Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
CJu1sWJfWk

Overview

General Information

Sample Name:CJu1sWJfWk (renamed file extension from none to dll)
Analysis ID:595319
MD5:2a52d4cc48659ad06386e6f1ddb17613
SHA1:fb551a1f927e6b86fb2e8281d4f09a753e5a7f5b
SHA256:ab8f6d64918bfde8d603af28047f91c3bdfd82df3d965391fc1b480542d64b89
Tags:Dridexexe
Infos:

Detection

Dridex
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected Dridex unpacked file
Multi AV Scanner detection for submitted file
Benign windows process drops PE files
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Changes memory attributes in foreign processes to executable or writable
Machine Learning detection for sample
Queues an APC in another process (thread injection)
Sigma detected: Suspicious Call by Ordinal
Machine Learning detection for dropped file
Contains functionality to prevent local Windows debugging
Uses Atom Bombing / ProGate to inject into other processes
Contains functionality to check if a debugger is running (IsDebuggerPresent)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
PE file contains sections with non-standard names
Queries the installation date of Windows
Detected potential crypto function
Found potential string decryption / allocating functions
Sample execution stops while process was sleeping (likely an evasion)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to call native functions
Contains functionality to communicate with device drivers
Found dropped PE file which has not been started or loaded
Contains functionality which may be used to detect a debugger (GetProcessHeap)
PE file contains executable resources (Code or Archives)
Contains functionality for execution timing, often used to detect debuggers
PE file contains strange resources
Drops PE files
Tries to load missing DLLs
Found evasive API chain checking for process token information
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Binary contains a suspicious time stamp
Registers a DLL
PE file contains more sections than normal
Found large amount of non-executed APIs
Uses Microsoft's Enhanced Cryptographic Provider
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)

Classification

  • System is w10x64
  • loaddll64.exe (PID: 6736 cmdline: loaddll64.exe "C:\Users\user\Desktop\CJu1sWJfWk.dll" MD5: 4E8A40CAD6CCC047914E3A7830A2D8AA)
    • cmd.exe (PID: 6732 cmdline: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\CJu1sWJfWk.dll",#1 MD5: 4E2ACF4F8A396486AB4268C94A6A245F)
      • rundll32.exe (PID: 6712 cmdline: rundll32.exe "C:\Users\user\Desktop\CJu1sWJfWk.dll",#1 MD5: 73C519F050C20580F8A62C849D49215A)
    • regsvr32.exe (PID: 6720 cmdline: regsvr32.exe /s C:\Users\user\Desktop\CJu1sWJfWk.dll MD5: D78B75FC68247E8A63ACBA846182740E)
      • explorer.exe (PID: 3688 cmdline: C:\Windows\Explorer.EXE MD5: AD5296B280E8F522A8A897C96BAB0E1D)
        • systemreset.exe (PID: 4916 cmdline: C:\Windows\system32\systemreset.exe MD5: 872AE9FE08ED1AA78208678967BE2FEF)
        • systemreset.exe (PID: 6332 cmdline: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exe MD5: 872AE9FE08ED1AA78208678967BE2FEF)
        • irftp.exe (PID: 6436 cmdline: C:\Windows\system32\irftp.exe MD5: F1C2D10CA8161DB689CD4FDE756E2DBB)
        • irftp.exe (PID: 1488 cmdline: C:\Users\user\AppData\Local\YMJtPINjt\irftp.exe MD5: F1C2D10CA8161DB689CD4FDE756E2DBB)
        • slui.exe (PID: 6528 cmdline: C:\Windows\system32\slui.exe MD5: 96A8EF9387619D17BB30B024DDF52BF3)
        • slui.exe (PID: 6080 cmdline: C:\Users\user\AppData\Local\ns1MY\slui.exe MD5: 96A8EF9387619D17BB30B024DDF52BF3)
        • mfpmp.exe (PID: 6232 cmdline: C:\Windows\system32\mfpmp.exe MD5: 7C3D09D6DB5DB4A272FCF4C1BB3986BD)
        • mfpmp.exe (PID: 1268 cmdline: C:\Users\user\AppData\Local\oNo29a9yW\mfpmp.exe MD5: 7C3D09D6DB5DB4A272FCF4C1BB3986BD)
        • rdpinit.exe (PID: 4256 cmdline: C:\Windows\system32\rdpinit.exe MD5: EF7C9CF6EA5B8B9C5C8320990714C35D)
        • rdpinit.exe (PID: 6032 cmdline: C:\Users\user\AppData\Local\V3ju9LunR\rdpinit.exe MD5: EF7C9CF6EA5B8B9C5C8320990714C35D)
        • Dxpserver.exe (PID: 7016 cmdline: C:\Windows\system32\Dxpserver.exe MD5: DCCB1D350193BE0A26CEAFF602DB848E)
        • Dxpserver.exe (PID: 7084 cmdline: C:\Users\user\AppData\Local\PVsO8HfRn\Dxpserver.exe MD5: DCCB1D350193BE0A26CEAFF602DB848E)
        • FXSCOVER.exe (PID: 5564 cmdline: C:\Windows\system32\FXSCOVER.exe MD5: BEAB16FEFCB7F62BBC135FB87DF7FDF2)
        • FXSCOVER.exe (PID: 5584 cmdline: C:\Users\user\AppData\Local\qpscHm\FXSCOVER.exe MD5: BEAB16FEFCB7F62BBC135FB87DF7FDF2)
        • mmc.exe (PID: 6456 cmdline: C:\Windows\system32\mmc.exe MD5: BA80301974CC8C4FB9F3F9DDB5905C30)
        • mmc.exe (PID: 4960 cmdline: C:\Users\user\AppData\Local\iSZdEuUQU\mmc.exe MD5: BA80301974CC8C4FB9F3F9DDB5905C30)
        • RdpSaUacHelper.exe (PID: 7116 cmdline: C:\Windows\system32\RdpSaUacHelper.exe MD5: DA88A7B872B1A52F2465D12CFBA4EDAB)
        • RdpSaUacHelper.exe (PID: 6408 cmdline: C:\Users\user\AppData\Local\KN4et9\RdpSaUacHelper.exe MD5: DA88A7B872B1A52F2465D12CFBA4EDAB)
        • mblctr.exe (PID: 1776 cmdline: C:\Windows\system32\mblctr.exe MD5: 0CE1C2D873D151A19FB993139D19E68B)
    • rundll32.exe (PID: 6776 cmdline: rundll32.exe C:\Users\user\Desktop\CJu1sWJfWk.dll,BeginBufferedAnimation MD5: 73C519F050C20580F8A62C849D49215A)
    • rundll32.exe (PID: 4724 cmdline: rundll32.exe C:\Users\user\Desktop\CJu1sWJfWk.dll,BeginBufferedPaint MD5: 73C519F050C20580F8A62C849D49215A)
    • rundll32.exe (PID: 1268 cmdline: rundll32.exe C:\Users\user\Desktop\CJu1sWJfWk.dll,BeginPanningFeedback MD5: 73C519F050C20580F8A62C849D49215A)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000024.00000002.744653050.00007FFF2F281000.00000020.00000001.01000000.00000019.sdmpJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
    00000020.00000002.672187503.00007FFF2F291000.00000020.00000001.01000000.00000015.sdmpJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
      00000026.00000002.774985699.00007FFF2E811000.00000020.00000001.01000000.0000001B.sdmpJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
        00000004.00000002.367061712.00007FFF2F261000.00000020.00000001.01000000.00000003.sdmpJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
          00000028.00000002.810456162.00007FFF2F291000.00000020.00000001.01000000.0000001D.sdmpJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
            Click to see the 10 entries
            SourceRuleDescriptionAuthorStrings
            32.2.rdpinit.exe.7fff2f290000.3.unpackJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
              28.2.slui.exe.7fff2f290000.3.unpackJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
                18.2.systemreset.exe.7fff2f290000.3.unpackJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
                  30.2.mfpmp.exe.7fff2f290000.3.unpackJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
                    5.2.rundll32.exe.7fff2f260000.2.unpackJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
                      Click to see the 8 entries

                      System Summary

                      barindex
                      Source: Process startedAuthor: Florian Roth: Data: Command: rundll32.exe "C:\Users\user\Desktop\CJu1sWJfWk.dll",#1, CommandLine: rundll32.exe "C:\Users\user\Desktop\CJu1sWJfWk.dll",#1, CommandLine|base64offset|contains: , Image: C:\Windows\System32\rundll32.exe, NewProcessName: C:\Windows\System32\rundll32.exe, OriginalFileName: C:\Windows\System32\rundll32.exe, ParentCommandLine: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\CJu1sWJfWk.dll",#1, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 6732, ProcessCommandLine: rundll32.exe "C:\Users\user\Desktop\CJu1sWJfWk.dll",#1, ProcessId: 6712
                      Source: File createdAuthor: frack113: Data: EventID: 11, Image: C:\Windows\explorer.exe, ProcessId: 3688, TargetFilename: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exe

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection

                      barindex
                      Source: CJu1sWJfWk.dllVirustotal: Detection: 76%Perma Link
                      Source: CJu1sWJfWk.dllMetadefender: Detection: 62%Perma Link
                      Source: CJu1sWJfWk.dllReversingLabs: Detection: 88%
                      Source: CJu1sWJfWk.dllAvira: detected
                      Source: C:\Users\user\AppData\Local\KN4et9\WINSTA.dllAvira: detection malicious, Label: TR/Crypt.ZPACK.Gen
                      Source: C:\Users\user\AppData\Local\PVsO8HfRn\dwmapi.dllAvira: detection malicious, Label: TR/Crypt.XPACK.Gen7
                      Source: C:\Users\user\AppData\Local\ns1MY\WTSAPI32.dllAvira: detection malicious, Label: TR/Crypt.ZPACK.Gen
                      Source: C:\Users\user\AppData\Local\YMJtPINjt\WINMM.dllAvira: detection malicious, Label: TR/Crypt.ZPACK.Gen
                      Source: C:\Users\user\AppData\Local\PVsO8HfRn\dwmapi.dllAvira: detection malicious, Label: TR/Crypt.XPACK.Gen7
                      Source: C:\Users\user\AppData\Local\qpscHm\MFC42u.dllAvira: detection malicious, Label: TR/Crypt.ZPACK.Gen
                      Source: C:\Users\user\AppData\Local\4hM96ANL\ReAgent.dllAvira: detection malicious, Label: TR/Crypt.XPACK.Gen7
                      Source: C:\Users\user\AppData\Local\KN4et9\WINSTA.dllAvira: detection malicious, Label: TR/Crypt.ZPACK.Gen
                      Source: C:\Users\user\AppData\Local\ns1MY\WTSAPI32.dllAvira: detection malicious, Label: TR/Crypt.ZPACK.Gen
                      Source: C:\Users\user\AppData\Local\oQi\VERSION.dllAvira: detection malicious, Label: TR/Crypt.ZPACK.Gen
                      Source: C:\Users\user\AppData\Local\iSZdEuUQU\mmcbase.DLLAvira: detection malicious, Label: TR/Crypt.XPACK.Gen7
                      Source: C:\Users\user\AppData\Local\oNo29a9yW\MFPlat.DLLAvira: detection malicious, Label: TR/Crypt.XPACK.Gen7
                      Source: CJu1sWJfWk.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\KN4et9\WINSTA.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\PVsO8HfRn\dwmapi.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\ns1MY\WTSAPI32.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\YMJtPINjt\WINMM.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\PVsO8HfRn\dwmapi.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\qpscHm\MFC42u.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\4hM96ANL\ReAgent.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\KN4et9\WINSTA.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\ns1MY\WTSAPI32.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\oQi\VERSION.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\iSZdEuUQU\mmcbase.DLLJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\oNo29a9yW\MFPlat.DLLJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\V3ju9LunR\rdpinit.exeCode function: 32_2_00007FF7C6A02D94 CryptAcquireContextW,GetLastError,CryptGenRandom,GetLastError,CryptReleaseContext,32_2_00007FF7C6A02D94
                      Source: CJu1sWJfWk.dllStatic PE information: TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT, HIGH_ENTROPY_VA
                      Source: Binary string: slui.pdb source: slui.exe, 0000001C.00000000.576973852.00007FF6896DC000.00000002.00000001.01000000.0000000F.sdmp, slui.exe, 0000001C.00000002.602092427.00007FF6896DC000.00000002.00000001.01000000.0000000F.sdmp
                      Source: Binary string: FXSCOVER.pdb source: FXSCOVER.exe, 00000024.00000000.719410189.00007FF71BF22000.00000002.00000001.01000000.00000018.sdmp, FXSCOVER.exe, 00000024.00000002.744580898.00007FF71BF22000.00000002.00000001.01000000.00000018.sdmp
                      Source: Binary string: irftp.pdbGCTL source: irftp.exe, 00000015.00000002.571923555.00007FF669285000.00000002.00000001.01000000.0000000B.sdmp, irftp.exe, 00000015.00000000.532927512.00007FF669285000.00000002.00000001.01000000.0000000B.sdmp
                      Source: Binary string: MFPMP.pdb source: mfpmp.exe, 0000001E.00000002.641878378.00007FF7FF637000.00000002.00000001.01000000.00000011.sdmp, mfpmp.exe, 0000001E.00000000.618202747.00007FF7FF637000.00000002.00000001.01000000.00000011.sdmp
                      Source: Binary string: rdpinit.pdb source: rdpinit.exe, 00000020.00000000.647965981.00007FF7C6A3E000.00000002.00000001.01000000.00000014.sdmp, rdpinit.exe, 00000020.00000002.672090134.00007FF7C6A3E000.00000002.00000001.01000000.00000014.sdmp
                      Source: Binary string: rdpinit.pdbGCTL source: rdpinit.exe, 00000020.00000000.647965981.00007FF7C6A3E000.00000002.00000001.01000000.00000014.sdmp, rdpinit.exe, 00000020.00000002.672090134.00007FF7C6A3E000.00000002.00000001.01000000.00000014.sdmp
                      Source: Binary string: MFPMP.pdbUGP source: mfpmp.exe, 0000001E.00000002.641878378.00007FF7FF637000.00000002.00000001.01000000.00000011.sdmp, mfpmp.exe, 0000001E.00000000.618202747.00007FF7FF637000.00000002.00000001.01000000.00000011.sdmp
                      Source: Binary string: systemreset.pdb source: systemreset.exe, 00000012.00000002.527294557.00007FF6C4651000.00000002.00000001.01000000.00000009.sdmp, systemreset.exe, 00000012.00000000.501974007.00007FF6C4651000.00000002.00000001.01000000.00000009.sdmp
                      Source: Binary string: FXSCOVER.pdbGCTL source: FXSCOVER.exe, 00000024.00000000.719410189.00007FF71BF22000.00000002.00000001.01000000.00000018.sdmp, FXSCOVER.exe, 00000024.00000002.744580898.00007FF71BF22000.00000002.00000001.01000000.00000018.sdmp
                      Source: Binary string: DXPServer.pdbGCTL source: Dxpserver.exe, 00000022.00000000.677391115.00007FF73F041000.00000002.00000001.01000000.00000016.sdmp, Dxpserver.exe, 00000022.00000002.701873761.00007FF73F041000.00000002.00000001.01000000.00000016.sdmp
                      Source: Binary string: systemreset.pdbGCTL source: systemreset.exe, 00000012.00000002.527294557.00007FF6C4651000.00000002.00000001.01000000.00000009.sdmp, systemreset.exe, 00000012.00000000.501974007.00007FF6C4651000.00000002.00000001.01000000.00000009.sdmp
                      Source: Binary string: slui.pdbUGP source: slui.exe, 0000001C.00000000.576973852.00007FF6896DC000.00000002.00000001.01000000.0000000F.sdmp, slui.exe, 0000001C.00000002.602092427.00007FF6896DC000.00000002.00000001.01000000.0000000F.sdmp
                      Source: Binary string: DXPServer.pdb source: Dxpserver.exe, 00000022.00000000.677391115.00007FF73F041000.00000002.00000001.01000000.00000016.sdmp, Dxpserver.exe, 00000022.00000002.701873761.00007FF73F041000.00000002.00000001.01000000.00000016.sdmp
                      Source: Binary string: irftp.pdb source: irftp.exe, 00000015.00000002.571923555.00007FF669285000.00000002.00000001.01000000.0000000B.sdmp, irftp.exe, 00000015.00000000.532927512.00007FF669285000.00000002.00000001.01000000.0000000B.sdmp
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2BED10 FindFirstFileExW,0_2_00007FFF2F2BED10
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C464A9EC memset,SetLastError,SetLastError,HeapAlloc,GetLastError,FindFirstFileW,memset,memset,wcsrchr,SetLastError,CompareStringW,CompareStringW,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,memset,FindNextFileW,GetLastError,GetLastError,GetLastError,FindClose,GetLastError,RtlFreeHeap,GetLastError,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,SetLastError,SetLastError,18_2_00007FF6C464A9EC
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C464B1D0 FindFirstFileW,FindNextFileW,_wcsicmp,_wcsicmp,SetFileAttributesW,DeleteFileW,GetLastError,FindClose,GetLastError,SetLastError,18_2_00007FF6C464B1D0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C46374A0 memset,FindFirstFileW,FindClose,PostMessageW,18_2_00007FF6C46374A0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2EED10 FindFirstFileExW,18_2_00007FFF2F2EED10
                      Source: C:\Users\user\AppData\Local\YMJtPINjt\irftp.exeCode function: 21_2_00007FF66927B908 FindFirstFileW,lstrcmpW,lstrcmpW,FindNextFileW,FindClose,21_2_00007FF66927B908
                      Source: C:\Users\user\AppData\Local\YMJtPINjt\irftp.exeCode function: 21_2_00007FF66927C018 FindFirstFileW,lstrcmpW,lstrcmpW,CreateFileW,GetFileSize,CloseHandle,FindNextFileW,FindClose,21_2_00007FF66927C018
                      Source: C:\Users\user\AppData\Local\YMJtPINjt\irftp.exeCode function: 21_2_00007FFF2E86ED10 FindFirstFileExW,21_2_00007FFF2E86ED10
                      Source: C:\Users\user\AppData\Local\YMJtPINjt\irftp.exeCode function: 21_2_00007FF66927A6E8 select,recv,GetLastError,select,21_2_00007FF66927A6E8

                      E-Banking Fraud

                      barindex
                      Source: Yara matchFile source: 32.2.rdpinit.exe.7fff2f290000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 28.2.slui.exe.7fff2f290000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 18.2.systemreset.exe.7fff2f290000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 30.2.mfpmp.exe.7fff2f290000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.7fff2f260000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.rundll32.exe.7fff2f260000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 36.2.FXSCOVER.exe.7fff2f280000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 4.2.rundll32.exe.7fff2f260000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 21.2.irftp.exe.7fff2e810000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.regsvr32.exe.7fff2f260000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll64.exe.7fff2f260000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 34.2.Dxpserver.exe.7fff2f290000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.7fff2f260000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000024.00000002.744653050.00007FFF2F281000.00000020.00000001.01000000.00000019.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000020.00000002.672187503.00007FFF2F291000.00000020.00000001.01000000.00000015.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000026.00000002.774985699.00007FFF2E811000.00000020.00000001.01000000.0000001B.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000002.367061712.00007FFF2F261000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000028.00000002.810456162.00007FFF2F291000.00000020.00000001.01000000.0000001D.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000022.00000002.701945948.00007FFF2F291000.00000020.00000001.01000000.00000017.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.386333587.00007FFF2F261000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000003.00000002.490083251.00007FFF2F261000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000001C.00000002.602217664.00007FFF2F291000.00000020.00000001.01000000.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.380243641.00007FFF2F261000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000012.00000002.527531881.00007FFF2F291000.00000020.00000001.01000000.0000000A.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.366294704.00007FFF2F261000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000015.00000002.572046007.00007FFF2E811000.00000020.00000001.01000000.0000000C.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.372913462.00007FFF2F261000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000001E.00000002.641971707.00007FFF2F291000.00000020.00000001.01000000.00000012.sdmp, type: MEMORY
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2A97D00_2_00007FFF2F2A97D0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2C76500_2_00007FFF2F2C7650
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2CD5200_2_00007FFF2F2CD520
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2BDDC00_2_00007FFF2F2BDDC0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2ACA500_2_00007FFF2F2ACA50
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F29AA700_2_00007FFF2F29AA70
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2AA2C00_2_00007FFF2F2AA2C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2B31500_2_00007FFF2F2B3150
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2959F00_2_00007FFF2F2959F0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2950200_2_00007FFF2F295020
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2878800_2_00007FFF2F287880
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F282F500_2_00007FFF2F282F50
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2C0F300_2_00007FFF2F2C0F30
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F28872B0_2_00007FFF2F28872B
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2667900_2_00007FFF2F266790
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2DEF800_2_00007FFF2F2DEF80
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2CC7800_2_00007FFF2F2CC780
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F27E7700_2_00007FFF2F27E770
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2C07700_2_00007FFF2F2C0770
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2C57600_2_00007FFF2F2C5760
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F27A7D00_2_00007FFF2F27A7D0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F278FC00_2_00007FFF2F278FC0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F28E7B00_2_00007FFF2F28E7B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2DB7A00_2_00007FFF2F2DB7A0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2610100_2_00007FFF2F261010
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2848000_2_00007FFF2F284800
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2D4FF00_2_00007FFF2F2D4FF0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F286FE00_2_00007FFF2F286FE0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2B06500_2_00007FFF2F2B0650
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2616200_2_00007FFF2F261620
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F26DE200_2_00007FFF2F26DE20
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F266E900_2_00007FFF2F266E90
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F267E800_2_00007FFF2F267E80
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2786700_2_00007FFF2F278670
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2C7EC00_2_00007FFF2F2C7EC0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F28F6B00_2_00007FFF2F28F6B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2CA6B00_2_00007FFF2F2CA6B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2906A00_2_00007FFF2F2906A0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F283D500_2_00007FFF2F283D50
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F28D5500_2_00007FFF2F28D550
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F291D300_2_00007FFF2F291D30
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F279D700_2_00007FFF2F279D70
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2795C00_2_00007FFF2F2795C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2925C00_2_00007FFF2F2925C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F26C5A00_2_00007FFF2F26C5A0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2836100_2_00007FFF2F283610
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F292E100_2_00007FFF2F292E10
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2765E00_2_00007FFF2F2765E0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F265C200_2_00007FFF2F265C20
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2754200_2_00007FFF2F275420
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2CE49D0_2_00007FFF2F2CE49D
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2CE4940_2_00007FFF2F2CE494
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2CA4900_2_00007FFF2F2CA490
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2CE48B0_2_00007FFF2F2CE48B
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F28AC800_2_00007FFF2F28AC80
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F273CD00_2_00007FFF2F273CD0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F295CD00_2_00007FFF2F295CD0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2CE4B60_2_00007FFF2F2CE4B6
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2CE4AD0_2_00007FFF2F2CE4AD
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2C2CA00_2_00007FFF2F2C2CA0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2CE4A60_2_00007FFF2F2CE4A6
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F290D100_2_00007FFF2F290D10
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F293CF00_2_00007FFF2F293CF0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2653500_2_00007FFF2F265350
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2C5B500_2_00007FFF2F2C5B50
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2833400_2_00007FFF2F283340
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2783400_2_00007FFF2F278340
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F291B300_2_00007FFF2F291B30
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F26BB200_2_00007FFF2F26BB20
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2C43900_2_00007FFF2F2C4390
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2943600_2_00007FFF2F294360
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2B4BC00_2_00007FFF2F2B4BC0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2774100_2_00007FFF2F277410
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2C94100_2_00007FFF2F2C9410
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2CE4000_2_00007FFF2F2CE400
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2723F00_2_00007FFF2F2723F0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F29B2500_2_00007FFF2F29B250
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F267A400_2_00007FFF2F267A40
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2CB2600_2_00007FFF2F2CB260
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2892C00_2_00007FFF2F2892C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2BF2C00_2_00007FFF2F2BF2C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F28DAA00_2_00007FFF2F28DAA0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2C82A00_2_00007FFF2F2C82A0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2CAAA00_2_00007FFF2F2CAAA0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F28A3100_2_00007FFF2F28A310
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2903000_2_00007FFF2F290300
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2C7AF00_2_00007FFF2F2C7AF0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F29BAE00_2_00007FFF2F29BAE0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2882E00_2_00007FFF2F2882E0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2C2AE00_2_00007FFF2F2C2AE0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2C69500_2_00007FFF2F2C6950
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2841400_2_00007FFF2F284140
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2961300_2_00007FFF2F296130
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2999900_2_00007FFF2F299990
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2629800_2_00007FFF2F262980
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2CB9600_2_00007FFF2F2CB960
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2921D00_2_00007FFF2F2921D0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2869C00_2_00007FFF2F2869C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F27E9B00_2_00007FFF2F27E9B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2811B00_2_00007FFF2F2811B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F28E9A00_2_00007FFF2F28E9A0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2991F00_2_00007FFF2F2991F0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2989F00_2_00007FFF2F2989F0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F28F1F00_2_00007FFF2F28F1F0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2850500_2_00007FFF2F285050
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2B58400_2_00007FFF2F2B5840
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F28C0300_2_00007FFF2F28C030
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2900200_2_00007FFF2F290020
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F27D8900_2_00007FFF2F27D890
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F29F8700_2_00007FFF2F29F870
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2AF8700_2_00007FFF2F2AF870
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2618D00_2_00007FFF2F2618D0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2708B00_2_00007FFF2F2708B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F27E1100_2_00007FFF2F27E110
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F2839100_2_00007FFF2F283910
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFF2F26B1000_2_00007FFF2F26B100
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C4637E2018_2_00007FF6C4637E20
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C462E5D418_2_00007FF6C462E5D4
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C462369418_2_00007FF6C4623694
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C4623E7C18_2_00007FF6C4623E7C
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C463866018_2_00007FF6C4638660
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C464071C18_2_00007FF6C464071C
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C4648ED818_2_00007FF6C4648ED8
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C464DF9018_2_00007FF6C464DF90
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C463582018_2_00007FF6C4635820
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C464207C18_2_00007FF6C464207C
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C463885018_2_00007FF6C4638850
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C46380D018_2_00007FF6C46380D0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C462321818_2_00007FF6C4623218
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C4636A2018_2_00007FF6C4636A20
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C46419FC18_2_00007FF6C46419FC
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C464A9EC18_2_00007FF6C464A9EC
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C4646AB018_2_00007FF6C4646AB0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C463633018_2_00007FF6C4636330
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C463832018_2_00007FF6C4638320
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C463732418_2_00007FF6C4637324
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C4637B7018_2_00007FF6C4637B70
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C4643BE018_2_00007FF6C4643BE0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C464BC5818_2_00007FF6C464BC58
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FF6C464551018_2_00007FF6C4645510
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2D97D018_2_00007FFF2F2D97D0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2F765018_2_00007FFF2F2F7650
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2FD52018_2_00007FFF2F2FD520
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2EDDC018_2_00007FFF2F2EDDC0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2C5CD018_2_00007FFF2F2C5CD0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2DCA5018_2_00007FFF2F2DCA50
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2CAA7018_2_00007FFF2F2CAA70
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2DA2C018_2_00007FFF2F2DA2C0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2CBAE018_2_00007FFF2F2CBAE0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2E315018_2_00007FFF2F2E3150
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2C59F018_2_00007FFF2F2C59F0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2C502018_2_00007FFF2F2C5020
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2B788018_2_00007FFF2F2B7880
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2B2F5018_2_00007FFF2F2B2F50
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F30BF6F18_2_00007FFF2F30BF6F
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F30EF8018_2_00007FFF2F30EF80
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2F0F3018_2_00007FFF2F2F0F30
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2B872B18_2_00007FFF2F2B872B
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F29679018_2_00007FFF2F296790
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2FC78018_2_00007FFF2F2FC780
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2AE77018_2_00007FFF2F2AE770
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2F077018_2_00007FFF2F2F0770
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2F576018_2_00007FFF2F2F5760
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2AA7D018_2_00007FFF2F2AA7D0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2A8FC018_2_00007FFF2F2A8FC0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2BE7B018_2_00007FFF2F2BE7B0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F30B7A018_2_00007FFF2F30B7A0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F29101018_2_00007FFF2F291010
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2B480018_2_00007FFF2F2B4800
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F304FF018_2_00007FFF2F304FF0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2B6FE018_2_00007FFF2F2B6FE0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2E065018_2_00007FFF2F2E0650
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F29DE2018_2_00007FFF2F29DE20
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F29162018_2_00007FFF2F291620
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F296E9018_2_00007FFF2F296E90
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F297E8018_2_00007FFF2F297E80
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2A867018_2_00007FFF2F2A8670
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2F7EC018_2_00007FFF2F2F7EC0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2BF6B018_2_00007FFF2F2BF6B0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2FA6B018_2_00007FFF2F2FA6B0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2C06A018_2_00007FFF2F2C06A0
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2BD55018_2_00007FFF2F2BD550
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2B3D5018_2_00007FFF2F2B3D50
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2C1D3018_2_00007FFF2F2C1D30
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F30C59018_2_00007FFF2F30C590
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2E8D2018_2_00007FFF2F2E8D20
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exeCode function: 18_2_00007FFF2F2A9D7018_2_00007FFF2F2A9D70
                      Source: C:\Users\user\AppData\Local\4hM96ANL\systemreset.exe