Source: 4.0.VJaX7U6LAp.exe.400000.6.unpack, type: UNPACKEDPE | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 4.0.VJaX7U6LAp.exe.400000.6.unpack, type: UNPACKEDPE | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 4.0.VJaX7U6LAp.exe.400000.8.unpack, type: UNPACKEDPE | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 4.0.VJaX7U6LAp.exe.400000.8.unpack, type: UNPACKEDPE | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 4.0.VJaX7U6LAp.exe.400000.6.raw.unpack, type: UNPACKEDPE | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 4.0.VJaX7U6LAp.exe.400000.6.raw.unpack, type: UNPACKEDPE | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 4.2.VJaX7U6LAp.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 4.2.VJaX7U6LAp.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 4.0.VJaX7U6LAp.exe.400000.8.raw.unpack, type: UNPACKEDPE | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 4.0.VJaX7U6LAp.exe.400000.8.raw.unpack, type: UNPACKEDPE | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 4.0.VJaX7U6LAp.exe.400000.4.unpack, type: UNPACKEDPE | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 4.0.VJaX7U6LAp.exe.400000.4.unpack, type: UNPACKEDPE | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 4.2.VJaX7U6LAp.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 4.2.VJaX7U6LAp.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 0.2.VJaX7U6LAp.exe.37d71e0.2.raw.unpack, type: UNPACKEDPE | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 0.2.VJaX7U6LAp.exe.37d71e0.2.raw.unpack, type: UNPACKEDPE | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 0.2.VJaX7U6LAp.exe.37887c0.3.raw.unpack, type: UNPACKEDPE | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 0.2.VJaX7U6LAp.exe.37887c0.3.raw.unpack, type: UNPACKEDPE | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 00000004.00000000.359814087.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 00000004.00000000.359814087.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 00000004.00000000.359438927.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 00000004.00000000.359438927.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 00000006.00000000.392844589.000000000763B000.00000040.00020000.sdmp, type: MEMORY | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 00000006.00000000.392844589.000000000763B000.00000040.00020000.sdmp, type: MEMORY | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 0000000B.00000002.620322575.0000000000990000.00000040.00020000.sdmp, type: MEMORY | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 0000000B.00000002.620322575.0000000000990000.00000040.00020000.sdmp, type: MEMORY | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 00000000.00000002.362891212.0000000003659000.00000004.00000001.sdmp, type: MEMORY | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 00000000.00000002.362891212.0000000003659000.00000004.00000001.sdmp, type: MEMORY | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 0000000B.00000002.620433344.00000000009C0000.00000004.00000001.sdmp, type: MEMORY | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 0000000B.00000002.620433344.00000000009C0000.00000004.00000001.sdmp, type: MEMORY | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 00000004.00000002.428718419.00000000018A0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 00000004.00000002.428718419.00000000018A0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 00000004.00000002.428663450.0000000001870000.00000040.00020000.sdmp, type: MEMORY | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 00000004.00000002.428663450.0000000001870000.00000040.00020000.sdmp, type: MEMORY | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 0000000B.00000002.619605094.0000000000480000.00000040.00020000.sdmp, type: MEMORY | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 0000000B.00000002.619605094.0000000000480000.00000040.00020000.sdmp, type: MEMORY | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 00000006.00000000.407150774.000000000763B000.00000040.00020000.sdmp, type: MEMORY | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 00000006.00000000.407150774.000000000763B000.00000040.00020000.sdmp, type: MEMORY | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 00000004.00000002.424469063.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 00000004.00000002.424469063.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 4.0.VJaX7U6LAp.exe.400000.6.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 4.0.VJaX7U6LAp.exe.400000.6.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 4.0.VJaX7U6LAp.exe.400000.8.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 4.0.VJaX7U6LAp.exe.400000.8.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 4.0.VJaX7U6LAp.exe.400000.6.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 4.0.VJaX7U6LAp.exe.400000.6.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 4.2.VJaX7U6LAp.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 4.2.VJaX7U6LAp.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 4.0.VJaX7U6LAp.exe.400000.8.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 4.0.VJaX7U6LAp.exe.400000.8.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 4.0.VJaX7U6LAp.exe.400000.4.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 4.0.VJaX7U6LAp.exe.400000.4.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 4.2.VJaX7U6LAp.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 4.2.VJaX7U6LAp.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0.2.VJaX7U6LAp.exe.37d71e0.2.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0.2.VJaX7U6LAp.exe.37d71e0.2.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0.2.VJaX7U6LAp.exe.37887c0.3.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0.2.VJaX7U6LAp.exe.37887c0.3.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000004.00000000.359814087.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000004.00000000.359814087.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000004.00000000.359438927.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000004.00000000.359438927.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000006.00000000.392844589.000000000763B000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000006.00000000.392844589.000000000763B000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000B.00000002.620322575.0000000000990000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000B.00000002.620322575.0000000000990000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000000.00000002.362891212.0000000003659000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000000.00000002.362891212.0000000003659000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000B.00000002.620433344.00000000009C0000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000B.00000002.620433344.00000000009C0000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000004.00000002.428718419.00000000018A0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000004.00000002.428718419.00000000018A0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000004.00000002.428663450.0000000001870000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000004.00000002.428663450.0000000001870000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000B.00000002.619605094.0000000000480000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000B.00000002.619605094.0000000000480000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000006.00000000.407150774.000000000763B000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000006.00000000.407150774.000000000763B000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000004.00000002.424469063.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000004.00000002.424469063.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: C:\Users\user\Desktop\VJaX7U6LAp.exe | Code function: 4_2_00419D50 NtCreateFile, | 4_2_00419D50 |
Source: C:\Users\user\Desktop\VJaX7U6LAp.exe | Code function: 4_2_00419E00 NtReadFile, | 4_2_00419E00 |
Source: C:\Users\user\Desktop\VJaX7U6LAp.exe | Code function: 4_2_00419E80 NtClose, | 4_2_00419E80 |
Source: C:\Users\user\Desktop\VJaX7U6LAp.exe | Code function: 4_2_00419F30 NtAllocateVirtualMemory, | 4_2_00419F30 |
Source: C:\Users\user\Desktop\VJaX7U6LAp.exe | Code function: 4_2_00419D4B NtCreateFile, | 4_2_00419D4B |
Source: C:\Users\user\Desktop\VJaX7U6LAp.exe | Code function: 4_2_00419E7A NtClose, | 4_2_00419E7A |
Source: C:\Users\user\Desktop\VJaX7U6LAp.exe | Code function: 4_2_00419F2D NtAllocateVirtualMemory, | 4_2_00419F2D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39A50 NtCreateFile,LdrInitializeThunk, | 11_2_02B39A50 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39860 NtQuerySystemInformation,LdrInitializeThunk, | 11_2_02B39860 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39840 NtDelayExecution,LdrInitializeThunk, | 11_2_02B39840 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B399A0 NtCreateSection,LdrInitializeThunk, | 11_2_02B399A0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39910 NtAdjustPrivilegesToken,LdrInitializeThunk, | 11_2_02B39910 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B396E0 NtFreeVirtualMemory,LdrInitializeThunk, | 11_2_02B396E0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B396D0 NtCreateKey,LdrInitializeThunk, | 11_2_02B396D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39660 NtAllocateVirtualMemory,LdrInitializeThunk, | 11_2_02B39660 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39650 NtQueryValueKey,LdrInitializeThunk, | 11_2_02B39650 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39780 NtMapViewOfSection,LdrInitializeThunk, | 11_2_02B39780 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39FE0 NtCreateMutant,LdrInitializeThunk, | 11_2_02B39FE0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39710 NtQueryInformationToken,LdrInitializeThunk, | 11_2_02B39710 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B395D0 NtClose,LdrInitializeThunk, | 11_2_02B395D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39540 NtReadFile,LdrInitializeThunk, | 11_2_02B39540 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39A80 NtOpenDirectoryObject, | 11_2_02B39A80 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39A20 NtResumeThread, | 11_2_02B39A20 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39A10 NtQuerySection, | 11_2_02B39A10 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39A00 NtProtectVirtualMemory, | 11_2_02B39A00 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B3A3B0 NtGetContextThread, | 11_2_02B3A3B0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39B00 NtSetValueKey, | 11_2_02B39B00 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B398A0 NtWriteVirtualMemory, | 11_2_02B398A0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B398F0 NtReadVirtualMemory, | 11_2_02B398F0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39820 NtEnumerateKey, | 11_2_02B39820 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B3B040 NtSuspendThread, | 11_2_02B3B040 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B399D0 NtCreateProcessEx, | 11_2_02B399D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39950 NtQueueApcThread, | 11_2_02B39950 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39610 NtEnumerateValueKey, | 11_2_02B39610 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39670 NtQueryInformationProcess, | 11_2_02B39670 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B397A0 NtUnmapViewOfSection, | 11_2_02B397A0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39730 NtQueryVirtualMemory, | 11_2_02B39730 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B3A710 NtOpenProcessToken, | 11_2_02B3A710 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B3A770 NtOpenThread, | 11_2_02B3A770 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39770 NtSetInformationFile, | 11_2_02B39770 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39760 NtOpenProcess, | 11_2_02B39760 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B395F0 NtQueryInformationFile, | 11_2_02B395F0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B3AD30 NtSetContextThread, | 11_2_02B3AD30 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39520 NtWaitForSingleObject, | 11_2_02B39520 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B39560 NtWriteFile, | 11_2_02B39560 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_00499D50 NtCreateFile, | 11_2_00499D50 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_00499E00 NtReadFile, | 11_2_00499E00 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_00499E80 NtClose, | 11_2_00499E80 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_00499F30 NtAllocateVirtualMemory, | 11_2_00499F30 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_00499D4B NtCreateFile, | 11_2_00499D4B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_00499E7A NtClose, | 11_2_00499E7A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_00499F2D NtAllocateVirtualMemory, | 11_2_00499F2D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B0AAB0 mov eax, dword ptr fs:[00000030h] | 11_2_02B0AAB0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B0AAB0 mov eax, dword ptr fs:[00000030h] | 11_2_02B0AAB0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2FAB0 mov eax, dword ptr fs:[00000030h] | 11_2_02B2FAB0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF52A5 mov eax, dword ptr fs:[00000030h] | 11_2_02AF52A5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF52A5 mov eax, dword ptr fs:[00000030h] | 11_2_02AF52A5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF52A5 mov eax, dword ptr fs:[00000030h] | 11_2_02AF52A5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF52A5 mov eax, dword ptr fs:[00000030h] | 11_2_02AF52A5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF52A5 mov eax, dword ptr fs:[00000030h] | 11_2_02AF52A5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2D294 mov eax, dword ptr fs:[00000030h] | 11_2_02B2D294 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2D294 mov eax, dword ptr fs:[00000030h] | 11_2_02B2D294 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B22AE4 mov eax, dword ptr fs:[00000030h] | 11_2_02B22AE4 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B22ACB mov eax, dword ptr fs:[00000030h] | 11_2_02B22ACB |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B34A2C mov eax, dword ptr fs:[00000030h] | 11_2_02B34A2C |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B34A2C mov eax, dword ptr fs:[00000030h] | 11_2_02B34A2C |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B13A1C mov eax, dword ptr fs:[00000030h] | 11_2_02B13A1C |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BBAA16 mov eax, dword ptr fs:[00000030h] | 11_2_02BBAA16 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BBAA16 mov eax, dword ptr fs:[00000030h] | 11_2_02BBAA16 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AFAA16 mov eax, dword ptr fs:[00000030h] | 11_2_02AFAA16 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AFAA16 mov eax, dword ptr fs:[00000030h] | 11_2_02AFAA16 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B08A0A mov eax, dword ptr fs:[00000030h] | 11_2_02B08A0A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF5210 mov eax, dword ptr fs:[00000030h] | 11_2_02AF5210 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF5210 mov ecx, dword ptr fs:[00000030h] | 11_2_02AF5210 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF5210 mov eax, dword ptr fs:[00000030h] | 11_2_02AF5210 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF5210 mov eax, dword ptr fs:[00000030h] | 11_2_02AF5210 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B3927A mov eax, dword ptr fs:[00000030h] | 11_2_02B3927A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BAB260 mov eax, dword ptr fs:[00000030h] | 11_2_02BAB260 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BAB260 mov eax, dword ptr fs:[00000030h] | 11_2_02BAB260 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC8A62 mov eax, dword ptr fs:[00000030h] | 11_2_02BC8A62 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BBEA55 mov eax, dword ptr fs:[00000030h] | 11_2_02BBEA55 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF9240 mov eax, dword ptr fs:[00000030h] | 11_2_02AF9240 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF9240 mov eax, dword ptr fs:[00000030h] | 11_2_02AF9240 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF9240 mov eax, dword ptr fs:[00000030h] | 11_2_02AF9240 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF9240 mov eax, dword ptr fs:[00000030h] | 11_2_02AF9240 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B84257 mov eax, dword ptr fs:[00000030h] | 11_2_02B84257 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC5BA5 mov eax, dword ptr fs:[00000030h] | 11_2_02BC5BA5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B24BAD mov eax, dword ptr fs:[00000030h] | 11_2_02B24BAD |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B24BAD mov eax, dword ptr fs:[00000030h] | 11_2_02B24BAD |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B24BAD mov eax, dword ptr fs:[00000030h] | 11_2_02B24BAD |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2B390 mov eax, dword ptr fs:[00000030h] | 11_2_02B2B390 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B22397 mov eax, dword ptr fs:[00000030h] | 11_2_02B22397 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB138A mov eax, dword ptr fs:[00000030h] | 11_2_02BB138A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BAD380 mov ecx, dword ptr fs:[00000030h] | 11_2_02BAD380 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B01B8F mov eax, dword ptr fs:[00000030h] | 11_2_02B01B8F |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B01B8F mov eax, dword ptr fs:[00000030h] | 11_2_02B01B8F |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B203E2 mov eax, dword ptr fs:[00000030h] | 11_2_02B203E2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B203E2 mov eax, dword ptr fs:[00000030h] | 11_2_02B203E2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B203E2 mov eax, dword ptr fs:[00000030h] | 11_2_02B203E2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B203E2 mov eax, dword ptr fs:[00000030h] | 11_2_02B203E2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B203E2 mov eax, dword ptr fs:[00000030h] | 11_2_02B203E2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B203E2 mov eax, dword ptr fs:[00000030h] | 11_2_02B203E2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B1DBE9 mov eax, dword ptr fs:[00000030h] | 11_2_02B1DBE9 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B753CA mov eax, dword ptr fs:[00000030h] | 11_2_02B753CA |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B753CA mov eax, dword ptr fs:[00000030h] | 11_2_02B753CA |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB131B mov eax, dword ptr fs:[00000030h] | 11_2_02BB131B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B23B7A mov eax, dword ptr fs:[00000030h] | 11_2_02B23B7A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B23B7A mov eax, dword ptr fs:[00000030h] | 11_2_02B23B7A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AFDB60 mov ecx, dword ptr fs:[00000030h] | 11_2_02AFDB60 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC8B58 mov eax, dword ptr fs:[00000030h] | 11_2_02BC8B58 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AFDB40 mov eax, dword ptr fs:[00000030h] | 11_2_02AFDB40 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AFF358 mov eax, dword ptr fs:[00000030h] | 11_2_02AFF358 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2F0BF mov ecx, dword ptr fs:[00000030h] | 11_2_02B2F0BF |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2F0BF mov eax, dword ptr fs:[00000030h] | 11_2_02B2F0BF |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2F0BF mov eax, dword ptr fs:[00000030h] | 11_2_02B2F0BF |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B220A0 mov eax, dword ptr fs:[00000030h] | 11_2_02B220A0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B220A0 mov eax, dword ptr fs:[00000030h] | 11_2_02B220A0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B220A0 mov eax, dword ptr fs:[00000030h] | 11_2_02B220A0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B220A0 mov eax, dword ptr fs:[00000030h] | 11_2_02B220A0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B220A0 mov eax, dword ptr fs:[00000030h] | 11_2_02B220A0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B220A0 mov eax, dword ptr fs:[00000030h] | 11_2_02B220A0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B390AF mov eax, dword ptr fs:[00000030h] | 11_2_02B390AF |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF9080 mov eax, dword ptr fs:[00000030h] | 11_2_02AF9080 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B73884 mov eax, dword ptr fs:[00000030h] | 11_2_02B73884 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B73884 mov eax, dword ptr fs:[00000030h] | 11_2_02B73884 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF58EC mov eax, dword ptr fs:[00000030h] | 11_2_02AF58EC |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF40E1 mov eax, dword ptr fs:[00000030h] | 11_2_02AF40E1 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF40E1 mov eax, dword ptr fs:[00000030h] | 11_2_02AF40E1 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF40E1 mov eax, dword ptr fs:[00000030h] | 11_2_02AF40E1 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B8B8D0 mov eax, dword ptr fs:[00000030h] | 11_2_02B8B8D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B8B8D0 mov ecx, dword ptr fs:[00000030h] | 11_2_02B8B8D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B8B8D0 mov eax, dword ptr fs:[00000030h] | 11_2_02B8B8D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B8B8D0 mov eax, dword ptr fs:[00000030h] | 11_2_02B8B8D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B8B8D0 mov eax, dword ptr fs:[00000030h] | 11_2_02B8B8D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B8B8D0 mov eax, dword ptr fs:[00000030h] | 11_2_02B8B8D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B0B02A mov eax, dword ptr fs:[00000030h] | 11_2_02B0B02A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B0B02A mov eax, dword ptr fs:[00000030h] | 11_2_02B0B02A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B0B02A mov eax, dword ptr fs:[00000030h] | 11_2_02B0B02A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B0B02A mov eax, dword ptr fs:[00000030h] | 11_2_02B0B02A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2002D mov eax, dword ptr fs:[00000030h] | 11_2_02B2002D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2002D mov eax, dword ptr fs:[00000030h] | 11_2_02B2002D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2002D mov eax, dword ptr fs:[00000030h] | 11_2_02B2002D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2002D mov eax, dword ptr fs:[00000030h] | 11_2_02B2002D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2002D mov eax, dword ptr fs:[00000030h] | 11_2_02B2002D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B77016 mov eax, dword ptr fs:[00000030h] | 11_2_02B77016 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B77016 mov eax, dword ptr fs:[00000030h] | 11_2_02B77016 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B77016 mov eax, dword ptr fs:[00000030h] | 11_2_02B77016 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC4015 mov eax, dword ptr fs:[00000030h] | 11_2_02BC4015 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC4015 mov eax, dword ptr fs:[00000030h] | 11_2_02BC4015 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB2073 mov eax, dword ptr fs:[00000030h] | 11_2_02BB2073 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC1074 mov eax, dword ptr fs:[00000030h] | 11_2_02BC1074 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B10050 mov eax, dword ptr fs:[00000030h] | 11_2_02B10050 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B10050 mov eax, dword ptr fs:[00000030h] | 11_2_02B10050 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B751BE mov eax, dword ptr fs:[00000030h] | 11_2_02B751BE |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B751BE mov eax, dword ptr fs:[00000030h] | 11_2_02B751BE |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B751BE mov eax, dword ptr fs:[00000030h] | 11_2_02B751BE |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B751BE mov eax, dword ptr fs:[00000030h] | 11_2_02B751BE |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B769A6 mov eax, dword ptr fs:[00000030h] | 11_2_02B769A6 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B261A0 mov eax, dword ptr fs:[00000030h] | 11_2_02B261A0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B261A0 mov eax, dword ptr fs:[00000030h] | 11_2_02B261A0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB49A4 mov eax, dword ptr fs:[00000030h] | 11_2_02BB49A4 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB49A4 mov eax, dword ptr fs:[00000030h] | 11_2_02BB49A4 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB49A4 mov eax, dword ptr fs:[00000030h] | 11_2_02BB49A4 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB49A4 mov eax, dword ptr fs:[00000030h] | 11_2_02BB49A4 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B22990 mov eax, dword ptr fs:[00000030h] | 11_2_02B22990 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B1C182 mov eax, dword ptr fs:[00000030h] | 11_2_02B1C182 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2A185 mov eax, dword ptr fs:[00000030h] | 11_2_02B2A185 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AFB1E1 mov eax, dword ptr fs:[00000030h] | 11_2_02AFB1E1 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AFB1E1 mov eax, dword ptr fs:[00000030h] | 11_2_02AFB1E1 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AFB1E1 mov eax, dword ptr fs:[00000030h] | 11_2_02AFB1E1 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B841E8 mov eax, dword ptr fs:[00000030h] | 11_2_02B841E8 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2513A mov eax, dword ptr fs:[00000030h] | 11_2_02B2513A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2513A mov eax, dword ptr fs:[00000030h] | 11_2_02B2513A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B14120 mov eax, dword ptr fs:[00000030h] | 11_2_02B14120 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B14120 mov eax, dword ptr fs:[00000030h] | 11_2_02B14120 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B14120 mov eax, dword ptr fs:[00000030h] | 11_2_02B14120 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B14120 mov eax, dword ptr fs:[00000030h] | 11_2_02B14120 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B14120 mov ecx, dword ptr fs:[00000030h] | 11_2_02B14120 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF9100 mov eax, dword ptr fs:[00000030h] | 11_2_02AF9100 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF9100 mov eax, dword ptr fs:[00000030h] | 11_2_02AF9100 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF9100 mov eax, dword ptr fs:[00000030h] | 11_2_02AF9100 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AFC962 mov eax, dword ptr fs:[00000030h] | 11_2_02AFC962 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AFB171 mov eax, dword ptr fs:[00000030h] | 11_2_02AFB171 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AFB171 mov eax, dword ptr fs:[00000030h] | 11_2_02AFB171 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B1B944 mov eax, dword ptr fs:[00000030h] | 11_2_02B1B944 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B1B944 mov eax, dword ptr fs:[00000030h] | 11_2_02B1B944 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B746A7 mov eax, dword ptr fs:[00000030h] | 11_2_02B746A7 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC0EA5 mov eax, dword ptr fs:[00000030h] | 11_2_02BC0EA5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC0EA5 mov eax, dword ptr fs:[00000030h] | 11_2_02BC0EA5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC0EA5 mov eax, dword ptr fs:[00000030h] | 11_2_02BC0EA5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B8FE87 mov eax, dword ptr fs:[00000030h] | 11_2_02B8FE87 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B216E0 mov ecx, dword ptr fs:[00000030h] | 11_2_02B216E0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B076E2 mov eax, dword ptr fs:[00000030h] | 11_2_02B076E2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC8ED6 mov eax, dword ptr fs:[00000030h] | 11_2_02BC8ED6 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B38EC7 mov eax, dword ptr fs:[00000030h] | 11_2_02B38EC7 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BAFEC0 mov eax, dword ptr fs:[00000030h] | 11_2_02BAFEC0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B236CC mov eax, dword ptr fs:[00000030h] | 11_2_02B236CC |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BAFE3F mov eax, dword ptr fs:[00000030h] | 11_2_02BAFE3F |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AFE620 mov eax, dword ptr fs:[00000030h] | 11_2_02AFE620 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2A61C mov eax, dword ptr fs:[00000030h] | 11_2_02B2A61C |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2A61C mov eax, dword ptr fs:[00000030h] | 11_2_02B2A61C |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AFC600 mov eax, dword ptr fs:[00000030h] | 11_2_02AFC600 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AFC600 mov eax, dword ptr fs:[00000030h] | 11_2_02AFC600 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AFC600 mov eax, dword ptr fs:[00000030h] | 11_2_02AFC600 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B28E00 mov eax, dword ptr fs:[00000030h] | 11_2_02B28E00 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB1608 mov eax, dword ptr fs:[00000030h] | 11_2_02BB1608 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B1AE73 mov eax, dword ptr fs:[00000030h] | 11_2_02B1AE73 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B1AE73 mov eax, dword ptr fs:[00000030h] | 11_2_02B1AE73 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B1AE73 mov eax, dword ptr fs:[00000030h] | 11_2_02B1AE73 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B1AE73 mov eax, dword ptr fs:[00000030h] | 11_2_02B1AE73 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B1AE73 mov eax, dword ptr fs:[00000030h] | 11_2_02B1AE73 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B0766D mov eax, dword ptr fs:[00000030h] | 11_2_02B0766D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B07E41 mov eax, dword ptr fs:[00000030h] | 11_2_02B07E41 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B07E41 mov eax, dword ptr fs:[00000030h] | 11_2_02B07E41 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B07E41 mov eax, dword ptr fs:[00000030h] | 11_2_02B07E41 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B07E41 mov eax, dword ptr fs:[00000030h] | 11_2_02B07E41 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B07E41 mov eax, dword ptr fs:[00000030h] | 11_2_02B07E41 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B07E41 mov eax, dword ptr fs:[00000030h] | 11_2_02B07E41 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BBAE44 mov eax, dword ptr fs:[00000030h] | 11_2_02BBAE44 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BBAE44 mov eax, dword ptr fs:[00000030h] | 11_2_02BBAE44 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B77794 mov eax, dword ptr fs:[00000030h] | 11_2_02B77794 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B77794 mov eax, dword ptr fs:[00000030h] | 11_2_02B77794 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B77794 mov eax, dword ptr fs:[00000030h] | 11_2_02B77794 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B08794 mov eax, dword ptr fs:[00000030h] | 11_2_02B08794 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B337F5 mov eax, dword ptr fs:[00000030h] | 11_2_02B337F5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF4F2E mov eax, dword ptr fs:[00000030h] | 11_2_02AF4F2E |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF4F2E mov eax, dword ptr fs:[00000030h] | 11_2_02AF4F2E |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2E730 mov eax, dword ptr fs:[00000030h] | 11_2_02B2E730 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B1F716 mov eax, dword ptr fs:[00000030h] | 11_2_02B1F716 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B8FF10 mov eax, dword ptr fs:[00000030h] | 11_2_02B8FF10 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B8FF10 mov eax, dword ptr fs:[00000030h] | 11_2_02B8FF10 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC070D mov eax, dword ptr fs:[00000030h] | 11_2_02BC070D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC070D mov eax, dword ptr fs:[00000030h] | 11_2_02BC070D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2A70E mov eax, dword ptr fs:[00000030h] | 11_2_02B2A70E |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2A70E mov eax, dword ptr fs:[00000030h] | 11_2_02B2A70E |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B0FF60 mov eax, dword ptr fs:[00000030h] | 11_2_02B0FF60 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC8F6A mov eax, dword ptr fs:[00000030h] | 11_2_02BC8F6A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B0EF40 mov eax, dword ptr fs:[00000030h] | 11_2_02B0EF40 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B0849B mov eax, dword ptr fs:[00000030h] | 11_2_02B0849B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB14FB mov eax, dword ptr fs:[00000030h] | 11_2_02BB14FB |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B76CF0 mov eax, dword ptr fs:[00000030h] | 11_2_02B76CF0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B76CF0 mov eax, dword ptr fs:[00000030h] | 11_2_02B76CF0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B76CF0 mov eax, dword ptr fs:[00000030h] | 11_2_02B76CF0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC8CD6 mov eax, dword ptr fs:[00000030h] | 11_2_02BC8CD6 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2BC2C mov eax, dword ptr fs:[00000030h] | 11_2_02B2BC2C |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC740D mov eax, dword ptr fs:[00000030h] | 11_2_02BC740D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC740D mov eax, dword ptr fs:[00000030h] | 11_2_02BC740D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC740D mov eax, dword ptr fs:[00000030h] | 11_2_02BC740D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB1C06 mov eax, dword ptr fs:[00000030h] | 11_2_02BB1C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB1C06 mov eax, dword ptr fs:[00000030h] | 11_2_02BB1C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB1C06 mov eax, dword ptr fs:[00000030h] | 11_2_02BB1C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB1C06 mov eax, dword ptr fs:[00000030h] | 11_2_02BB1C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB1C06 mov eax, dword ptr fs:[00000030h] | 11_2_02BB1C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB1C06 mov eax, dword ptr fs:[00000030h] | 11_2_02BB1C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB1C06 mov eax, dword ptr fs:[00000030h] | 11_2_02BB1C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB1C06 mov eax, dword ptr fs:[00000030h] | 11_2_02BB1C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB1C06 mov eax, dword ptr fs:[00000030h] | 11_2_02BB1C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB1C06 mov eax, dword ptr fs:[00000030h] | 11_2_02BB1C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB1C06 mov eax, dword ptr fs:[00000030h] | 11_2_02BB1C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB1C06 mov eax, dword ptr fs:[00000030h] | 11_2_02BB1C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB1C06 mov eax, dword ptr fs:[00000030h] | 11_2_02BB1C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BB1C06 mov eax, dword ptr fs:[00000030h] | 11_2_02BB1C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B76C0A mov eax, dword ptr fs:[00000030h] | 11_2_02B76C0A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B76C0A mov eax, dword ptr fs:[00000030h] | 11_2_02B76C0A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B76C0A mov eax, dword ptr fs:[00000030h] | 11_2_02B76C0A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B76C0A mov eax, dword ptr fs:[00000030h] | 11_2_02B76C0A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B1746D mov eax, dword ptr fs:[00000030h] | 11_2_02B1746D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B8C450 mov eax, dword ptr fs:[00000030h] | 11_2_02B8C450 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B8C450 mov eax, dword ptr fs:[00000030h] | 11_2_02B8C450 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2A44B mov eax, dword ptr fs:[00000030h] | 11_2_02B2A44B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B21DB5 mov eax, dword ptr fs:[00000030h] | 11_2_02B21DB5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B21DB5 mov eax, dword ptr fs:[00000030h] | 11_2_02B21DB5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B21DB5 mov eax, dword ptr fs:[00000030h] | 11_2_02B21DB5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC05AC mov eax, dword ptr fs:[00000030h] | 11_2_02BC05AC |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC05AC mov eax, dword ptr fs:[00000030h] | 11_2_02BC05AC |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B235A1 mov eax, dword ptr fs:[00000030h] | 11_2_02B235A1 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF2D8A mov eax, dword ptr fs:[00000030h] | 11_2_02AF2D8A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF2D8A mov eax, dword ptr fs:[00000030h] | 11_2_02AF2D8A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF2D8A mov eax, dword ptr fs:[00000030h] | 11_2_02AF2D8A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF2D8A mov eax, dword ptr fs:[00000030h] | 11_2_02AF2D8A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AF2D8A mov eax, dword ptr fs:[00000030h] | 11_2_02AF2D8A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2FD9B mov eax, dword ptr fs:[00000030h] | 11_2_02B2FD9B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B2FD9B mov eax, dword ptr fs:[00000030h] | 11_2_02B2FD9B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B22581 mov eax, dword ptr fs:[00000030h] | 11_2_02B22581 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B22581 mov eax, dword ptr fs:[00000030h] | 11_2_02B22581 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B22581 mov eax, dword ptr fs:[00000030h] | 11_2_02B22581 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B22581 mov eax, dword ptr fs:[00000030h] | 11_2_02B22581 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BA8DF1 mov eax, dword ptr fs:[00000030h] | 11_2_02BA8DF1 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B0D5E0 mov eax, dword ptr fs:[00000030h] | 11_2_02B0D5E0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B0D5E0 mov eax, dword ptr fs:[00000030h] | 11_2_02B0D5E0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BBFDE2 mov eax, dword ptr fs:[00000030h] | 11_2_02BBFDE2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BBFDE2 mov eax, dword ptr fs:[00000030h] | 11_2_02BBFDE2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BBFDE2 mov eax, dword ptr fs:[00000030h] | 11_2_02BBFDE2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BBFDE2 mov eax, dword ptr fs:[00000030h] | 11_2_02BBFDE2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B76DC9 mov eax, dword ptr fs:[00000030h] | 11_2_02B76DC9 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B76DC9 mov eax, dword ptr fs:[00000030h] | 11_2_02B76DC9 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B76DC9 mov eax, dword ptr fs:[00000030h] | 11_2_02B76DC9 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B76DC9 mov ecx, dword ptr fs:[00000030h] | 11_2_02B76DC9 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B76DC9 mov eax, dword ptr fs:[00000030h] | 11_2_02B76DC9 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B76DC9 mov eax, dword ptr fs:[00000030h] | 11_2_02B76DC9 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B7A537 mov eax, dword ptr fs:[00000030h] | 11_2_02B7A537 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BBE539 mov eax, dword ptr fs:[00000030h] | 11_2_02BBE539 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B03D34 mov eax, dword ptr fs:[00000030h] | 11_2_02B03D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B03D34 mov eax, dword ptr fs:[00000030h] | 11_2_02B03D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B03D34 mov eax, dword ptr fs:[00000030h] | 11_2_02B03D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B03D34 mov eax, dword ptr fs:[00000030h] | 11_2_02B03D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B03D34 mov eax, dword ptr fs:[00000030h] | 11_2_02B03D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B03D34 mov eax, dword ptr fs:[00000030h] | 11_2_02B03D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B03D34 mov eax, dword ptr fs:[00000030h] | 11_2_02B03D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B03D34 mov eax, dword ptr fs:[00000030h] | 11_2_02B03D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B03D34 mov eax, dword ptr fs:[00000030h] | 11_2_02B03D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B03D34 mov eax, dword ptr fs:[00000030h] | 11_2_02B03D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B03D34 mov eax, dword ptr fs:[00000030h] | 11_2_02B03D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B03D34 mov eax, dword ptr fs:[00000030h] | 11_2_02B03D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B03D34 mov eax, dword ptr fs:[00000030h] | 11_2_02B03D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BC8D34 mov eax, dword ptr fs:[00000030h] | 11_2_02BC8D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B24D3B mov eax, dword ptr fs:[00000030h] | 11_2_02B24D3B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B24D3B mov eax, dword ptr fs:[00000030h] | 11_2_02B24D3B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B24D3B mov eax, dword ptr fs:[00000030h] | 11_2_02B24D3B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02AFAD30 mov eax, dword ptr fs:[00000030h] | 11_2_02AFAD30 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B1C577 mov eax, dword ptr fs:[00000030h] | 11_2_02B1C577 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B1C577 mov eax, dword ptr fs:[00000030h] | 11_2_02B1C577 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B17D50 mov eax, dword ptr fs:[00000030h] | 11_2_02B17D50 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B33D43 mov eax, dword ptr fs:[00000030h] | 11_2_02B33D43 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02B73540 mov eax, dword ptr fs:[00000030h] | 11_2_02B73540 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 11_2_02BA3D40 mov eax, dword ptr fs:[00000030h] | 11_2_02BA3D40 |