Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443F9D90 CryptReleaseContext,CryptAcquireContextW,GetLastError,CryptAcquireContextW,GetLastError, | 19_2_00007FF7443F9D90 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443E0D50 memset,CoInitialize,SysFreeString,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,SysStringByteLen,SysAllocStringByteLen,SysStringLen,towupper,SysStringLen,SysFreeString,SysAllocString,_time64,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,SysFreeString,SysAllocString,SysStringByteLen,GetProcessHeap,HeapAlloc,memcpy,CryptDecrypt,SysAllocStringByteLen,memset,memcpy,GetProcessHeap,HeapFree,PostMessageW,SysFreeString,SysFreeString,SysFreeString,SysFreeString,SysFreeString,SysFreeString,CoUninitialize, | 19_2_00007FF7443E0D50 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443E1DB4 GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CompareStringW,SysAllocString,SysAllocString,??_V@YAXPEAX@Z,CryptReleaseContext, | 19_2_00007FF7443E1DB4 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443F9E94 memset,SysStringLen,SysStringLen,SysStringLen,memcpy,CryptEncrypt,GetLastError, | 19_2_00007FF7443F9E94 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443FAE40 CryptGetUserKey,CryptExportKey,GetProcessHeap,HeapAlloc,CryptExportKey,CryptBinaryToStringW,GetProcessHeap,HeapAlloc,CryptBinaryToStringW,SysAllocString,CryptDestroyKey,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 19_2_00007FF7443FAE40 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF744406EDC CryptGenRandom, | 19_2_00007FF744406EDC |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF744406F74 CryptAcquireContextW,time,srand,CryptGenRandom,CryptGenRandom,CryptGenRandom,CryptGenRandom,CryptGenRandom,CryptReleaseContext, | 19_2_00007FF744406F74 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443E2808 memset,CoInitialize,CryptReleaseContext,SysFreeString,_wtoi,SysStringByteLen,SysFreeString,SysAllocStringByteLen,SysAllocStringByteLen,SysStringByteLen,GetProcessHeap,HeapAlloc,memcpy,CryptDecrypt,SysAllocStringByteLen,memset,memcpy,GetProcessHeap,HeapFree,SysFreeString,SysFreeString,SysFreeString,SysFreeString,SysFreeString,CoUninitialize, | 19_2_00007FF7443E2808 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443FA024 SysStringLen,SysStringLen,CryptEncrypt,GetLastError,memset,memcpy,CryptEncrypt,GetLastError,??_V@YAXPEAX@Z, | 19_2_00007FF7443FA024 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443FA8F4 CryptGetUserKey,CryptStringToBinaryW,GetProcessHeap,HeapAlloc,CryptStringToBinaryW,CryptImportKey,GetProcessHeap,HeapFree,CryptDestroyKey, | 19_2_00007FF7443FA8F4 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443E21F4 memset,SysAllocString,CryptEncrypt,memcpy,??_V@YAXPEAX@Z,memset,memcpy,??_V@YAXPEAX@Z,memcpy,CryptEncrypt,SysAllocStringByteLen,??_V@YAXPEAX@Z,??_V@YAXPEAX@Z,SysStringByteLen,SysStringByteLen,SysAllocStringByteLen,memcpy,memcpy,SysFreeString,SysFreeString,SysFreeString,SysFreeString,SysFreeString, | 19_2_00007FF7443E21F4 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443FA1C8 SysStringLen,SysStringLen,SysFreeString,SysAllocString,CryptDecrypt,SysAllocStringByteLen,memset,memcpy,free, | 19_2_00007FF7443FA1C8 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443F9AB0 CryptDestroyHash,CryptDestroyKey,CryptReleaseContext,CryptDestroyHash,CryptDestroyKey,CryptReleaseContext, | 19_2_00007FF7443F9AB0 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443FAAC4 CryptStringToBinaryW,GetProcessHeap,HeapAlloc,CryptStringToBinaryW,CryptImportKey,CryptDestroyKey,CryptGenKey,CryptExportKey,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,CryptExportKey,CryptBinaryToStringW,GetProcessHeap,HeapAlloc,CryptBinaryToStringW,SysAllocString,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,CryptDestroyKey, | 19_2_00007FF7443FAAC4 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443DBAC8 memset,#261,CreateFileW,GetLastError,GetLastError,GetFileSizeEx,GetProcessHeap,HeapAlloc,ReadFile,CryptBinaryToStringW,GetProcessHeap,HeapAlloc,CryptBinaryToStringW,GetProcessHeap,HeapAlloc,GetComputerNameW,GetProcessHeap,HeapAlloc,GetUserNameExW,GetUserNameW,SysAllocString,CloseHandle,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 19_2_00007FF7443DBAC8 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443F9B3C CryptReleaseContext,CryptAcquireContextW,GetLastError,CryptAcquireContextW,GetLastError, | 19_2_00007FF7443F9B3C |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443F9BCC CryptDestroyHash,CryptDestroyKey,CryptCreateHash,SysStringByteLen,CryptHashData,CryptDeriveKey,GetLastError, | 19_2_00007FF7443F9BCC |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443FA43C CryptGenRandom, | 19_2_00007FF7443FA43C |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443FA508 memset,memcpy,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,memcpy,CryptDestroyHash, | 19_2_00007FF7443FA508 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443F9CA4 CryptDestroyHash,CryptDestroyKey,CryptCreateHash,SysStringByteLen,CryptHashData,CryptDeriveKey,CryptSetKeyParam,GetLastError, | 19_2_00007FF7443F9CA4 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443E04C8 memset,memset,_time64,SysAllocString,SysFreeString,CryptEncrypt,memcpy,??_V@YAXPEAX@Z,memset,memcpy,??_V@YAXPEAX@Z,memcpy,CryptEncrypt,SysAllocStringByteLen,??_V@YAXPEAX@Z,??_V@YAXPEAX@Z,SysAllocString,SysFreeString,GetProcessHeap,HeapFree,SysFreeString,SysFreeString,SysFreeString,SysFreeString,SysFreeString, | 19_2_00007FF7443E04C8 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21F43E0 CryptImportKey,CryptSetKeyParam,CryptSetKeyParam,CryptGetKeyParam,CryptEncrypt,CryptDecrypt,GetLastError,CryptDestroyKey,GetProcessHeap,HeapFree, | 29_2_00007FF7F21F43E0 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21F84E4 CryptImportKey,GetLastError,CryptImportKey,CryptExportKey,GetProcessHeap,HeapAlloc,CryptExportKey,GetProcessHeap,HeapAlloc,memmove,GetProcessHeap,HeapFree,CryptDestroyKey,CryptDestroyKey,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,CryptReleaseContext, | 29_2_00007FF7F21F84E4 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21FA198 CryptExportKey,GetLastError,GetProcessHeap,HeapAlloc,CryptExportKey,GetProcessHeap,HeapFree,CryptDestroyKey, | 29_2_00007FF7F21FA198 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21F82F0 CryptGenKey,GetLastError,CryptDestroyKey,GetProcessHeap,HeapAlloc,CryptDestroyKey,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 29_2_00007FF7F21F82F0 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21F87EC UuidCreate,UuidToStringW,CryptAcquireContextW,GetLastError,GetProcessHeap,HeapFree,RpcStringFreeW, | 29_2_00007FF7F21F87EC |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21FAC28 CryptGetUserKey,GetLastError,CryptDestroyKey, | 29_2_00007FF7F21FAC28 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21F998C GetProcessHeap,HeapFree,CryptReleaseContext,GetProcessHeap,HeapFree, | 29_2_00007FF7F21F998C |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21F9A24 CryptExportKey,GetLastError,GetProcessHeap,HeapAlloc,CryptExportKey,GetProcessHeap,HeapFree,CryptDestroyKey, | 29_2_00007FF7F21F9A24 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21F4064 GetProcessHeap,HeapAlloc,memmove,CryptImportKey,GetLastError,CryptImportKey,GetLastError,CryptImportKey,GetLastError,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,CryptDestroyKey,CryptDestroyKey, | 29_2_00007FF7F21F4064 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21FA0C4 CryptReleaseContext,CryptAcquireContextW,GetLastError,GetProcessHeap,HeapFree, | 29_2_00007FF7F21FA0C4 |
Source: | Binary string: MSRA.pdb source: msra.exe, 00000013.00000000.367253133.00007FF74440C000.00000002.00000001.01000000.0000000A.sdmp, msra.exe, 00000013.00000002.391229137.00007FF74440C000.00000002.00000001.01000000.0000000A.sdmp, msra.exe.5.dr |
Source: | Binary string: RecoveryDrive.pdbGCTL source: RecoveryDrive.exe, 0000001D.00000000.459453459.00007FF7F224C000.00000002.00000001.01000000.00000011.sdmp, RecoveryDrive.exe, 0000001D.00000002.483695697.00007FF7F224C000.00000002.00000001.01000000.00000011.sdmp, RecoveryDrive.exe.5.dr |
Source: | Binary string: msinfo32.pdb source: msinfo32.exe.5.dr |
Source: | Binary string: wscript.pdbGCTL source: wscript.exe, 00000028.00000000.584120682.00007FF775F85000.00000002.00000001.01000000.0000001A.sdmp, wscript.exe, 00000028.00000002.611169672.00007FF775F85000.00000002.00000001.01000000.0000001A.sdmp, wscript.exe.5.dr |
Source: | Binary string: MFPMP.pdb source: mfpmp.exe, 00000016.00000000.402543032.00007FF7243D7000.00000002.00000001.01000000.0000000C.sdmp, mfpmp.exe, 00000016.00000002.426009184.00007FF7243D7000.00000002.00000001.01000000.0000000C.sdmp, mfpmp.exe.5.dr |
Source: | Binary string: netplwiz.pdb source: Netplwiz.exe, 0000001A.00000000.430649778.00007FF6D63E4000.00000002.00000001.01000000.0000000F.sdmp, Netplwiz.exe, 0000001A.00000002.454430360.00007FF6D63E4000.00000002.00000001.01000000.0000000F.sdmp, Netplwiz.exe, 00000021.00000000.525832806.00007FF618294000.00000002.00000001.01000000.00000015.sdmp, Netplwiz.exe, 00000021.00000002.548659085.00007FF618294000.00000002.00000001.01000000.00000015.sdmp, Netplwiz.exe.5.dr, Netplwiz.exe0.5.dr |
Source: | Binary string: MusNotificationUx.pdb source: MusNotificationUx.exe, 00000025.00000000.554704894.00007FF7E997E000.00000002.00000001.01000000.00000017.sdmp, MusNotificationUx.exe, 00000025.00000002.579596179.00007FF7E997E000.00000002.00000001.01000000.00000017.sdmp, MusNotificationUx.exe.5.dr |
Source: | Binary string: netplwiz.pdbGCTL source: Netplwiz.exe, 0000001A.00000000.430649778.00007FF6D63E4000.00000002.00000001.01000000.0000000F.sdmp, Netplwiz.exe, 0000001A.00000002.454430360.00007FF6D63E4000.00000002.00000001.01000000.0000000F.sdmp, Netplwiz.exe, 00000021.00000000.525832806.00007FF618294000.00000002.00000001.01000000.00000015.sdmp, Netplwiz.exe, 00000021.00000002.548659085.00007FF618294000.00000002.00000001.01000000.00000015.sdmp, Netplwiz.exe.5.dr, Netplwiz.exe0.5.dr |
Source: | Binary string: OptionalFeatures.pdb source: OptionalFeatures.exe, 0000001F.00000000.489565264.00007FF7638D4000.00000002.00000001.01000000.00000013.sdmp, OptionalFeatures.exe, 0000001F.00000002.512402334.00007FF7638D4000.00000002.00000001.01000000.00000013.sdmp, OptionalFeatures.exe.5.dr |
Source: | Binary string: MusNotificationUx.pdbGCTL source: MusNotificationUx.exe, 00000025.00000000.554704894.00007FF7E997E000.00000002.00000001.01000000.00000017.sdmp, MusNotificationUx.exe, 00000025.00000002.579596179.00007FF7E997E000.00000002.00000001.01000000.00000017.sdmp, MusNotificationUx.exe.5.dr |
Source: | Binary string: MFPMP.pdbUGP source: mfpmp.exe, 00000016.00000000.402543032.00007FF7243D7000.00000002.00000001.01000000.0000000C.sdmp, mfpmp.exe, 00000016.00000002.426009184.00007FF7243D7000.00000002.00000001.01000000.0000000C.sdmp, mfpmp.exe.5.dr |
Source: | Binary string: wscript.pdb source: wscript.exe, 00000028.00000000.584120682.00007FF775F85000.00000002.00000001.01000000.0000001A.sdmp, wscript.exe, 00000028.00000002.611169672.00007FF775F85000.00000002.00000001.01000000.0000001A.sdmp, wscript.exe.5.dr |
Source: | Binary string: RecoveryDrive.pdb source: RecoveryDrive.exe, 0000001D.00000000.459453459.00007FF7F224C000.00000002.00000001.01000000.00000011.sdmp, RecoveryDrive.exe, 0000001D.00000002.483695697.00007FF7F224C000.00000002.00000001.01000000.00000011.sdmp, RecoveryDrive.exe.5.dr |
Source: | Binary string: DevicePairingWizard.pdb source: DevicePairingWizard.exe.5.dr |
Source: | Binary string: msinfo32.pdbGCTL source: msinfo32.exe.5.dr |
Source: | Binary string: OptionalFeatures.pdbGCTL source: OptionalFeatures.exe, 0000001F.00000000.489565264.00007FF7638D4000.00000002.00000001.01000000.00000013.sdmp, OptionalFeatures.exe, 0000001F.00000002.512402334.00007FF7638D4000.00000002.00000001.01000000.00000013.sdmp, OptionalFeatures.exe.5.dr |
Source: | Binary string: DevicePairingWizard.pdbGCTL source: DevicePairingWizard.exe.5.dr |
Source: | Binary string: MSRA.pdbGCTL source: msra.exe, 00000013.00000000.367253133.00007FF74440C000.00000002.00000001.01000000.0000000A.sdmp, msra.exe, 00000013.00000002.391229137.00007FF74440C000.00000002.00000001.01000000.0000000A.sdmp, msra.exe.5.dr |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24FED10 FindFirstFileExW, | 0_2_00007FFFE24FED10 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443DE800 memset,FindFirstFileW,FindClose, | 19_2_00007FF7443DE800 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FFFEF9AED10 FindFirstFileExW, | 19_2_00007FFFEF9AED10 |
Source: C:\Users\user\AppData\Local\jOnYG\mfpmp.exe | Code function: 22_2_00007FFFF6D2ED10 FindFirstFileExW, | 22_2_00007FFFF6D2ED10 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F2205458 memset,memset,memset,memset,FindFirstFileW,CompareStringW,CompareStringW,memset,FindNextFileW,FindClose,CoTaskMemFree,GetProcessHeap,HeapFree, | 29_2_00007FF7F2205458 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21D21CC GetProcessHeap,HeapFree,GetFileAttributesW,GetLastError,GetProcessHeap,HeapFree,_wcsicmp,GetProcessHeap,HeapFree,FindClose,FindFirstFileW,FindClose,GetLastError,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,FindNextFileW,memmove,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,FindClose,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 29_2_00007FF7F21D21CC |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21E6718 WIMCreateFile,GetLastError,FindClose,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,WIMCloseHandle,WIMCloseHandle,memset,WIMGetAttributes,GetLastError,memset,GetFullPathNameW,GetLastError,memset,FindFirstFileW,GetLastError,GetProcessHeap,HeapFree,WIMCreateFile,WIMCloseHandle,memset,WIMGetAttributes,FindNextFileW,GetLastError,GetLastError,GetLastError, | 29_2_00007FF7F21E6718 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21E57FC memset,GetSystemWindowsDirectoryW,GetLastError,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetFileAttributesW,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetFileAttributesW,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetVolumeInformationW,memset,FindFirstFileW,GetLastError,CompareStringW,CompareStringW,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,FindNextFileW,GetLastError,GetLastError,GetProcessHeap,HeapFree,GetFileAttributesW,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetFileAttributesW,GetProcessHeap,HeapFree,FindClose,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 29_2_00007FF7F21E57FC |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F2200638 memset,SetLastError,SetLastError,HeapAlloc,GetLastError,FindFirstFileW,memset,memset,wcsrchr,SetLastError,CompareStringW,CompareStringW,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,memset,FindNextFileW,GetLastError,GetLastError,GetLastError,FindClose,GetLastError,RtlFreeHeap,GetLastError,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,SetLastError,SetLastError, | 29_2_00007FF7F2200638 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21FE958 free,memset,FindFirstFileW,GetLastError,GetLastError,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,FindClose, | 29_2_00007FF7F21FE958 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F220B964 memset,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,FindFirstFileW,GetLastError,GetLastError,_wcsicmp,_wcsicmp,GetLastError,GetCurrentThread,NtQueryInformationThread,FindNextFileW,GetLastError,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,FindClose,SetLastError, | 29_2_00007FF7F220B964 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21E4E28 GetFileAttributesW,GetLastError,memset,FindFirstFileW,GetLastError,FindClose,GetProcessHeap,CompareStringW,CompareStringW,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,FindNextFileW,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,CreateFileW,GetLastError,CloseHandle,GetFileSizeEx,GetLastError,CloseHandle,CloseHandle,GetProcessHeap,HeapFree,CloseHandle,GetProcessHeap,CloseHandle,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 29_2_00007FF7F21E4E28 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FFFF0E1ED10 FindFirstFileExW, | 29_2_00007FFFF0E1ED10 |
Source: Yara match | File source: 26.2.Netplwiz.exe.7ffff6cd0000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 29.2.RecoveryDrive.exe.7ffff0dc0000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 37.2.MusNotificationUx.exe.7fffe3390000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 33.2.Netplwiz.exe.7ffff6cd0000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 19.2.msra.exe.7fffef950000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 40.2.wscript.exe.7fffe3390000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.loaddll64.exe.7fffe24a0000.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.2.rundll32.exe.7fffe24a0000.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 9.2.rundll32.exe.7fffe24a0000.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 31.2.OptionalFeatures.exe.7ffff6cd0000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 7.2.rundll32.exe.7fffe24a0000.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 22.2.mfpmp.exe.7ffff6cd0000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.rundll32.exe.7fffe24a0000.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000016.00000002.426087810.00007FFFF6CD1000.00000020.00000001.01000000.0000000D.sdmp, type: MEMORY |
Source: Yara match | File source: 00000028.00000002.611239452.00007FFFE3391000.00000020.00000001.01000000.0000001B.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.269553653.00007FFFE24A1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001D.00000002.483809310.00007FFFF0DC1000.00000020.00000001.01000000.00000012.sdmp, type: MEMORY |
Source: Yara match | File source: 00000007.00000002.254908404.00007FFFE24A1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 00000025.00000002.579652462.00007FFFE3391000.00000020.00000001.01000000.00000019.sdmp, type: MEMORY |
Source: Yara match | File source: 00000009.00000002.262721560.00007FFFE24A1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.548716546.00007FFFF6CD1000.00000020.00000001.01000000.00000016.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001F.00000002.512496586.00007FFFF6CD1000.00000020.00000001.01000000.00000014.sdmp, type: MEMORY |
Source: Yara match | File source: 00000013.00000002.391467819.00007FFFEF951000.00000020.00000001.01000000.0000000B.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.357465812.00007FFFE24A1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.248280628.00007FFFE24A1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001A.00000002.454470944.00007FFFF6CD1000.00000020.00000001.01000000.00000010.sdmp, type: MEMORY |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443FA8F4 CryptGetUserKey,CryptStringToBinaryW,GetProcessHeap,HeapAlloc,CryptStringToBinaryW,CryptImportKey,GetProcessHeap,HeapFree,CryptDestroyKey, | 19_2_00007FF7443FA8F4 |
Source: C:\Users\user\AppData\Local\p9w993CR\msra.exe | Code function: 19_2_00007FF7443FAAC4 CryptStringToBinaryW,GetProcessHeap,HeapAlloc,CryptStringToBinaryW,CryptImportKey,CryptDestroyKey,CryptGenKey,CryptExportKey,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,CryptExportKey,CryptBinaryToStringW,GetProcessHeap,HeapAlloc,CryptBinaryToStringW,SysAllocString,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,CryptDestroyKey, | 19_2_00007FF7443FAAC4 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21F43E0 CryptImportKey,CryptSetKeyParam,CryptSetKeyParam,CryptGetKeyParam,CryptEncrypt,CryptDecrypt,GetLastError,CryptDestroyKey,GetProcessHeap,HeapFree, | 29_2_00007FF7F21F43E0 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21F84E4 CryptImportKey,GetLastError,CryptImportKey,CryptExportKey,GetProcessHeap,HeapAlloc,CryptExportKey,GetProcessHeap,HeapAlloc,memmove,GetProcessHeap,HeapFree,CryptDestroyKey,CryptDestroyKey,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,CryptReleaseContext, | 29_2_00007FF7F21F84E4 |
Source: C:\Users\user\AppData\Local\TQg3bhA\RecoveryDrive.exe | Code function: 29_2_00007FF7F21F4064 GetProcessHeap,HeapAlloc,memmove,CryptImportKey,GetLastError,CryptImportKey,GetLastError,CryptImportKey,GetLastError,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,CryptDestroyKey,CryptDestroyKey, | 29_2_00007FF7F21F4064 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24DAA70 | 0_2_00007FFFE24DAA70 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24ECA50 | 0_2_00007FFFE24ECA50 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24EA2C0 | 0_2_00007FFFE24EA2C0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24C7880 | 0_2_00007FFFE24C7880 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24D5020 | 0_2_00007FFFE24D5020 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24F3150 | 0_2_00007FFFE24F3150 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24D59F0 | 0_2_00007FFFE24D59F0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE2507650 | 0_2_00007FFFE2507650 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24E97D0 | 0_2_00007FFFE24E97D0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE250D520 | 0_2_00007FFFE250D520 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24FDDC0 | 0_2_00007FFFE24FDDC0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE250B260 | 0_2_00007FFFE250B260 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24DB250 | 0_2_00007FFFE24DB250 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24A7A40 | 0_2_00007FFFE24A7A40 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE2507AF0 | 0_2_00007FFFE2507AF0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24DBAE0 | 0_2_00007FFFE24DBAE0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24C82E0 | 0_2_00007FFFE24C82E0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE2502AE0 | 0_2_00007FFFE2502AE0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24CA310 | 0_2_00007FFFE24CA310 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24D0300 | 0_2_00007FFFE24D0300 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24CDAA0 | 0_2_00007FFFE24CDAA0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE25082A0 | 0_2_00007FFFE25082A0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE250AAA0 | 0_2_00007FFFE250AAA0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24C92C0 | 0_2_00007FFFE24C92C0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24FF2C0 | 0_2_00007FFFE24FF2C0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24D4360 | 0_2_00007FFFE24D4360 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE2504390 | 0_2_00007FFFE2504390 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24D1B30 | 0_2_00007FFFE24D1B30 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24ABB20 | 0_2_00007FFFE24ABB20 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24A5350 | 0_2_00007FFFE24A5350 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE2505B50 | 0_2_00007FFFE2505B50 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24C3340 | 0_2_00007FFFE24C3340 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24B8340 | 0_2_00007FFFE24B8340 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE250E400 | 0_2_00007FFFE250E400 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24B23F0 | 0_2_00007FFFE24B23F0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE2509410 | 0_2_00007FFFE2509410 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24B7410 | 0_2_00007FFFE24B7410 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24F4BC0 | 0_2_00007FFFE24F4BC0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24DF870 | 0_2_00007FFFE24DF870 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24EF870 | 0_2_00007FFFE24EF870 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24BD890 | 0_2_00007FFFE24BD890 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24CC030 | 0_2_00007FFFE24CC030 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24D0020 | 0_2_00007FFFE24D0020 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24C5050 | 0_2_00007FFFE24C5050 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24F5840 | 0_2_00007FFFE24F5840 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24BE110 | 0_2_00007FFFE24BE110 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24C3910 | 0_2_00007FFFE24C3910 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24AB100 | 0_2_00007FFFE24AB100 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24B08B0 | 0_2_00007FFFE24B08B0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24A18D0 | 0_2_00007FFFE24A18D0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE250B960 | 0_2_00007FFFE250B960 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24D9990 | 0_2_00007FFFE24D9990 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24A2980 | 0_2_00007FFFE24A2980 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24D6130 | 0_2_00007FFFE24D6130 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE2506950 | 0_2_00007FFFE2506950 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24C4140 | 0_2_00007FFFE24C4140 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24D91F0 | 0_2_00007FFFE24D91F0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24D89F0 | 0_2_00007FFFE24D89F0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24CF1F0 | 0_2_00007FFFE24CF1F0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24BE9B0 | 0_2_00007FFFE24BE9B0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24C11B0 | 0_2_00007FFFE24C11B0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24CE9A0 | 0_2_00007FFFE24CE9A0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24D21D0 | 0_2_00007FFFE24D21D0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24C69C0 | 0_2_00007FFFE24C69C0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24B8670 | 0_2_00007FFFE24B8670 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24A6E90 | 0_2_00007FFFE24A6E90 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24A7E80 | 0_2_00007FFFE24A7E80 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24A1620 | 0_2_00007FFFE24A1620 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24ADE20 | 0_2_00007FFFE24ADE20 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24F0650 | 0_2_00007FFFE24F0650 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24CF6B0 | 0_2_00007FFFE24CF6B0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24D06A0 | 0_2_00007FFFE24D06A0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE250A6B0 | 0_2_00007FFFE250A6B0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE2507EC0 | 0_2_00007FFFE2507EC0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE251EF80 | 0_2_00007FFFE251EF80 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE250C780 | 0_2_00007FFFE250C780 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24BE770 | 0_2_00007FFFE24BE770 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE2500770 | 0_2_00007FFFE2500770 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE2505760 | 0_2_00007FFFE2505760 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24A6790 | 0_2_00007FFFE24A6790 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE2500F30 | 0_2_00007FFFE2500F30 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24C872B | 0_2_00007FFFE24C872B |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24C2F50 | 0_2_00007FFFE24C2F50 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24C6FE0 | 0_2_00007FFFE24C6FE0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24A1010 | 0_2_00007FFFE24A1010 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE2514FF0 | 0_2_00007FFFE2514FF0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24C4800 | 0_2_00007FFFE24C4800 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24CE7B0 | 0_2_00007FFFE24CE7B0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE251B7A0 | 0_2_00007FFFE251B7A0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24BA7D0 | 0_2_00007FFFE24BA7D0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24B8FC0 | 0_2_00007FFFE24B8FC0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE250E48B | 0_2_00007FFFE250E48B |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE250A490 | 0_2_00007FFFE250A490 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE250E494 | 0_2_00007FFFE250E494 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE250E49D | 0_2_00007FFFE250E49D |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24CAC80 | 0_2_00007FFFE24CAC80 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24A5C20 | 0_2_00007FFFE24A5C20 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24B5420 | 0_2_00007FFFE24B5420 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24D3CF0 | 0_2_00007FFFE24D3CF0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24D0D10 | 0_2_00007FFFE24D0D10 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE2502CA0 | 0_2_00007FFFE2502CA0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE250E4A6 | 0_2_00007FFFE250E4A6 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24B3CD0 | 0_2_00007FFFE24B3CD0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE24D5CD0 | 0_2_00007FFFE24D5CD0 |
Source: C:\Windows\System32\loaddll64.exe | Code function: 0_2_00007FFFE2 |