Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140034870 |
1_2_0000000140034870 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140035270 |
1_2_0000000140035270 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140048AC0 |
1_2_0000000140048AC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014005C340 |
1_2_000000014005C340 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140065B80 |
1_2_0000000140065B80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014006A4B0 |
1_2_000000014006A4B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400524B0 |
1_2_00000001400524B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140026CC0 |
1_2_0000000140026CC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004BD40 |
1_2_000000014004BD40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400495B0 |
1_2_00000001400495B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140036F30 |
1_2_0000000140036F30 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140069010 |
1_2_0000000140069010 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140001010 |
1_2_0000000140001010 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140066020 |
1_2_0000000140066020 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002F840 |
1_2_000000014002F840 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014005D850 |
1_2_000000014005D850 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140064080 |
1_2_0000000140064080 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140010880 |
1_2_0000000140010880 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400688A0 |
1_2_00000001400688A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002D0D0 |
1_2_000000014002D0D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400018D0 |
1_2_00000001400018D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140016100 |
1_2_0000000140016100 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014001D100 |
1_2_000000014001D100 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002A110 |
1_2_000000014002A110 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014001D910 |
1_2_000000014001D910 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140015120 |
1_2_0000000140015120 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014000B120 |
1_2_000000014000B120 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004F940 |
1_2_000000014004F940 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140039140 |
1_2_0000000140039140 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140023140 |
1_2_0000000140023140 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140057950 |
1_2_0000000140057950 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014001E170 |
1_2_000000014001E170 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140002980 |
1_2_0000000140002980 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400611A0 |
1_2_00000001400611A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400389A0 |
1_2_00000001400389A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400381A0 |
1_2_00000001400381A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002E1B0 |
1_2_000000014002E1B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400139D0 |
1_2_00000001400139D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400319F0 |
1_2_00000001400319F0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002EA00 |
1_2_000000014002EA00 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140022A00 |
1_2_0000000140022A00 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014003B220 |
1_2_000000014003B220 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140067A40 |
1_2_0000000140067A40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140069A50 |
1_2_0000000140069A50 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140007A60 |
1_2_0000000140007A60 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014003AAC0 |
1_2_000000014003AAC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014003A2E0 |
1_2_000000014003A2E0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140062B00 |
1_2_0000000140062B00 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140018300 |
1_2_0000000140018300 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002FB20 |
1_2_000000014002FB20 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140031340 |
1_2_0000000140031340 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140022340 |
1_2_0000000140022340 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140017B40 |
1_2_0000000140017B40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014000BB40 |
1_2_000000014000BB40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004EB60 |
1_2_000000014004EB60 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140005370 |
1_2_0000000140005370 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002CB80 |
1_2_000000014002CB80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014006B390 |
1_2_000000014006B390 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140054BA0 |
1_2_0000000140054BA0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140033BB0 |
1_2_0000000140033BB0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400263C0 |
1_2_00000001400263C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400123C0 |
1_2_00000001400123C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140063BD0 |
1_2_0000000140063BD0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400663F0 |
1_2_00000001400663F0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140023BF0 |
1_2_0000000140023BF0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014006B41B |
1_2_000000014006B41B |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014006B424 |
1_2_000000014006B424 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014006B42D |
1_2_000000014006B42D |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014006B436 |
1_2_000000014006B436 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014006B43D |
1_2_000000014006B43D |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140024440 |
1_2_0000000140024440 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140005C40 |
1_2_0000000140005C40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014006B446 |
1_2_000000014006B446 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014005F490 |
1_2_000000014005F490 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140022D00 |
1_2_0000000140022D00 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140035520 |
1_2_0000000140035520 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140019D20 |
1_2_0000000140019D20 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140030530 |
1_2_0000000140030530 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140023530 |
1_2_0000000140023530 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140031540 |
1_2_0000000140031540 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140033540 |
1_2_0000000140033540 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014007BD50 |
1_2_000000014007BD50 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140078570 |
1_2_0000000140078570 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140019580 |
1_2_0000000140019580 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400205A0 |
1_2_00000001400205A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140025DB0 |
1_2_0000000140025DB0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140071DC0 |
1_2_0000000140071DC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014000C5C0 |
1_2_000000014000C5C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002DDE0 |
1_2_000000014002DDE0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140031DF0 |
1_2_0000000140031DF0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014000DDF0 |
1_2_000000014000DDF0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140001620 |
1_2_0000000140001620 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140018630 |
1_2_0000000140018630 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140032650 |
1_2_0000000140032650 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140064E80 |
1_2_0000000140064E80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140016E80 |
1_2_0000000140016E80 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140007EA0 |
1_2_0000000140007EA0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400286B0 |
1_2_00000001400286B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140006EB0 |
1_2_0000000140006EB0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400276C0 |
1_2_00000001400276C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002FEC0 |
1_2_000000014002FEC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002EED0 |
1_2_000000014002EED0 |
Source: C:\Users\user\AppData\Local\SbH2\Netplwiz.exe |
Code function: 22_2_00007FF7D7312B04 |
22_2_00007FF7D7312B04 |
Source: C:\Users\user\AppData\Local\r4gbgdji\recdisc.exe |
Code function: 27_2_00007FF6C200D96C |
27_2_00007FF6C200D96C |
Source: C:\Users\user\AppData\Local\r4gbgdji\recdisc.exe |
Code function: 27_2_00007FF6C20092C4 |
27_2_00007FF6C20092C4 |
Source: C:\Users\user\AppData\Local\r4gbgdji\recdisc.exe |
Code function: 27_2_00007FF6C200231C |
27_2_00007FF6C200231C |
Source: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Code function: 31_2_00007FF6DC4CB9B4 |
31_2_00007FF6DC4CB9B4 |
Source: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Code function: 31_2_00007FF6DC4C5998 |
31_2_00007FF6DC4C5998 |
Source: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Code function: 31_2_00007FF6DC4CD570 |
31_2_00007FF6DC4CD570 |
Source: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Code function: 31_2_00007FF6DC4C5364 |
31_2_00007FF6DC4C5364 |
Source: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Code function: 31_2_00007FF6DC4CCE28 |
31_2_00007FF6DC4CCE28 |
Source: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Code function: 31_2_00007FF6DC4CD220 |
31_2_00007FF6DC4CD220 |
Source: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Code function: 31_2_00007FF6DC4C97D4 |
31_2_00007FF6DC4C97D4 |
Source: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Code function: 31_2_00007FF6DC4C83BC |
31_2_00007FF6DC4C83BC |
Source: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Code function: 31_2_00007FF6DC4C91DC |
31_2_00007FF6DC4C91DC |
Source: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Code function: 31_2_00007FF6DC4CA094 |
31_2_00007FF6DC4CA094 |
Source: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Code function: 31_2_00007FF6DC4C8058 |
31_2_00007FF6DC4C8058 |
Source: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Code function: 31_2_00007FF6DC4C730C |
31_2_00007FF6DC4C730C |
Source: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Code function: 31_2_00007FF6DC4C12F8 |
31_2_00007FF6DC4C12F8 |
Source: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Code function: 31_2_00007FF6DC4C6920 |
31_2_00007FF6DC4C6920 |
Source: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Code function: 31_2_00007FF6DC4C5EE0 |
31_2_00007FF6DC4C5EE0 |
Source: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Code function: 31_2_00007FF6DC4C84DC |
31_2_00007FF6DC4C84DC |
Source: C:\Users\user\AppData\Local\JaJWNKcB\wermgr.exe |
Code function: 36_2_00007FF7E2152F54 |
36_2_00007FF7E2152F54 |
Source: C:\Users\user\AppData\Local\JaJWNKcB\wermgr.exe |
Code function: 36_2_00007FF7E215E368 |
36_2_00007FF7E215E368 |
Source: C:\Users\user\AppData\Local\JaJWNKcB\wermgr.exe |
Code function: 36_2_00007FF7E215CFF0 |
36_2_00007FF7E215CFF0 |
Source: C:\Users\user\AppData\Local\JaJWNKcB\wermgr.exe |
Code function: 36_2_00007FF7E2162438 |
36_2_00007FF7E2162438 |
Source: C:\Users\user\AppData\Local\JaJWNKcB\wermgr.exe |
Code function: 36_2_00007FF7E2156848 |
36_2_00007FF7E2156848 |
Source: C:\Users\user\AppData\Local\JaJWNKcB\wermgr.exe |
Code function: 36_2_00007FF7E2160A58 |
36_2_00007FF7E2160A58 |
Source: C:\Users\user\AppData\Local\JaJWNKcB\wermgr.exe |
Code function: 36_2_00007FF7E2157EFC |
36_2_00007FF7E2157EFC |
Source: C:\Users\user\AppData\Local\02vERQ6Eo\wermgr.exe |
Code function: 39_2_00007FF75F9B7EFC |
39_2_00007FF75F9B7EFC |
Source: C:\Users\user\AppData\Local\02vERQ6Eo\wermgr.exe |
Code function: 39_2_00007FF75F9C2438 |
39_2_00007FF75F9C2438 |
Source: C:\Users\user\AppData\Local\02vERQ6Eo\wermgr.exe |
Code function: 39_2_00007FF75F9B6848 |
39_2_00007FF75F9B6848 |
Source: C:\Users\user\AppData\Local\02vERQ6Eo\wermgr.exe |
Code function: 39_2_00007FF75F9C0A58 |
39_2_00007FF75F9C0A58 |
Source: C:\Users\user\AppData\Local\02vERQ6Eo\wermgr.exe |
Code function: 39_2_00007FF75F9BCFF0 |
39_2_00007FF75F9BCFF0 |
Source: C:\Users\user\AppData\Local\02vERQ6Eo\wermgr.exe |
Code function: 39_2_00007FF75F9B2F54 |
39_2_00007FF75F9B2F54 |
Source: C:\Users\user\AppData\Local\02vERQ6Eo\wermgr.exe |
Code function: 39_2_00007FF75F9BE368 |
39_2_00007FF75F9BE368 |
Source: C:\Users\user\AppData\Local\iBq\rdpinput.exe |
Code function: 41_2_00007FF609402578 |
41_2_00007FF609402578 |
Source: C:\Users\user\AppData\Local\iBq\rdpinput.exe |
Code function: 41_2_00007FF60940FD48 |
41_2_00007FF60940FD48 |
Source: C:\Users\user\AppData\Local\iBq\rdpinput.exe |
Code function: 41_2_00007FF609403BE0 |
41_2_00007FF609403BE0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140046C90 NtClose, |
1_2_0000000140046C90 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014006A4B0 NtQuerySystemInformation, |
1_2_000000014006A4B0 |
Source: C:\Users\user\AppData\Local\r4gbgdji\recdisc.exe |
Code function: 27_2_00007FF6C2009F88 NtQuerySystemInformation, |
27_2_00007FF6C2009F88 |
Source: C:\Users\user\AppData\Local\r4gbgdji\recdisc.exe |
Code function: 27_2_00007FF6C20115EC memset,CreateFileW,memset,NtQueryInformationFile,NtSetInformationFile,CloseHandle, |
27_2_00007FF6C20115EC |
Source: C:\Users\user\AppData\Local\r4gbgdji\recdisc.exe |
Code function: 27_2_00007FF6C2011460 CreateFileW,NtQueryInformationFile,CloseHandle, |
27_2_00007FF6C2011460 |
Source: C:\Users\user\AppData\Local\JaJWNKcB\wermgr.exe |
Code function: 36_2_00007FF7E2161F54 NtQueryLicenseValue, |
36_2_00007FF7E2161F54 |
Source: C:\Users\user\AppData\Local\JaJWNKcB\wermgr.exe |
Code function: 36_2_00007FF7E215E368 ZwQueryWnfStateNameInformation,ZwUpdateWnfStateData,EtwEventWriteNoRegistration,NtQuerySystemInformation,NtOpenEvent,NtWaitForSingleObject,NtClose,RtlAllocateAndInitializeSid,RtlInitUnicodeString,memset,NtAlpcConnectPort,memset,NtAlpcSendWaitReceivePort,RtlFreeSid,NtClose, |
36_2_00007FF7E215E368 |
Source: C:\Users\user\AppData\Local\JaJWNKcB\wermgr.exe |
Code function: 36_2_00007FF7E2158404 DbgPrintEx,NtQueryInformationProcess,DbgPrintEx,DbgPrintEx,ReadProcessMemory,DbgPrintEx,GetLastError, |
36_2_00007FF7E2158404 |
Source: C:\Users\user\AppData\Local\JaJWNKcB\wermgr.exe |
Code function: 36_2_00007FF7E2162438 LoadLibraryExW,GetProcAddress,NtQueryLicenseValue,FreeLibrary,NtQueryLicenseValue, |
36_2_00007FF7E2162438 |
Source: C:\Users\user\AppData\Local\JaJWNKcB\wermgr.exe |
Code function: 36_2_00007FF7E21582EC DbgPrintEx,NtQueryInformationProcess,DbgPrintEx,DbgPrintEx,ReadProcessMemory,DbgPrintEx,GetLastError, |
36_2_00007FF7E21582EC |
Source: C:\Users\user\AppData\Local\02vERQ6Eo\wermgr.exe |
Code function: 39_2_00007FF75F9B82EC DbgPrintEx,NtQueryInformationProcess,DbgPrintEx,DbgPrintEx,ReadProcessMemory,DbgPrintEx,GetLastError, |
39_2_00007FF75F9B82EC |
Source: C:\Users\user\AppData\Local\02vERQ6Eo\wermgr.exe |
Code function: 39_2_00007FF75F9C2438 LoadLibraryExW,GetProcAddress,NtQueryLicenseValue,FreeLibrary,NtQueryLicenseValue, |
39_2_00007FF75F9C2438 |
Source: C:\Users\user\AppData\Local\02vERQ6Eo\wermgr.exe |
Code function: 39_2_00007FF75F9B8404 DbgPrintEx,NtQueryInformationProcess,DbgPrintEx,DbgPrintEx,ReadProcessMemory,DbgPrintEx,GetLastError, |
39_2_00007FF75F9B8404 |
Source: C:\Users\user\AppData\Local\02vERQ6Eo\wermgr.exe |
Code function: 39_2_00007FF75F9C1F54 NtQueryLicenseValue, |
39_2_00007FF75F9C1F54 |
Source: C:\Users\user\AppData\Local\02vERQ6Eo\wermgr.exe |
Code function: 39_2_00007FF75F9BE368 ZwQueryWnfStateNameInformation,ZwUpdateWnfStateData,EtwEventWriteNoRegistration,NtQuerySystemInformation,NtOpenEvent,NtWaitForSingleObject,NtClose,RtlAllocateAndInitializeSid,RtlInitUnicodeString,memset,NtAlpcConnectPort,memset,NtAlpcSendWaitReceivePort,RtlFreeSid,NtClose, |
39_2_00007FF75F9BE368 |
Source: unknown |
Process created: C:\Windows\System32\loaddll64.exe loaddll64.exe 'C:\Users\user\Desktop\yPeVDkBY3n.dll' |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\yPeVDkBY3n.dll',#1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\yPeVDkBY3n.dll',#1 |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\yPeVDkBY3n.dll,??0?$PatternProvider@VExpandCollapseProvider@DirectUI@@UIExpandCollapseProvider@@$00@DirectUI@@QEAA@XZ |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\yPeVDkBY3n.dll,??0?$PatternProvider@VGridItemProvider@DirectUI@@UIGridItemProvider@@$01@DirectUI@@QEAA@XZ |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\yPeVDkBY3n.dll,??0?$PatternProvider@VGridProvider@DirectUI@@UIGridProvider@@$02@DirectUI@@QEAA@XZ |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\Netplwiz.exe C:\Windows\system32\Netplwiz.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\SbH2\Netplwiz.exe C:\Users\user\AppData\Local\SbH2\Netplwiz.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\recdisc.exe C:\Windows\system32\recdisc.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\r4gbgdji\recdisc.exe C:\Users\user\AppData\Local\r4gbgdji\recdisc.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\phoneactivate.exe C:\Windows\system32\phoneactivate.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\wermgr.exe C:\Windows\system32\wermgr.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\JaJWNKcB\wermgr.exe C:\Users\user\AppData\Local\JaJWNKcB\wermgr.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\wermgr.exe C:\Windows\system32\wermgr.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\02vERQ6Eo\wermgr.exe C:\Users\user\AppData\Local\02vERQ6Eo\wermgr.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\rdpinput.exe C:\Windows\system32\rdpinput.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\iBq\rdpinput.exe C:\Users\user\AppData\Local\iBq\rdpinput.exe |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\yPeVDkBY3n.dll',#1 |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\yPeVDkBY3n.dll,??0?$PatternProvider@VExpandCollapseProvider@DirectUI@@UIExpandCollapseProvider@@$00@DirectUI@@QEAA@XZ |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\yPeVDkBY3n.dll,??0?$PatternProvider@VGridItemProvider@DirectUI@@UIGridItemProvider@@$01@DirectUI@@QEAA@XZ |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\yPeVDkBY3n.dll,??0?$PatternProvider@VGridProvider@DirectUI@@UIGridProvider@@$02@DirectUI@@QEAA@XZ |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\yPeVDkBY3n.dll',#1 |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\Netplwiz.exe C:\Windows\system32\Netplwiz.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\SbH2\Netplwiz.exe C:\Users\user\AppData\Local\SbH2\Netplwiz.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\recdisc.exe C:\Windows\system32\recdisc.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\r4gbgdji\recdisc.exe C:\Users\user\AppData\Local\r4gbgdji\recdisc.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\phoneactivate.exe C:\Windows\system32\phoneactivate.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe C:\Users\user\AppData\Local\lW7exk8\phoneactivate.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\wermgr.exe C:\Windows\system32\wermgr.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\JaJWNKcB\wermgr.exe C:\Users\user\AppData\Local\JaJWNKcB\wermgr.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\wermgr.exe C:\Windows\system32\wermgr.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\02vERQ6Eo\wermgr.exe C:\Users\user\AppData\Local\02vERQ6Eo\wermgr.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\rdpinput.exe C:\Windows\system32\rdpinput.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Local\iBq\rdpinput.exe C:\Users\user\AppData\Local\iBq\rdpinput.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: unknown unknown |
Jump to behavior |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .qkm |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .cvjb |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .tlmkv |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .wucsxe |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .fltwtj |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .tblq |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .hcmjm |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .nagyk |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .jrucz |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .rnr |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .ths |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .uuy |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .llcgmp |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .zibji |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .nnbdme |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .oxoht |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .poofxn |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .yoxffm |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .lbp |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .cmyjh |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .khlpd |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .ksydf |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .jtgc |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .ivi |
Source: yPeVDkBY3n.dll |
Static PE information: section name: .sqcys |
Source: phoneactivate.exe.6.dr |
Static PE information: section name: .imrsiv |
Source: wermgr.exe.6.dr |
Static PE information: section name: .imrsiv |
Source: wermgr.exe.6.dr |
Static PE information: section name: .didat |
Source: wermgr.exe0.6.dr |
Static PE information: section name: .imrsiv |
Source: wermgr.exe0.6.dr |
Static PE information: section name: .didat |
Source: WMPDMC.exe.6.dr |
Static PE information: section name: .didat |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .qkm |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .cvjb |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .tlmkv |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .wucsxe |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .fltwtj |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .tblq |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .hcmjm |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .nagyk |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .jrucz |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .rnr |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .ths |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .uuy |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .llcgmp |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .zibji |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .nnbdme |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .oxoht |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .poofxn |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .yoxffm |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .lbp |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .cmyjh |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .khlpd |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .ksydf |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .jtgc |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .ivi |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .sqcys |
Source: NETPLWIZ.dll.6.dr |
Static PE information: section name: .pyswvk |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .qkm |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .cvjb |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .tlmkv |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .wucsxe |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .fltwtj |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .tblq |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .hcmjm |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .nagyk |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .jrucz |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .rnr |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .ths |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .uuy |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .llcgmp |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .zibji |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .nnbdme |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .oxoht |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .poofxn |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .yoxffm |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .lbp |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .cmyjh |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .khlpd |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .ksydf |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .jtgc |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .ivi |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .sqcys |
Source: ReAgent.dll.6.dr |
Static PE information: section name: .xfh |
Source: DUI70.dll.6.dr |
Static PE information: section name: .qkm |
Source: DUI70.dll.6.dr |
Static PE information: section name: .cvjb |
Source: DUI70.dll.6.dr |
Static PE information: section name: .tlmkv |
Source: DUI70.dll.6.dr |
Static PE information: section name: .wucsxe |
Source: DUI70.dll.6.dr |
Static PE information: section name: .fltwtj |
Source: DUI70.dll.6.dr |
Static PE information: section name: .tblq |
Source: DUI70.dll.6.dr |
Static PE information: section name: .hcmjm |
Source: DUI70.dll.6.dr |
Static PE information: section name: .nagyk |
Source: DUI70.dll.6.dr |
Static PE information: section name: .jrucz |
Source: DUI70.dll.6.dr |
Static PE information: section name: .rnr |
Source: DUI70.dll.6.dr |
Static PE information: section name: .ths |
Source: DUI70.dll.6.dr |
Static PE information: section name: .uuy |
Source: DUI70.dll.6.dr |
Static PE information: section name: .llcgmp |
Source: DUI70.dll.6.dr |
Static PE information: section name: .zibji |
Source: DUI70.dll.6.dr |
Static PE information: section name: .nnbdme |
Source: DUI70.dll.6.dr |
Static PE information: section name: .oxoht |
Source: DUI70.dll.6.dr |
Static PE information: section name: .poofxn |
Source: DUI70.dll.6.dr |
Static PE information: section name: .yoxffm |
Source: DUI70.dll.6.dr |
Static PE information: section name: .lbp |
Source: DUI70.dll.6.dr |
Static PE information: section name: .cmyjh |
Source: DUI70.dll.6.dr |
Static PE information: section name: .khlpd |
Source: DUI70.dll.6.dr |
Static PE information: section name: .ksydf |
Source: DUI70.dll.6.dr |
Static PE information: section name: .jtgc |
Source: DUI70.dll.6.dr |
Static PE information: section name: .ivi |
Source: DUI70.dll.6.dr |
Static PE information: section name: .sqcys |
Source: DUI70.dll.6.dr |
Static PE information: section name: .grwy |
Source: wer.dll.6.dr |
Static PE information: section name: .qkm |
Source: wer.dll.6.dr |
Static PE information: section name: .cvjb |
Source: wer.dll.6.dr |
Static PE information: section name: .tlmkv |
Source: wer.dll.6.dr |
Static PE information: section name: .wucsxe |
Source: wer.dll.6.dr |
Static PE information: section name: .fltwtj |
Source: wer.dll.6.dr |
Static PE information: section name: .tblq |
Source: wer.dll.6.dr |
Static PE information: section name: .hcmjm |
Source: wer.dll.6.dr |
Static PE information: section name: .nagyk |
Source: wer.dll.6.dr |
Static PE information: section name: .jrucz |
Source: wer.dll.6.dr |
Static PE information: section name: .rnr |
Source: wer.dll.6.dr |
Static PE information: section name: .ths |
Source: wer.dll.6.dr |
Static PE information: section name: .uuy |
Source: wer.dll.6.dr |
Static PE information: section name: .llcgmp |
Source: wer.dll.6.dr |
Static PE information: section name: .zibji |
Source: wer.dll.6.dr |
Static PE information: section name: .nnbdme |
Source: wer.dll.6.dr |
Static PE information: section name: .oxoht |
Source: wer.dll.6.dr |
Static PE information: section name: .poofxn |
Source: wer.dll.6.dr |
Static PE information: section name: .yoxffm |
Source: wer.dll.6.dr |
Static PE information: section name: .lbp |
Source: wer.dll.6.dr |
Static PE information: section name: .cmyjh |
Source: wer.dll.6.dr |
Static PE information: section name: .khlpd |
Source: wer.dll.6.dr |
Static PE information: section name: .ksydf |
Source: wer.dll.6.dr |
Static PE information: section name: .jtgc |
Source: wer.dll.6.dr |
Static PE information: section name: .ivi |
Source: wer.dll.6.dr |
Static PE information: section name: .sqcys |
Source: wer.dll.6.dr |
Static PE information: section name: .qbg |
Source: wer.dll0.6.dr |
Static PE information: section name: .qkm |
Source: wer.dll0.6.dr |
Static PE information: section name: .cvjb |
Source: wer.dll0.6.dr |
Static PE information: section name: .tlmkv |
Source: wer.dll0.6.dr |
Static PE information: section name: .wucsxe |
Source: wer.dll0.6.dr |
Static PE information: section name: .fltwtj |
Source: wer.dll0.6.dr |
Static PE information: section name: .tblq |
Source: wer.dll0.6.dr |
Static PE information: section name: .hcmjm |
Source: wer.dll0.6.dr |
Static PE information: section name: .nagyk |
Source: wer.dll0.6.dr |
Static PE information: section name: .jrucz |
Source: wer.dll0.6.dr |
Static PE information: section name: .rnr |
Source: wer.dll0.6.dr |
Static PE information: section name: .ths |
Source: wer.dll0.6.dr |
Static PE information: section name: .uuy |
Source: wer.dll0.6.dr |
Static PE information: section name: .llcgmp |
Source: wer.dll0.6.dr |
Static PE information: section name: .zibji |
Source: wer.dll0.6.dr |
Static PE information: section name: .nnbdme |
Source: wer.dll0.6.dr |
Static PE information: section name: .oxoht |
Source: wer.dll0.6.dr |
Static PE information: section name: .poofxn |
Source: wer.dll0.6.dr |
Static PE information: section name: .yoxffm |
Source: wer.dll0.6.dr |
Static PE information: section name: .lbp |
Source: wer.dll0.6.dr |
Static PE information: section name: .cmyjh |
Source: wer.dll0.6.dr |
Static PE information: section name: .khlpd |
Source: wer.dll0.6.dr |
Static PE information: section name: .ksydf |
Source: wer.dll0.6.dr |
Static PE information: section name: .jtgc |
Source: wer.dll0.6.dr |
Static PE information: section name: .ivi |
Source: wer.dll0.6.dr |
Static PE information: section name: .sqcys |
Source: wer.dll0.6.dr |
Static PE information: section name: .kjh |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .qkm |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .cvjb |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .tlmkv |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .wucsxe |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .fltwtj |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .tblq |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .hcmjm |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .nagyk |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .jrucz |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .rnr |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .ths |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .uuy |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .llcgmp |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .zibji |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .nnbdme |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .oxoht |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .poofxn |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .yoxffm |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .lbp |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .cmyjh |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .khlpd |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .ksydf |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .jtgc |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .ivi |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .sqcys |
Source: WINSTA.dll.6.dr |
Static PE information: section name: .iwang |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .qkm |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .cvjb |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .tlmkv |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .wucsxe |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .fltwtj |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .tblq |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .hcmjm |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .nagyk |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .jrucz |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .rnr |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .ths |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .uuy |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .llcgmp |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .zibji |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .nnbdme |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .oxoht |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .poofxn |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .yoxffm |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .lbp |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .cmyjh |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .khlpd |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .ksydf |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .jtgc |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .ivi |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .sqcys |
Source: SYSDM.CPL.6.dr |
Static PE information: section name: .gkwrn |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .qkm |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .cvjb |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .tlmkv |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .wucsxe |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .fltwtj |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .tblq |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .hcmjm |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .nagyk |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .jrucz |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .rnr |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .ths |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .uuy |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .llcgmp |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .zibji |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .nnbdme |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .oxoht |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .poofxn |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .yoxffm |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .lbp |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .cmyjh |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .khlpd |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .ksydf |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .jtgc |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .ivi |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .sqcys |
Source: dwmapi.dll.6.dr |
Static PE information: section name: .hmami |
Source: wer.dll1.6.dr |
Static PE information: section name: .qkm |
Source: wer.dll1.6.dr |
Static PE information: section name: .cvjb |
Source: wer.dll1.6.dr |
Static PE information: section name: .tlmkv |
Source: wer.dll1.6.dr |
Static PE information: section name: .wucsxe |
Source: wer.dll1.6.dr |
Static PE information: section name: .fltwtj |
Source: wer.dll1.6.dr |
Static PE information: section name: .tblq |
Source: wer.dll1.6.dr |
Static PE information: section name: .hcmjm |
Source: wer.dll1.6.dr |
Static PE information: section name: .nagyk |
Source: wer.dll1.6.dr |
Static PE information: section name: .jrucz |
Source: wer.dll1.6.dr |
Static PE information: section name: .rnr |
Source: wer.dll1.6.dr |
Static PE information: section name: .ths |
Source: wer.dll1.6.dr |
Static PE information: section name: .uuy |
Source: wer.dll1.6.dr |
Static PE information: section name: .llcgmp |
Source: wer.dll1.6.dr |
Static PE information: section name: .zibji |
Source: wer.dll1.6.dr |
Static PE information: section name: .nnbdme |
Source: wer.dll1.6.dr |
Static PE information: section name: .oxoht |
Source: wer.dll1.6.dr |
Static PE information: section name: .poofxn |
Source: wer.dll1.6.dr |
Static PE information: section name: .yoxffm |
Source: wer.dll1.6.dr |
Static PE information: section name: .lbp |
Source: wer.dll1.6.dr |
Static PE information: section name: .cmyjh |
Source: wer.dll1.6.dr |
Static PE information: section name: .khlpd |
Source: wer.dll1.6.dr |
Static PE information: section name: .ksydf |
Source: wer.dll1.6.dr |
Static PE information: section name: .jtgc |
Source: wer.dll1.6.dr |
Static PE information: section name: .ivi |
Source: wer.dll1.6.dr |
Static PE information: section name: .sqcys |
Source: wer.dll1.6.dr |
Static PE information: section name: .uxnmn |