Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
elBAfme5gQ

Overview

General Information

Sample Name:elBAfme5gQ (renamed file extension from none to dll)
Analysis ID:595323
MD5:ca7c6f265e4bc09e6d9d0b2b6234e8b3
SHA1:1720aadb4965df64ee40d32957ee6080500639b2
SHA256:a8f566b8d2d9f9a418211039cb76552d460f83195d519a89313a880ead9bd4a4
Tags:Dridexexe
Infos:

Detection

Dridex
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected Dridex unpacked file
Multi AV Scanner detection for submitted file
Benign windows process drops PE files
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Changes memory attributes in foreign processes to executable or writable
Machine Learning detection for sample
Modifies the prolog of user mode functions (user mode inline hooks)
Queues an APC in another process (thread injection)
Sigma detected: Suspicious Call by Ordinal
Machine Learning detection for dropped file
Uses Atom Bombing / ProGate to inject into other processes
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Contains functionality to execute programs as a different user
PE file contains sections with non-standard names
Queries the installation date of Windows
Detected potential crypto function
Found potential string decryption / allocating functions
Contains functionality to call native functions
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to dynamically determine API calls
Contains functionality which may be used to detect a debugger (GetProcessHeap)
PE file contains executable resources (Code or Archives)
Contains functionality for execution timing, often used to detect debuggers
Sample file is different than original file name gathered from version info
PE file contains strange resources
Drops PE files
Tries to load missing DLLs
Found evasive API chain checking for process token information
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Binary contains a suspicious time stamp
PE file contains more sections than normal
Found large amount of non-executed APIs
Uses Microsoft's Enhanced Cryptographic Provider
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)

Classification

  • System is w10x64
  • loaddll64.exe (PID: 6828 cmdline: loaddll64.exe "C:\Users\user\Desktop\elBAfme5gQ.dll" MD5: 4E8A40CAD6CCC047914E3A7830A2D8AA)
    • cmd.exe (PID: 6836 cmdline: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\elBAfme5gQ.dll",#1 MD5: 4E2ACF4F8A396486AB4268C94A6A245F)
      • rundll32.exe (PID: 6856 cmdline: rundll32.exe "C:\Users\user\Desktop\elBAfme5gQ.dll",#1 MD5: 73C519F050C20580F8A62C849D49215A)
    • rundll32.exe (PID: 6844 cmdline: rundll32.exe C:\Users\user\Desktop\elBAfme5gQ.dll,CreateXmlReader MD5: 73C519F050C20580F8A62C849D49215A)
      • explorer.exe (PID: 3968 cmdline: C:\Windows\Explorer.EXE MD5: AD5296B280E8F522A8A897C96BAB0E1D)
        • PresentationSettings.exe (PID: 7040 cmdline: C:\Windows\system32\PresentationSettings.exe MD5: 76086DD04B6760277A2B897345A0B457)
        • PresentationSettings.exe (PID: 5432 cmdline: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exe MD5: 76086DD04B6760277A2B897345A0B457)
        • DmNotificationBroker.exe (PID: 5352 cmdline: C:\Windows\system32\DmNotificationBroker.exe MD5: 1643D5735213BC89C0012F0E48253765)
        • DmNotificationBroker.exe (PID: 5876 cmdline: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exe MD5: 1643D5735213BC89C0012F0E48253765)
        • WFS.exe (PID: 4504 cmdline: C:\Windows\system32\WFS.exe MD5: CD6ACF3B997099B6CFB2417D3942F755)
        • WFS.exe (PID: 6212 cmdline: C:\Users\user\AppData\Local\daH0n9\WFS.exe MD5: CD6ACF3B997099B6CFB2417D3942F755)
        • DmNotificationBroker.exe (PID: 6008 cmdline: C:\Windows\system32\DmNotificationBroker.exe MD5: 1643D5735213BC89C0012F0E48253765)
        • DmNotificationBroker.exe (PID: 1804 cmdline: C:\Users\user\AppData\Local\pEcAZnNU3\DmNotificationBroker.exe MD5: 1643D5735213BC89C0012F0E48253765)
        • wusa.exe (PID: 6376 cmdline: C:\Windows\system32\wusa.exe MD5: 04CE745559916B99248F266BBF5F9ED9)
    • rundll32.exe (PID: 6896 cmdline: rundll32.exe C:\Users\user\Desktop\elBAfme5gQ.dll,CreateXmlReaderInputWithEncodingCodePage MD5: 73C519F050C20580F8A62C849D49215A)
    • rundll32.exe (PID: 6928 cmdline: rundll32.exe C:\Users\user\Desktop\elBAfme5gQ.dll,CreateXmlReaderInputWithEncodingName MD5: 73C519F050C20580F8A62C849D49215A)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000015.00000002.455715001.00007FFC66921000.00000020.00000001.01000000.0000000C.sdmpJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
    00000002.00000002.382683427.00007FFC646C1000.00000020.00000001.01000000.00000003.sdmpJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
      0000001F.00000002.529541082.00007FFC67881000.00000020.00000001.01000000.00000010.sdmpJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
        00000006.00000002.279312817.00007FFC646C1000.00000020.00000001.01000000.00000003.sdmpJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
          00000003.00000002.265252224.00007FFC646C1000.00000020.00000001.01000000.00000003.sdmpJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
            Click to see the 4 entries
            SourceRuleDescriptionAuthorStrings
            18.2.PresentationSettings.exe.7ffc66970000.3.unpackJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
              25.2.WFS.exe.7ffc66970000.3.unpackJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
                2.2.rundll32.exe.7ffc646c0000.2.unpackJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
                  31.2.DmNotificationBroker.exe.7ffc67880000.3.unpackJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
                    5.2.rundll32.exe.7ffc646c0000.2.unpackJoeSecurity_Dridex_2Yara detected Dridex unpacked fileJoe Security
                      Click to see the 4 entries

                      System Summary

                      barindex
                      Source: Process startedAuthor: Florian Roth: Data: Command: rundll32.exe "C:\Users\user\Desktop\elBAfme5gQ.dll",#1, CommandLine: rundll32.exe "C:\Users\user\Desktop\elBAfme5gQ.dll",#1, CommandLine|base64offset|contains: , Image: C:\Windows\System32\rundll32.exe, NewProcessName: C:\Windows\System32\rundll32.exe, OriginalFileName: C:\Windows\System32\rundll32.exe, ParentCommandLine: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\elBAfme5gQ.dll",#1, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 6836, ProcessCommandLine: rundll32.exe "C:\Users\user\Desktop\elBAfme5gQ.dll",#1, ProcessId: 6856
                      Source: File createdAuthor: frack113: Data: EventID: 11, Image: C:\Windows\explorer.exe, ProcessId: 3968, TargetFilename: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exe

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection

                      barindex
                      Source: elBAfme5gQ.dllVirustotal: Detection: 62%Perma Link
                      Source: elBAfme5gQ.dllMetadefender: Detection: 65%Perma Link
                      Source: elBAfme5gQ.dllReversingLabs: Detection: 88%
                      Source: elBAfme5gQ.dllAvira: detected
                      Source: C:\Users\user\AppData\Local\WRsLe\DUI70.dllAvira: detection malicious, Label: TR/Crypt.XPACK.Gen4
                      Source: C:\Users\user\AppData\Local\daH0n9\credui.dllAvira: detection malicious, Label: TR/Crypt.XPACK.Gen7
                      Source: C:\Users\user\AppData\Local\WRsLe\DUI70.dllAvira: detection malicious, Label: TR/Crypt.XPACK.Gen4
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\WINMM.dllAvira: detection malicious, Label: TR/Crypt.ZPACK.Gen
                      Source: elBAfme5gQ.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\WRsLe\DUI70.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\daH0n9\credui.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\WRsLe\DUI70.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\WINMM.dllJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E073F500 CryptProtectData,GetLastError,RegSetValueExW,
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E073F5C8 RegQueryValueExW,RegQueryValueExW,CryptUnprotectData,GetLastError,LocalFree,
                      Source: elBAfme5gQ.dllStatic PE information: TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT, HIGH_ENTROPY_VA
                      Source: Binary string: DmNotificationBroker.pdb source: DmNotificationBroker.exe, 00000015.00000000.431514520.00007FF793F65000.00000002.00000001.01000000.0000000B.sdmp, DmNotificationBroker.exe, 00000015.00000002.455649631.00007FF793F65000.00000002.00000001.01000000.0000000B.sdmp, DmNotificationBroker.exe, 0000001F.00000000.502738188.00007FF6DC635000.00000002.00000001.01000000.0000000F.sdmp, DmNotificationBroker.exe, 0000001F.00000002.529497507.00007FF6DC635000.00000002.00000001.01000000.0000000F.sdmp, DmNotificationBroker.exe0.4.dr, DmNotificationBroker.exe.4.dr
                      Source: Binary string: PresentationSettings.pdb source: PresentationSettings.exe, 00000012.00000002.417779681.00007FF7B4466000.00000002.00000001.01000000.00000009.sdmp, PresentationSettings.exe, 00000012.00000000.394587436.00007FF7B4466000.00000002.00000001.01000000.00000009.sdmp, PresentationSettings.exe.4.dr
                      Source: Binary string: DmNotificationBroker.pdbGCTL source: DmNotificationBroker.exe, 00000015.00000000.431514520.00007FF793F65000.00000002.00000001.01000000.0000000B.sdmp, DmNotificationBroker.exe, 00000015.00000002.455649631.00007FF793F65000.00000002.00000001.01000000.0000000B.sdmp, DmNotificationBroker.exe, 0000001F.00000000.502738188.00007FF6DC635000.00000002.00000001.01000000.0000000F.sdmp, DmNotificationBroker.exe, 0000001F.00000002.529497507.00007FF6DC635000.00000002.00000001.01000000.0000000F.sdmp, DmNotificationBroker.exe0.4.dr, DmNotificationBroker.exe.4.dr
                      Source: Binary string: Wfs.pdbGCTL source: WFS.exe, 00000019.00000002.489112517.00007FF7E075C000.00000002.00000001.01000000.0000000D.sdmp, WFS.exe, 00000019.00000000.461037552.00007FF7E075C000.00000002.00000001.01000000.0000000D.sdmp, WFS.exe.4.dr
                      Source: Binary string: Wfs.pdb source: WFS.exe, 00000019.00000002.489112517.00007FF7E075C000.00000002.00000001.01000000.0000000D.sdmp, WFS.exe, 00000019.00000000.461037552.00007FF7E075C000.00000002.00000001.01000000.0000000D.sdmp, WFS.exe.4.dr
                      Source: Binary string: PresentationSettings.pdbGCTL source: PresentationSettings.exe, 00000012.00000002.417779681.00007FF7B4466000.00000002.00000001.01000000.00000009.sdmp, PresentationSettings.exe, 00000012.00000000.394587436.00007FF7B4466000.00000002.00000001.01000000.00000009.sdmp, PresentationSettings.exe.4.dr
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6471ED10 FindFirstFileExW,
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B4464518 PathAppendW,FindFirstFileW,PathAppendW,GetLastError,PathFindExtensionW,StrCmpICW,FindNextFileW,FindClose,GetLastError,
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669CED10 FindFirstFileExW,
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6697ED10 FindFirstFileExW,
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E07071B0 #626,memset,#6887,#1122,#1287,FindFirstFileW,GetLastError,#6886,#1122,#1287,#1287,#624,EnterCriticalSection,LeaveCriticalSection,FindNextFileW,GetLastError,FindClose,#6887,#1040,SendMessageW,
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E07389BC wcscpy_s,wcscat_s,FindFirstFileW,_wcsicmp,FindNextFileW,GetLastError,FindClose,
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E0705B40 #626,#626,memset,memset,#6887,#620,#1122,#1040,#1287,FindFirstFileW,GetLastError,#6886,#620,#1122,#1040,#1287,#1287,#620,EnterCriticalSection,LeaveCriticalSection,FindNextFileW,GetLastError,FindClose,#6887,#1040,#1040,SendMessageW,
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E07230D8 SendMessageW,GetLastError,wcschr,#626,#2846,FindFirstFileW,GetLastError,#1040,#626,memset,GetLastError,ReadFile,GetLastError,CloseHandle,FindNextFileW,GetLastError,FindClose,GetLastError,#1040,CloseHandle,SendMessageW,#4262,#640,#1122,#1040,#6395,#6395,
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E06FF0AC GetTempPathW,GetLastError,wcsrchr,_wcsnset,GetCurrentProcessId,FindFirstFileW,GetLastError,DeleteFileW,GetLastError,FindNextFileW,GetLastError,GetLastError,FindClose,

                      E-Banking Fraud

                      barindex
                      Source: Yara matchFile source: 18.2.PresentationSettings.exe.7ffc66970000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 25.2.WFS.exe.7ffc66970000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 2.2.rundll32.exe.7ffc646c0000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 31.2.DmNotificationBroker.exe.7ffc67880000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.7ffc646c0000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.7ffc646c0000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll64.exe.7ffc646c0000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.rundll32.exe.7ffc646c0000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 21.2.DmNotificationBroker.exe.7ffc66920000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000015.00000002.455715001.00007FFC66921000.00000020.00000001.01000000.0000000C.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.382683427.00007FFC646C1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000001F.00000002.529541082.00007FFC67881000.00000020.00000001.01000000.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000002.279312817.00007FFC646C1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000003.00000002.265252224.00007FFC646C1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.285761236.00007FFC646C1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000019.00000002.489503728.00007FFC66971000.00000020.00000001.01000000.0000000E.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000012.00000002.417833376.00007FFC66971000.00000020.00000001.01000000.0000000A.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.271180425.00007FFC646C1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472D520
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64727650
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6471DDC0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC647097D0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F5020
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64713150
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E7880
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F59F0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6470CA50
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646FAA70
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6470A2C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F3CF0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D3CD0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F5CD0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646EAC80
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D9D70
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472E48B
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472A490
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472E494
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472E49D
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64722CA0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472E4A6
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E3D50
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646ED550
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472E4AD
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472E4B6
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F1D30
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F0D10
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D65E0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D95C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F25C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64710650
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646CC5A0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D8670
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646CDE20
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C1620
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E3610
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F2E10
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64720F30
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646EF6B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F06A0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64725760
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C6E90
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6473BF6F
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64720770
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C7E80
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646DE770
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E2F50
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472A6B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64727EC0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E872B
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E6FE0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646DA7D0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D8FC0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64715840
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646EE7B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C6790
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6470F870
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472C780
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6473EF80
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646FF870
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6473B7A0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E5050
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646EC030
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F0020
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C1010
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64734FF0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E4800
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C18D0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D08B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64726950
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472B960
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646DD890
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E4140
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F6130
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646DE110
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E3910
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646CB100
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646EF1F0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F91F0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F89F0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F21D0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E69C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646DE9B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E11B0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646EE9A0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472B260
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F9990
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C2980
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646FB250
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C7A40
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E82E0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646FBAE0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E92C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64725B50
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646EDAA0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F4360
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC647282A0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472AAA0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C5350
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646E3340
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D8340
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6471F2C0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F1B30
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646CBB20
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64722AE0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646EA310
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64727AF0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646F0300
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472E400
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D23F0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64729410
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64724390
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64714BC0
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D5420
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646C5C20
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC646D7410
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B4464374
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B4452D90
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B4453278
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B4463034
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B445441C
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B446354C
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B4463CDC
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B44536DC
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B445649C
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B44556A4
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FF7B44639C8
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A5020
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669B97D0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DD520
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A5CD0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D7650
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669CDDC0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669ABAE0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669BA2C0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669C3150
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66997880
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669AAA70
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669BCA50
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A59F0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699872B
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D0F30
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D5760
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D0770
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6698E770
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669EBF6F
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66992F50
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A06A0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DA6B0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699F6B0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66977E80
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66976E90
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D7EC0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669F0820
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A0020
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699C030
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66994800
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66971010
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669AF870
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669BF870
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669C5840
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66995050
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669EB7A0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699E7B0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DC780
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669EEF80
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66976790
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66996FE0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669E4FF0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66988FC0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6698A7D0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669C8D20
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A1D30
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A0D10
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66989D70
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66993D50
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699D550
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DE4A6
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D2CA0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DE49D
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DE4B6
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DE4AD
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DE48B
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699AC80
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DE494
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DA490
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A3CF0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66983CD0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66971620
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6697DE20
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66993610
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A2E10
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66988670
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669C0650
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6697C5A0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669EC590
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669865E0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669895C0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A25C0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6697BB20
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A1B30
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A0300
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699A310
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A4360
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66993340
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66988340
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66975350
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D5B50
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D82A0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DAAA0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699DAA0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D2AE0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669982E0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D7AF0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669CF2C0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669992C0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669C22C0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66975C20
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66985420
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DE400
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669EFC00
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66987410
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D9410
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D4390
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669823F0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669C4BC0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A6130
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6697B100
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6698E110
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66993910
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DB960
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66994140
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669D6950
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669808B0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669EC8B1
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6698D890
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669EC0EB
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669718D0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DB260
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66977A40
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669AB250
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699E9A0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6698E9B0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669911B0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66972980
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A9990
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC6699F1F0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A91F0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A89F0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669969C0
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A21D0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66955020
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669697D0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698D520
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66955CD0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66987650
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6697DDC0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6695BAE0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6696A2C0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66973150
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66947880
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6695AA70
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6696CA50
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669559F0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694872B
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66980F30
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66985760
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66980770
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6693E770
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6699BF6F
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66942F50
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669506A0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694F6B0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698A6B0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66927E80
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66926E90
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66987EC0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66950020
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669A0820
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694C030
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66944800
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66921010
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6695F870
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6696F870
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66975840
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66945050
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6699B7A0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694E7B0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698C780
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6699EF80
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66926790
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66946FE0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66994FF0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66938FC0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6693A7D0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66978D20
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66951D30
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66950D10
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66939D70
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694D550
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66943D50
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698E4A6
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66982CA0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698E49D
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698E4B6
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698E4AD
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694AC80
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698E48B
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698E494
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698A490
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66953CF0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66933CD0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66921620
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6692DE20
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66952E10
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66943610
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66938670
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66970650
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6692C5A0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6699C590
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669365E0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669525C0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669395C0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6692BB20
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66951B30
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66950300
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694A310
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66954360
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66943340
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66938340
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66985B50
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66925350
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694DAA0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669882A0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698AAA0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669482E0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66982AE0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66987AF0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669492C0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669722C0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6697F2C0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66925C20
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66935420
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698E400
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6699FC00
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66937410
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66989410
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66984390
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669323F0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66974BC0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66956130
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6692B100
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6693E110
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66943910
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698B960
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66944140
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66986950
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669308B0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6699C8B1
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6693D890
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6699C0EB
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669218D0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698B260
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66927A40
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6695B250
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694E9A0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6693E9B0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669411B0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66922980
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66959990
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6694F1F0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669591F0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669589F0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669469C0
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC669521D0
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E073A1B0
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E0736180
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E06F3258
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E06F9250
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E071B3A8
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E073B410
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E072D320
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E072A380
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E072E4C0
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E07354E0
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E071541C
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E06FC4F8
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E0752440
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E07415BC
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E072F5D0
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E06F85B0
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E0730630
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E06FB6C4
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E06F5738
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E071F71C
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E07318CC
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E073B904
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E071E840
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E06FC974
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E073A9E0
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E0713940
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E07019D0
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E0738AB0
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E06F3A30
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E0707AF0
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E0736C00
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E073FC0C
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E0735C10
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E072AB1C
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E072FB30
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E0752B6C
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E0710B80
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E06F4CD4
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E06F3A30
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E0733E1C
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E0736E50
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E0751F60
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E073B0DC
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: 25_2_00007FF7E072C060
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeCode function: String function: 00007FF7E06F38C8 appears 261 times
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC6472D520 NtQuerySystemInformation,RtlAllocateHeap,
                      Source: C:\Windows\System32\loaddll64.exeCode function: 0_2_00007FFC64707770 NtClose,
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669B7770 NtClose,
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC66995F40 NtCreateSection,NtMapViewOfSection,NtUnmapViewOfSection,NtDuplicateObject,NtDuplicateObject,
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A8060 NtReadVirtualMemory,
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669DD520 NtQuerySystemInformation,
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669A5CD0 RtlAddVectoredContinueHandler,VirtualProtect,VirtualProtect,RtlCreateUserThread,NtClose,
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669AC4D0 CreateFileMappingW,VirtualAlloc,NtMapViewOfSection,NtUnmapViewOfSection,NtDuplicateObject,NtDuplicateObject,
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669ACE20 NtDuplicateObject,NtClose,
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669ABAE0 NtReadVirtualMemory,RtlQueueApcWow64Thread,
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669BF150 NtDelayExecution,
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeCode function: 18_2_00007FFC669AAA70 VirtualAlloc,NtDuplicateObject,RtlQueueApcWow64Thread,
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66967770 NtClose,
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66945F40 NtCreateSection,NtMapViewOfSection,NtUnmapViewOfSection,NtDuplicateObject,NtDuplicateObject,
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6698D520 NtQuerySystemInformation,RtlAllocateHeap,
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC66955CD0 RtlAddVectoredContinueHandler,VirtualProtect,VirtualProtect,RtlCreateUserThread,NtClose,
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6695C4D0 CreateFileMappingW,VirtualAlloc,NtMapViewOfSection,NtUnmapViewOfSection,NtDuplicateObject,NtDuplicateObject,
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6695BAE0 NtReadVirtualMemory,
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeCode function: 21_2_00007FFC6695AA70 VirtualAlloc,NtDuplicateObject,RtlQueueApcWow64Thread,
                      Source: DmNotificationBroker.exe.4.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
                      Source: DmNotificationBroker.exe0.4.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
                      Source: elBAfme5gQ.dllBinary or memory string: OriginalFilenamedpnhupnp.dJ vs elBAfme5gQ.dll
                      Source: PresentationSettings.exe.4.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                      Source: PresentationSettings.exe.4.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                      Source: PresentationSettings.exe.4.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                      Source: PresentationSettings.exe.4.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                      Source: PresentationSettings.exe.4.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                      Source: PresentationSettings.exe.4.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                      Source: PresentationSettings.exe.4.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                      Source: PresentationSettings.exe.4.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                      Source: WFS.exe.4.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                      Source: WFS.exe.4.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                      Source: WFS.exe.4.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                      Source: C:\Windows\System32\loaddll64.exeSection loaded: kernel34.dll
                      Source: C:\Windows\explorer.exeSection loaded: kernel34.dll
                      Source: C:\Windows\explorer.exeSection loaded: windows.globalization.dll
                      Source: C:\Windows\explorer.exeSection loaded: capabilityaccessmanagerclient.dll
                      Source: C:\Users\user\AppData\Local\A3MiXbeK\PresentationSettings.exeSection loaded: kernel34.dll
                      Source: C:\Users\user\AppData\Local\WRsLe\DmNotificationBroker.exeSection loaded: kernel34.dll
                      Source: C:\Users\user\AppData\Local\daH0n9\WFS.exeSection loaded: kernel34.dll
                      Source: C:\Users\user\AppData\Local\pEcAZnNU3\DmNotificationBroker.exeSection loaded: kernel34.dll
                      Source: elBAfme5gQ.dllStatic PE information: Number of sections : 70 > 10
                      Source: DUI70.dll0.4.drStatic PE information: Number of sections : 71 > 10
                      Source: DUI70.dll.4.drStatic PE information: Number of sections : 71 > 10
                      Source: WINMM.dll.4.drStatic PE information: Number of sections : 71 > 10
                      Source: credui.dll.4.drStatic PE information: Number of sections : 71 > 10
                      Source: elBAfme5gQ.dllStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                      Source: WINMM.dll.4.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                      Source: DUI70.dll.4.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                      Source: credui.dll.4.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                      Source: DUI70.dll0.4.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                      Source: elBAfme5gQ.dllVirustotal: Detection: 62%
                      Source: elBAfme5gQ.dllMetadefender: Detection: 65%
                      Source: elBAfme5gQ.dllReversingLabs: Detection: 88%
                      Source: elBAfme5gQ.dllStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                      Source: C:\Windows\System32\loaddll64.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers