll.8.dr |
Static PE information: section name: .ubbf |
Source: DUI70.dll.8.dr |
Static PE information: section name: .ulwqi |
Source: DUI70.dll.8.dr |
Static PE information: section name: .imcflb |
Source: DUI70.dll.8.dr |
Static PE information: section name: .hgmkm |
Source: DUI70.dll.8.dr |
Static PE information: section name: .cnoij |
Source: DUI70.dll.8.dr |
Static PE information: section name: .qgdv |
Source: DUI70.dll.8.dr |
Static PE information: section name: .hsbye |
Source: DUI70.dll.8.dr |
Static PE information: section name: .cdn |
Source: DUI70.dll.8.dr |
Static PE information: section name: .hte |
Source: DUI70.dll.8.dr |
Static PE information: section name: .vcnknm |
Source: DUI70.dll.8.dr |
Static PE information: section name: .thfe |
Source: DUI70.dll.8.dr |
Static PE information: section name: .tat |
Source: DUI70.dll.8.dr |
Static PE information: section name: .xqltbd |
Source: DUI70.dll.8.dr |
Static PE information: section name: .ypfdqp |
Source: WINMM.dll.8.dr |
Static PE information: section name: .qkm |
Source: WINMM.dll.8.dr |
Static PE information: section name: .cvjb |
Source: WINMM.dll.8.dr |
Static PE information: section name: .tlmkv |
Source: WINMM.dll.8.dr |
Static PE information: section name: .wucsxe |
Source: WINMM.dll.8.dr |
Static PE information: section name: .fltwtj |
Source: WINMM.dll.8.dr |
Static PE information: section name: .tblq |
Source: WINMM.dll.8.dr |
Static PE information: section name: .hcmjm |
Source: WINMM.dll.8.dr |
Static PE information: section name: .nagyk |
Source: WINMM.dll.8.dr |
Static PE information: section name: .jrucz |
Source: WINMM.dll.8.dr |
Static PE information: section name: .rnr |
Source: WINMM.dll.8.dr |
Static PE information: section name: .rdc |
Source: WINMM.dll.8.dr |
Static PE information: section name: .umrigl |
Source: WINMM.dll.8.dr |
Static PE information: section name: .nepl |
Source: WINMM.dll.8.dr |
Static PE information: section name: .akkqh |
Source: WINMM.dll.8.dr |
Static PE information: section name: .cvbwr |
Source: WINMM.dll.8.dr |
Static PE information: section name: .ftrk |
Source: WINMM.dll.8.dr |
Static PE information: section name: .ubbf |
Source: WINMM.dll.8.dr |
Static PE information: section name: .ulwqi |
Source: WINMM.dll.8.dr |
Static PE information: section name: .imcflb |
Source: WINMM.dll.8.dr |
Static PE information: section name: .hgmkm |
Source: WINMM.dll.8.dr |
Static PE information: section name: .cnoij |
Source: WINMM.dll.8.dr |
Static PE information: section name: .qgdv |
Source: WINMM.dll.8.dr |
Static PE information: section name: .hsbye |
Source: WINMM.dll.8.dr |
Static PE information: section name: .cdn |
Source: WINMM.dll.8.dr |
Static PE information: section name: .hte |
Source: WINMM.dll.8.dr |
Static PE information: section name: .vcnknm |
Source: WINMM.dll.8.dr |
Static PE information: section name: .thfe |
Source: WINMM.dll.8.dr |
Static PE information: section name: .tat |
Source: WINMM.dll.8.dr |
Static PE information: section name: .xqltbd |
Source: WINMM.dll.8.dr |
Static PE information: section name: .nghj |
Source: DUser.dll.8.dr |
Static PE information: section name: .qkm |
Source: DUser.dll.8.dr |
Static PE information: section name: .cvjb |
Source: DUser.dll.8.dr |
Static PE information: section name: .tlmkv |
Source: DUser.dll.8.dr |
Static PE information: section name: .wucsxe |
Source: DUser.dll.8.dr |
Static PE information: section name: .fltwtj |
Source: DUser.dll.8.dr |
Static PE information: section name: .tblq |
Source: DUser.dll.8.dr |
Static PE information: section name: .hcmjm |
Source: DUser.dll.8.dr |
Static PE information: section name: .nagyk |
Source: DUser.dll.8.dr |
Static PE information: section name: .jrucz |
Source: DUser.dll.8.dr |
Static PE information: section name: .rnr |
Source: DUser.dll.8.dr |
Static PE information: section name: .rdc |
Source: DUser.dll.8.dr |
Static PE information: section name: .umrigl |
Source: DUser.dll.8.dr |
Static PE information: section name: .nepl |
Source: DUser.dll.8.dr |
Static PE information: section name: .akkqh |
Source: DUser.dll.8.dr |
Static PE information: section name: .cvbwr |
Source: DUser.dll.8.dr |
Static PE information: section name: .ftrk |
Source: DUser.dll.8.dr |
Static PE information: section name: .ubbf |
Source: DUser.dll.8.dr |
Static PE information: section name: .ulwqi |
Source: DUser.dll.8.dr |
Static PE information: section name: .imcflb |
Source: DUser.dll.8.dr |
Static PE information: section name: .hgmkm |
Source: DUser.dll.8.dr |
Static PE information: section name: .cnoij |
Source: DUser.dll.8.dr |
Static PE information: section name: .qgdv |
Source: DUser.dll.8.dr |
Static PE information: section name: .hsbye |
Source: DUser.dll.8.dr |
Static PE information: section name: .cdn |
Source: DUser.dll.8.dr |
Static PE information: section name: .hte |
Source: DUser.dll.8.dr |
Static PE information: section name: .vcnknm |
Source: DUser.dll.8.dr |
Static PE information: section name: .thfe |
Source: DUser.dll.8.dr |
Static PE information: section name: .tat |
Source: DUser.dll.8.dr |
Static PE information: section name: .xqltbd |
Source: DUser.dll.8.dr |
Static PE information: section name: .lebs |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .qkm |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .cvjb |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .tlmkv |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .wucsxe |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .fltwtj |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .tblq |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .hcmjm |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .nagyk |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .jrucz |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .rnr |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .rdc |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .umrigl |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .nepl |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .akkqh |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .cvbwr |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .ftrk |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .ubbf |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .ulwqi |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .imcflb |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .hgmkm |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .cnoij |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .qgdv |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .hsbye |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .cdn |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .hte |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .vcnknm |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .thfe |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .tat |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .xqltbd |
Source: DUI70.dll0.8.dr |
Static PE information: section name: .lzkq |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .qkm |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .cvjb |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .tlmkv |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .wucsxe |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .fltwtj |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .tblq |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .hcmjm |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .nagyk |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .jrucz |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .rnr |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .rdc |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .umrigl |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .nepl |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .akkqh |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .cvbwr |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .ftrk |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .ubbf |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .ulwqi |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .imcflb |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .hgmkm |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .cnoij |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .qgdv |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .hsbye |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .cdn |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .hte |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .vcnknm |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .thfe |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .tat |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .xqltbd |
Source: MFC42u.dll.8.dr |
Static PE information: section name: .qhr |
Source: VERSION.dll.8.dr |
Static PE information: section name: .qkm |
Source: VERSION.dll.8.dr |
Static PE information: section name: .cvjb |
Source: VERSION.dll.8.dr |
Static PE information: section name: .tlmkv |
Source: VERSION.dll.8.dr |
Static PE information: section name: .wucsxe |
Source: VERSION.dll.8.dr |
Static PE information: section name: .fltwtj |
Source: VERSION.dll.8.dr |
Static PE information: section name: .tblq |
Source: VERSION.dll.8.dr |
Static PE information: section name: .hcmjm |
Source: VERSION.dll.8.dr |
Static PE information: section name: .nagyk |
Source: VERSION.dll.8.dr |
Static PE information: section name: .jrucz |
Source: VERSION.dll.8.dr |
Static PE information: section name: .rnr |
Source: VERSION.dll.8.dr |
Static PE information: section name: .rdc |
Source: VERSION.dll.8.dr |
Static PE information: section name: .umrigl |
Source: VERSION.dll.8.dr |
Static PE information: section name: .nepl |
Source: VERSION.dll.8.dr |
Static PE information: section name: .akkqh |
Source: VERSION.dll.8.dr |
Static PE information: section name: .cvbwr |
Source: VERSION.dll.8.dr |
Static PE information: section name: .ftrk |
Source: VERSION.dll.8.dr |
Static PE information: section name: .ubbf |
Source: VERSION.dll.8.dr |
Static PE information: section name: .ulwqi |
Source: VERSION.dll.8.dr |
Static PE information: section name: .imcflb |
Source: VERSION.dll.8.dr |
Static PE information: section name: .hgmkm |
Source: VERSION.dll.8.dr |
Static PE information: section name: .cnoij |
Source: VERSION.dll.8.dr |
Static PE information: section name: .qgdv |
Source: VERSION.dll.8.dr |
Static PE information: section name: .hsbye |
Source: VERSION.dll.8.dr |
Static PE information: section name: .cdn |
Source: VERSION.dll.8.dr |
Static PE information: section name: .hte |
Source: VERSION.dll.8.dr |
Static PE information: section name: .vcnknm |
Source: VERSION.dll.8.dr |
Static PE information: section name: .thfe |
Source: VERSION.dll.8.dr |
Static PE information: section name: .tat |
Source: VERSION.dll.8.dr |
Static PE information: section name: .xqltbd |
Source: VERSION.dll.8.dr |
Static PE information: section name: .pwi |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .qkm |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .cvjb |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .tlmkv |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .wucsxe |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .fltwtj |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .tblq |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .hcmjm |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .nagyk |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .jrucz |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .rnr |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .rdc |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .umrigl |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .nepl |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .akkqh |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .cvbwr |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .ftrk |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .ubbf |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .ulwqi |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .imcflb |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .hgmkm |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .cnoij |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .qgdv |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .hsbye |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .cdn |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .hte |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .vcnknm |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .thfe |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .tat |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .xqltbd |
Source: DUI70.dll1.8.dr |
Static PE information: section name: .tvyui |
Source: C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe |
Code function: 22_2_00007FF7A3C9C8A0 TlsGetValue,TlsSetValue,?Create@DUIXmlParser@DirectUI@@SAJPEAPEAV12@P6APEAVValue@2@PEBGPEAX@Z2P6AX11H2@Z2@Z,?SetXMLFromResource@DUIXmlParser@DirectUI@@QEAAJIPEAUHINSTANCE__@@0@Z,?CreateElement@DUIXmlParser@DirectUI@@QEAAJPEBGPEAVElement@2@1PEAKPEAPEAV32@@Z,?AddListener@Element@DirectUI@@QEAAJPEAUIElementListener@2@@Z,?CreateBool@Value@DirectUI@@SAPEAV12@_N@Z,?AccessibleProp@Element@DirectUI@@SAPEBUPropertyInfo@2@XZ,?SetValue@Element@DirectUI@@QEAAJP6APEBUPropertyInfo@2@XZHPEAVValue@2@@Z,?_ZeroRelease@Value@DirectUI@@AEAAXXZ,StrToID,?FindDescendent@Element@DirectUI@@QEAAPEAV12@G@Z,?GetClassInfoPtr@ModernProgressBar@DirectUI@@SAPEAUIClassInfo@2@XZ,?Destroy@DUIXmlParser@DirectUI@@QEAAXXZ,TlsGetValue,TlsSetValue, |
22_2_00007FF7A3C9C8A0 |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB5EE8C socket,WSAGetLastError,memset,setsockopt,WSAGetLastError,closesocket,setsockopt,memset,bind,listen,CreateIoCompletionPort, |
28_2_00007FF7EDB5EE8C |
Source: C:\Users\user\AppData\Local\94LPZAU0\irftp.exe |
Code function: 28_2_00007FF7EDB5A078 WSAStartup,OpenFileMappingW,MapViewOfFile,CloseHandle,GetLastError,DbgPrint,lstrcmpA,WSASocketW,UnmapViewOfFile,WSAGetLastError,DbgPrint,socket,WSAGetLastError,bind,WSAGetLastError,closesocket,listen,closesocket, |
28_2_00007FF7EDB5A078 |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A34A078 WSAStartup,OpenFileMappingW,MapViewOfFile,CloseHandle,GetLastError,DbgPrint,lstrcmpA,WSASocketW,UnmapViewOfFile,WSAGetLastError,DbgPrint,socket,WSAGetLastError,bind,WSAGetLastError,closesocket,listen,closesocket, |
38_2_00007FF65A34A078 |
Source: C:\Users\user\AppData\Local\hJiut\irftp.exe |
Code function: 38_2_00007FF65A34EE8C socket,WSAGetLastError,memset,setsockopt,WSAGetLastError,closesocket,setsockopt,memset,bind,listen,CreateIoCompletionPort, |
38_2_00007FF65A34EE8C |