VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Dropper, Trojan |
Ztarter.exe
Windows Exe (x86-32)
Created at 2019-12-19T20:53:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5P5NRG~1\AppData\Local\Temp\svchost.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x61c598 |
Size Of Code | 0x21b800 |
Size Of Initialized Data | 0x46600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-12-17 06:57:32+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Host Process for Windows Services |
FileVersion | 6.1.7601.23403 (win7sp1_ldr.160325-0600) |
InternalName | svchost.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | svchost.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7601.23403 |
Sections (11)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x219e74 | 0x21a000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.48 |
.itext | 0x61b000 | 0x161c | 0x1800 | 0x21a400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.99 |
.data | 0x61d000 | 0x87c8 | 0x8800 | 0x21bc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.7 |
.bss | 0x626000 | 0x77f0 | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x62e000 | 0x31b0 | 0x3200 | 0x224400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.32 |
.didata | 0x632000 | 0xb3c | 0xc00 | 0x227600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.1 |
.edata | 0x633000 | 0x9c | 0x200 | 0x228200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.95 |
.tls | 0x634000 | 0x48 | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rdata | 0x635000 | 0x5d | 0x200 | 0x228400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.37 |
.reloc | 0x636000 | 0x2f958 | 0x2fa00 | 0x228600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.72 |
.rsrc | 0x666000 | 0xa146 | 0xa200 | 0x258000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.3 |
Imports (11)
»
kernel32.dll (119)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFileType | 0x0 | 0x62e8a8 | 0x22e0f0 | 0x2244f0 | 0x0 |
GetACP | 0x0 | 0x62e8ac | 0x22e0f4 | 0x2244f4 | 0x0 |
CloseHandle | 0x0 | 0x62e8b0 | 0x22e0f8 | 0x2244f8 | 0x0 |
LocalFree | 0x0 | 0x62e8b4 | 0x22e0fc | 0x2244fc | 0x0 |
GetCurrentProcessId | 0x0 | 0x62e8b8 | 0x22e100 | 0x224500 | 0x0 |
SizeofResource | 0x0 | 0x62e8bc | 0x22e104 | 0x224504 | 0x0 |
VirtualProtect | 0x0 | 0x62e8c0 | 0x22e108 | 0x224508 | 0x0 |
QueryPerformanceFrequency | 0x0 | 0x62e8c4 | 0x22e10c | 0x22450c | 0x0 |
IsDebuggerPresent | 0x0 | 0x62e8c8 | 0x22e110 | 0x224510 | 0x0 |
FindNextFileW | 0x0 | 0x62e8cc | 0x22e114 | 0x224514 | 0x0 |
GetFullPathNameW | 0x0 | 0x62e8d0 | 0x22e118 | 0x224518 | 0x0 |
VirtualFree | 0x0 | 0x62e8d4 | 0x22e11c | 0x22451c | 0x0 |
ExitProcess | 0x0 | 0x62e8d8 | 0x22e120 | 0x224520 | 0x0 |
HeapAlloc | 0x0 | 0x62e8dc | 0x22e124 | 0x224524 | 0x0 |
GetCPInfoExW | 0x0 | 0x62e8e0 | 0x22e128 | 0x224528 | 0x0 |
RtlUnwind | 0x0 | 0x62e8e4 | 0x22e12c | 0x22452c | 0x0 |
GetCPInfo | 0x0 | 0x62e8e8 | 0x22e130 | 0x224530 | 0x0 |
EnumSystemLocalesW | 0x0 | 0x62e8ec | 0x22e134 | 0x224534 | 0x0 |
GetStdHandle | 0x0 | 0x62e8f0 | 0x22e138 | 0x224538 | 0x0 |
FileTimeToLocalFileTime | 0x0 | 0x62e8f4 | 0x22e13c | 0x22453c | 0x0 |
GetModuleHandleW | 0x0 | 0x62e8f8 | 0x22e140 | 0x224540 | 0x0 |
FreeLibrary | 0x0 | 0x62e8fc | 0x22e144 | 0x224544 | 0x0 |
TryEnterCriticalSection | 0x0 | 0x62e900 | 0x22e148 | 0x224548 | 0x0 |
HeapDestroy | 0x0 | 0x62e904 | 0x22e14c | 0x22454c | 0x0 |
FileTimeToDosDateTime | 0x0 | 0x62e908 | 0x22e150 | 0x224550 | 0x0 |
ReadFile | 0x0 | 0x62e90c | 0x22e154 | 0x224554 | 0x0 |
HeapSize | 0x0 | 0x62e910 | 0x22e158 | 0x224558 | 0x0 |
GetLastError | 0x0 | 0x62e914 | 0x22e15c | 0x22455c | 0x0 |
GetModuleFileNameW | 0x0 | 0x62e918 | 0x22e160 | 0x224560 | 0x0 |
SetLastError | 0x0 | 0x62e91c | 0x22e164 | 0x224564 | 0x0 |
GlobalAlloc | 0x0 | 0x62e920 | 0x22e168 | 0x224568 | 0x0 |
GlobalUnlock | 0x0 | 0x62e924 | 0x22e16c | 0x22456c | 0x0 |
FindResourceW | 0x0 | 0x62e928 | 0x22e170 | 0x224570 | 0x0 |
CreateThread | 0x0 | 0x62e92c | 0x22e174 | 0x224574 | 0x0 |
CompareStringW | 0x0 | 0x62e930 | 0x22e178 | 0x224578 | 0x0 |
CreateMutexW | 0x0 | 0x62e934 | 0x22e17c | 0x22457c | 0x0 |
LoadLibraryA | 0x0 | 0x62e938 | 0x22e180 | 0x224580 | 0x0 |
ResetEvent | 0x0 | 0x62e93c | 0x22e184 | 0x224584 | 0x0 |
MulDiv | 0x0 | 0x62e940 | 0x22e188 | 0x224588 | 0x0 |
FreeResource | 0x0 | 0x62e944 | 0x22e18c | 0x22458c | 0x0 |
GetVersion | 0x0 | 0x62e948 | 0x22e190 | 0x224590 | 0x0 |
RaiseException | 0x0 | 0x62e94c | 0x22e194 | 0x224594 | 0x0 |
MoveFileW | 0x0 | 0x62e950 | 0x22e198 | 0x224598 | 0x0 |
GlobalAddAtomW | 0x0 | 0x62e954 | 0x22e19c | 0x22459c | 0x0 |
FormatMessageW | 0x0 | 0x62e958 | 0x22e1a0 | 0x2245a0 | 0x0 |
SwitchToThread | 0x0 | 0x62e95c | 0x22e1a4 | 0x2245a4 | 0x0 |
GetExitCodeThread | 0x0 | 0x62e960 | 0x22e1a8 | 0x2245a8 | 0x0 |
GetCurrentThread | 0x0 | 0x62e964 | 0x22e1ac | 0x2245ac | 0x0 |
LoadLibraryExW | 0x0 | 0x62e968 | 0x22e1b0 | 0x2245b0 | 0x0 |
LockResource | 0x0 | 0x62e96c | 0x22e1b4 | 0x2245b4 | 0x0 |
GetCurrentThreadId | 0x0 | 0x62e970 | 0x22e1b8 | 0x2245b8 | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x62e974 | 0x22e1bc | 0x2245bc | 0x0 |
VirtualQuery | 0x0 | 0x62e978 | 0x22e1c0 | 0x2245c0 | 0x0 |
GlobalFindAtomW | 0x0 | 0x62e97c | 0x22e1c4 | 0x2245c4 | 0x0 |
VirtualQueryEx | 0x0 | 0x62e980 | 0x22e1c8 | 0x2245c8 | 0x0 |
GlobalFree | 0x0 | 0x62e984 | 0x22e1cc | 0x2245cc | 0x0 |
Sleep | 0x0 | 0x62e988 | 0x22e1d0 | 0x2245d0 | 0x0 |
EnterCriticalSection | 0x0 | 0x62e98c | 0x22e1d4 | 0x2245d4 | 0x0 |
SetFilePointer | 0x0 | 0x62e990 | 0x22e1d8 | 0x2245d8 | 0x0 |
LoadResource | 0x0 | 0x62e994 | 0x22e1dc | 0x2245dc | 0x0 |
SuspendThread | 0x0 | 0x62e998 | 0x22e1e0 | 0x2245e0 | 0x0 |
GetTickCount | 0x0 | 0x62e99c | 0x22e1e4 | 0x2245e4 | 0x0 |
GetFileSize | 0x0 | 0x62e9a0 | 0x22e1e8 | 0x2245e8 | 0x0 |
GetStartupInfoW | 0x0 | 0x62e9a4 | 0x22e1ec | 0x2245ec | 0x0 |
GlobalDeleteAtom | 0x0 | 0x62e9a8 | 0x22e1f0 | 0x2245f0 | 0x0 |
GetFileAttributesW | 0x0 | 0x62e9ac | 0x22e1f4 | 0x2245f4 | 0x0 |
InitializeCriticalSection | 0x0 | 0x62e9b0 | 0x22e1f8 | 0x2245f8 | 0x0 |
GetThreadPriority | 0x0 | 0x62e9b4 | 0x22e1fc | 0x2245fc | 0x0 |
GetCurrentProcess | 0x0 | 0x62e9b8 | 0x22e200 | 0x224600 | 0x0 |
SetThreadPriority | 0x0 | 0x62e9bc | 0x22e204 | 0x224604 | 0x0 |
GlobalLock | 0x0 | 0x62e9c0 | 0x22e208 | 0x224608 | 0x0 |
VirtualAlloc | 0x0 | 0x62e9c4 | 0x22e20c | 0x22460c | 0x0 |
GetCommandLineW | 0x0 | 0x62e9c8 | 0x22e210 | 0x224610 | 0x0 |
GetSystemInfo | 0x0 | 0x62e9cc | 0x22e214 | 0x224614 | 0x0 |
LeaveCriticalSection | 0x0 | 0x62e9d0 | 0x22e218 | 0x224618 | 0x0 |
GetProcAddress | 0x0 | 0x62e9d4 | 0x22e21c | 0x22461c | 0x0 |
ResumeThread | 0x0 | 0x62e9d8 | 0x22e220 | 0x224620 | 0x0 |
GetVersionExW | 0x0 | 0x62e9dc | 0x22e224 | 0x224624 | 0x0 |
VerifyVersionInfoW | 0x0 | 0x62e9e0 | 0x22e228 | 0x224628 | 0x0 |
HeapCreate | 0x0 | 0x62e9e4 | 0x22e22c | 0x22462c | 0x0 |
GetDiskFreeSpaceW | 0x0 | 0x62e9e8 | 0x22e230 | 0x224630 | 0x0 |
VerSetConditionMask | 0x0 | 0x62e9ec | 0x22e234 | 0x224634 | 0x0 |
FindFirstFileW | 0x0 | 0x62e9f0 | 0x22e238 | 0x224638 | 0x0 |
GetUserDefaultUILanguage | 0x0 | 0x62e9f4 | 0x22e23c | 0x22463c | 0x0 |
GetConsoleOutputCP | 0x0 | 0x62e9f8 | 0x22e240 | 0x224640 | 0x0 |
GetConsoleCP | 0x0 | 0x62e9fc | 0x22e244 | 0x224644 | 0x0 |
lstrlenW | 0x0 | 0x62ea00 | 0x22e248 | 0x224648 | 0x0 |
SetEndOfFile | 0x0 | 0x62ea04 | 0x22e24c | 0x22464c | 0x0 |
QueryPerformanceCounter | 0x0 | 0x62ea08 | 0x22e250 | 0x224650 | 0x0 |
HeapFree | 0x0 | 0x62ea0c | 0x22e254 | 0x224654 | 0x0 |
WideCharToMultiByte | 0x0 | 0x62ea10 | 0x22e258 | 0x224658 | 0x0 |
FindClose | 0x0 | 0x62ea14 | 0x22e25c | 0x22465c | 0x0 |
MultiByteToWideChar | 0x0 | 0x62ea18 | 0x22e260 | 0x224660 | 0x0 |
LoadLibraryW | 0x0 | 0x62ea1c | 0x22e264 | 0x224664 | 0x0 |
SetEvent | 0x0 | 0x62ea20 | 0x22e268 | 0x224668 | 0x0 |
GetLocaleInfoW | 0x0 | 0x62ea24 | 0x22e26c | 0x22466c | 0x0 |
CreateFileW | 0x0 | 0x62ea28 | 0x22e270 | 0x224670 | 0x0 |
EnumResourceNamesW | 0x0 | 0x62ea2c | 0x22e274 | 0x224674 | 0x0 |
DeleteFileW | 0x0 | 0x62ea30 | 0x22e278 | 0x224678 | 0x0 |
IsDBCSLeadByteEx | 0x0 | 0x62ea34 | 0x22e27c | 0x22467c | 0x0 |
GetEnvironmentVariableW | 0x0 | 0x62ea38 | 0x22e280 | 0x224680 | 0x0 |
GetLocalTime | 0x0 | 0x62ea3c | 0x22e284 | 0x224684 | 0x0 |
WaitForSingleObject | 0x0 | 0x62ea40 | 0x22e288 | 0x224688 | 0x0 |
WriteFile | 0x0 | 0x62ea44 | 0x22e28c | 0x22468c | 0x0 |
ExitThread | 0x0 | 0x62ea48 | 0x22e290 | 0x224690 | 0x0 |
DeleteCriticalSection | 0x0 | 0x62ea4c | 0x22e294 | 0x224694 | 0x0 |
GetDateFormatW | 0x0 | 0x62ea50 | 0x22e298 | 0x224698 | 0x0 |
TlsGetValue | 0x0 | 0x62ea54 | 0x22e29c | 0x22469c | 0x0 |
SetErrorMode | 0x0 | 0x62ea58 | 0x22e2a0 | 0x2246a0 | 0x0 |
IsValidLocale | 0x0 | 0x62ea5c | 0x22e2a4 | 0x2246a4 | 0x0 |
TlsSetValue | 0x0 | 0x62ea60 | 0x22e2a8 | 0x2246a8 | 0x0 |
GetSystemDefaultUILanguage | 0x0 | 0x62ea64 | 0x22e2ac | 0x2246ac | 0x0 |
EnumCalendarInfoW | 0x0 | 0x62ea68 | 0x22e2b0 | 0x2246b0 | 0x0 |
LocalAlloc | 0x0 | 0x62ea6c | 0x22e2b4 | 0x2246b4 | 0x0 |
RemoveDirectoryW | 0x0 | 0x62ea70 | 0x22e2b8 | 0x2246b8 | 0x0 |
CreateEventW | 0x0 | 0x62ea74 | 0x22e2bc | 0x2246bc | 0x0 |
WaitForMultipleObjectsEx | 0x0 | 0x62ea78 | 0x22e2c0 | 0x2246c0 | 0x0 |
SetThreadLocale | 0x0 | 0x62ea7c | 0x22e2c4 | 0x2246c4 | 0x0 |
GetThreadLocale | 0x0 | 0x62ea80 | 0x22e2c8 | 0x2246c8 | 0x0 |
winspool.drv (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DocumentPropertiesW | 0x0 | 0x62ea88 | 0x22e2d0 | 0x2246d0 | 0x0 |
ClosePrinter | 0x0 | 0x62ea8c | 0x22e2d4 | 0x2246d4 | 0x0 |
OpenPrinterW | 0x0 | 0x62ea90 | 0x22e2d8 | 0x2246d8 | 0x0 |
GetDefaultPrinterW | 0x0 | 0x62ea94 | 0x22e2dc | 0x2246dc | 0x0 |
EnumPrintersW | 0x0 | 0x62ea98 | 0x22e2e0 | 0x2246e0 | 0x0 |
comctl32.dll (35)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_GetImageInfo | 0x0 | 0x62eaa0 | 0x22e2e8 | 0x2246e8 | 0x0 |
FlatSB_SetScrollInfo | 0x0 | 0x62eaa4 | 0x22e2ec | 0x2246ec | 0x0 |
ImageList_DragMove | 0x0 | 0x62eaa8 | 0x22e2f0 | 0x2246f0 | 0x0 |
ImageList_Destroy | 0x0 | 0x62eaac | 0x22e2f4 | 0x2246f4 | 0x0 |
_TrackMouseEvent | 0x0 | 0x62eab0 | 0x22e2f8 | 0x2246f8 | 0x0 |
ImageList_DragShowNolock | 0x0 | 0x62eab4 | 0x22e2fc | 0x2246fc | 0x0 |
ImageList_Add | 0x0 | 0x62eab8 | 0x22e300 | 0x224700 | 0x0 |
FlatSB_SetScrollProp | 0x0 | 0x62eabc | 0x22e304 | 0x224704 | 0x0 |
ImageList_GetDragImage | 0x0 | 0x62eac0 | 0x22e308 | 0x224708 | 0x0 |
ImageList_Create | 0x0 | 0x62eac4 | 0x22e30c | 0x22470c | 0x0 |
ImageList_EndDrag | 0x0 | 0x62eac8 | 0x22e310 | 0x224710 | 0x0 |
ImageList_DrawEx | 0x0 | 0x62eacc | 0x22e314 | 0x224714 | 0x0 |
ImageList_SetImageCount | 0x0 | 0x62ead0 | 0x22e318 | 0x224718 | 0x0 |
FlatSB_GetScrollPos | 0x0 | 0x62ead4 | 0x22e31c | 0x22471c | 0x0 |
FlatSB_SetScrollPos | 0x0 | 0x62ead8 | 0x22e320 | 0x224720 | 0x0 |
InitializeFlatSB | 0x0 | 0x62eadc | 0x22e324 | 0x224724 | 0x0 |
ImageList_Copy | 0x0 | 0x62eae0 | 0x22e328 | 0x224728 | 0x0 |
FlatSB_GetScrollInfo | 0x0 | 0x62eae4 | 0x22e32c | 0x22472c | 0x0 |
ImageList_Write | 0x0 | 0x62eae8 | 0x22e330 | 0x224730 | 0x0 |
ImageList_SetBkColor | 0x0 | 0x62eaec | 0x22e334 | 0x224734 | 0x0 |
ImageList_GetBkColor | 0x0 | 0x62eaf0 | 0x22e338 | 0x224738 | 0x0 |
ImageList_BeginDrag | 0x0 | 0x62eaf4 | 0x22e33c | 0x22473c | 0x0 |
ImageList_GetIcon | 0x0 | 0x62eaf8 | 0x22e340 | 0x224740 | 0x0 |
ImageList_Replace | 0x0 | 0x62eafc | 0x22e344 | 0x224744 | 0x0 |
ImageList_GetImageCount | 0x0 | 0x62eb00 | 0x22e348 | 0x224748 | 0x0 |
ImageList_DragEnter | 0x0 | 0x62eb04 | 0x22e34c | 0x22474c | 0x0 |
ImageList_GetIconSize | 0x0 | 0x62eb08 | 0x22e350 | 0x224750 | 0x0 |
ImageList_SetIconSize | 0x0 | 0x62eb0c | 0x22e354 | 0x224754 | 0x0 |
ImageList_Read | 0x0 | 0x62eb10 | 0x22e358 | 0x224758 | 0x0 |
ImageList_DragLeave | 0x0 | 0x62eb14 | 0x22e35c | 0x22475c | 0x0 |
ImageList_LoadImageW | 0x0 | 0x62eb18 | 0x22e360 | 0x224760 | 0x0 |
ImageList_Draw | 0x0 | 0x62eb1c | 0x22e364 | 0x224764 | 0x0 |
ImageList_Remove | 0x0 | 0x62eb20 | 0x22e368 | 0x224768 | 0x0 |
ImageList_ReplaceIcon | 0x0 | 0x62eb24 | 0x22e36c | 0x22476c | 0x0 |
ImageList_SetOverlayImage | 0x0 | 0x62eb28 | 0x22e370 | 0x224770 | 0x0 |
shell32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Shell_NotifyIconW | 0x0 | 0x62eb30 | 0x22e378 | 0x224778 | 0x0 |
SHGetSpecialFolderPathW | 0x0 | 0x62eb34 | 0x22e37c | 0x22477c | 0x0 |
ShellExecuteW | 0x0 | 0x62eb38 | 0x22e380 | 0x224780 | 0x0 |
ole32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IsEqualGUID | 0x0 | 0x62eb40 | 0x22e388 | 0x224788 | 0x0 |
OleInitialize | 0x0 | 0x62eb44 | 0x22e38c | 0x22478c | 0x0 |
OleUninitialize | 0x0 | 0x62eb48 | 0x22e390 | 0x224790 | 0x0 |
CoInitialize | 0x0 | 0x62eb4c | 0x22e394 | 0x224794 | 0x0 |
CoCreateInstance | 0x0 | 0x62eb50 | 0x22e398 | 0x224798 | 0x0 |
CoUninitialize | 0x0 | 0x62eb54 | 0x22e39c | 0x22479c | 0x0 |
CoTaskMemFree | 0x0 | 0x62eb58 | 0x22e3a0 | 0x2247a0 | 0x0 |
CoTaskMemAlloc | 0x0 | 0x62eb5c | 0x22e3a4 | 0x2247a4 | 0x0 |
version.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFileVersionInfoSizeW | 0x0 | 0x62eb64 | 0x22e3ac | 0x2247ac | 0x0 |
VerQueryValueW | 0x0 | 0x62eb68 | 0x22e3b0 | 0x2247b0 | 0x0 |
GetFileVersionInfoW | 0x0 | 0x62eb6c | 0x22e3b4 | 0x2247b4 | 0x0 |
user32.dll (183)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CopyImage | 0x0 | 0x62eb74 | 0x22e3bc | 0x2247bc | 0x0 |
CreateWindowExW | 0x0 | 0x62eb78 | 0x22e3c0 | 0x2247c0 | 0x0 |
GetMenuItemInfoW | 0x0 | 0x62eb7c | 0x22e3c4 | 0x2247c4 | 0x0 |
SetMenuItemInfoW | 0x0 | 0x62eb80 | 0x22e3c8 | 0x2247c8 | 0x0 |
DefFrameProcW | 0x0 | 0x62eb84 | 0x22e3cc | 0x2247cc | 0x0 |
GetDCEx | 0x0 | 0x62eb88 | 0x22e3d0 | 0x2247d0 | 0x0 |
PeekMessageW | 0x0 | 0x62eb8c | 0x22e3d4 | 0x2247d4 | 0x0 |
MonitorFromWindow | 0x0 | 0x62eb90 | 0x22e3d8 | 0x2247d8 | 0x0 |
GetDlgCtrlID | 0x0 | 0x62eb94 | 0x22e3dc | 0x2247dc | 0x0 |
SetTimer | 0x0 | 0x62eb98 | 0x22e3e0 | 0x2247e0 | 0x0 |
WindowFromPoint | 0x0 | 0x62eb9c | 0x22e3e4 | 0x2247e4 | 0x0 |
BeginPaint | 0x0 | 0x62eba0 | 0x22e3e8 | 0x2247e8 | 0x0 |
RegisterClipboardFormatW | 0x0 | 0x62eba4 | 0x22e3ec | 0x2247ec | 0x0 |
FrameRect | 0x0 | 0x62eba8 | 0x22e3f0 | 0x2247f0 | 0x0 |
MapVirtualKeyW | 0x0 | 0x62ebac | 0x22e3f4 | 0x2247f4 | 0x0 |
IsWindowUnicode | 0x0 | 0x62ebb0 | 0x22e3f8 | 0x2247f8 | 0x0 |
RegisterWindowMessageW | 0x0 | 0x62ebb4 | 0x22e3fc | 0x2247fc | 0x0 |
FillRect | 0x0 | 0x62ebb8 | 0x22e400 | 0x224800 | 0x0 |
GetMenuStringW | 0x0 | 0x62ebbc | 0x22e404 | 0x224804 | 0x0 |
DispatchMessageW | 0x0 | 0x62ebc0 | 0x22e408 | 0x224808 | 0x0 |
CreateAcceleratorTableW | 0x0 | 0x62ebc4 | 0x22e40c | 0x22480c | 0x0 |
SendMessageA | 0x0 | 0x62ebc8 | 0x22e410 | 0x224810 | 0x0 |
DefMDIChildProcW | 0x0 | 0x62ebcc | 0x22e414 | 0x224814 | 0x0 |
EnumWindows | 0x0 | 0x62ebd0 | 0x22e418 | 0x224818 | 0x0 |
GetClassInfoW | 0x0 | 0x62ebd4 | 0x22e41c | 0x22481c | 0x0 |
ShowOwnedPopups | 0x0 | 0x62ebd8 | 0x22e420 | 0x224820 | 0x0 |
GetSystemMenu | 0x0 | 0x62ebdc | 0x22e424 | 0x224824 | 0x0 |
GetScrollRange | 0x0 | 0x62ebe0 | 0x22e428 | 0x224828 | 0x0 |
SetScrollPos | 0x0 | 0x62ebe4 | 0x22e42c | 0x22482c | 0x0 |
GetScrollPos | 0x0 | 0x62ebe8 | 0x22e430 | 0x224830 | 0x0 |
GetActiveWindow | 0x0 | 0x62ebec | 0x22e434 | 0x224834 | 0x0 |
SetActiveWindow | 0x0 | 0x62ebf0 | 0x22e438 | 0x224838 | 0x0 |
DrawEdge | 0x0 | 0x62ebf4 | 0x22e43c | 0x22483c | 0x0 |
GetKeyboardLayoutList | 0x0 | 0x62ebf8 | 0x22e440 | 0x224840 | 0x0 |
LoadBitmapW | 0x0 | 0x62ebfc | 0x22e444 | 0x224844 | 0x0 |
DrawFocusRect | 0x0 | 0x62ec00 | 0x22e448 | 0x224848 | 0x0 |
EnumChildWindows | 0x0 | 0x62ec04 | 0x22e44c | 0x22484c | 0x0 |
ReleaseCapture | 0x0 | 0x62ec08 | 0x22e450 | 0x224850 | 0x0 |
UnhookWindowsHookEx | 0x0 | 0x62ec0c | 0x22e454 | 0x224854 | 0x0 |
LoadCursorW | 0x0 | 0x62ec10 | 0x22e458 | 0x224858 | 0x0 |
GetCapture | 0x0 | 0x62ec14 | 0x22e45c | 0x22485c | 0x0 |
SetCapture | 0x0 | 0x62ec18 | 0x22e460 | 0x224860 | 0x0 |
CreatePopupMenu | 0x0 | 0x62ec1c | 0x22e464 | 0x224864 | 0x0 |
ScrollWindow | 0x0 | 0x62ec20 | 0x22e468 | 0x224868 | 0x0 |
ShowCaret | 0x0 | 0x62ec24 | 0x22e46c | 0x22486c | 0x0 |
GetMenuItemID | 0x0 | 0x62ec28 | 0x22e470 | 0x224870 | 0x0 |
GetLastActivePopup | 0x0 | 0x62ec2c | 0x22e474 | 0x224874 | 0x0 |
CharLowerBuffW | 0x0 | 0x62ec30 | 0x22e478 | 0x224878 | 0x0 |
GetSystemMetrics | 0x0 | 0x62ec34 | 0x22e47c | 0x22487c | 0x0 |
SetWindowLongW | 0x0 | 0x62ec38 | 0x22e480 | 0x224880 | 0x0 |
PostMessageW | 0x0 | 0x62ec3c | 0x22e484 | 0x224884 | 0x0 |
DrawMenuBar | 0x0 | 0x62ec40 | 0x22e488 | 0x224888 | 0x0 |
SetParent | 0x0 | 0x62ec44 | 0x22e48c | 0x22488c | 0x0 |
IsZoomed | 0x0 | 0x62ec48 | 0x22e490 | 0x224890 | 0x0 |
CharUpperBuffW | 0x0 | 0x62ec4c | 0x22e494 | 0x224894 | 0x0 |
GetClientRect | 0x0 | 0x62ec50 | 0x22e498 | 0x224898 | 0x0 |
IsChild | 0x0 | 0x62ec54 | 0x22e49c | 0x22489c | 0x0 |
ClientToScreen | 0x0 | 0x62ec58 | 0x22e4a0 | 0x2248a0 | 0x0 |
GetClipboardData | 0x0 | 0x62ec5c | 0x22e4a4 | 0x2248a4 | 0x0 |
SetClipboardData | 0x0 | 0x62ec60 | 0x22e4a8 | 0x2248a8 | 0x0 |
SetWindowPlacement | 0x0 | 0x62ec64 | 0x22e4ac | 0x2248ac | 0x0 |
IsIconic | 0x0 | 0x62ec68 | 0x22e4b0 | 0x2248b0 | 0x0 |
CallNextHookEx | 0x0 | 0x62ec6c | 0x22e4b4 | 0x2248b4 | 0x0 |
GetMonitorInfoW | 0x0 | 0x62ec70 | 0x22e4b8 | 0x2248b8 | 0x0 |
ShowWindow | 0x0 | 0x62ec74 | 0x22e4bc | 0x2248bc | 0x0 |
CheckMenuItem | 0x0 | 0x62ec78 | 0x22e4c0 | 0x2248c0 | 0x0 |
CharUpperW | 0x0 | 0x62ec7c | 0x22e4c4 | 0x2248c4 | 0x0 |
DefWindowProcW | 0x0 | 0x62ec80 | 0x22e4c8 | 0x2248c8 | 0x0 |
GetForegroundWindow | 0x0 | 0x62ec84 | 0x22e4cc | 0x2248cc | 0x0 |
SetForegroundWindow | 0x0 | 0x62ec88 | 0x22e4d0 | 0x2248d0 | 0x0 |
GetWindowTextW | 0x0 | 0x62ec8c | 0x22e4d4 | 0x2248d4 | 0x0 |
EnableWindow | 0x0 | 0x62ec90 | 0x22e4d8 | 0x2248d8 | 0x0 |
DestroyWindow | 0x0 | 0x62ec94 | 0x22e4dc | 0x2248dc | 0x0 |
IsDialogMessageW | 0x0 | 0x62ec98 | 0x22e4e0 | 0x2248e0 | 0x0 |
EndMenu | 0x0 | 0x62ec9c | 0x22e4e4 | 0x2248e4 | 0x0 |
RegisterClassW | 0x0 | 0x62eca0 | 0x22e4e8 | 0x2248e8 | 0x0 |
CharNextW | 0x0 | 0x62eca4 | 0x22e4ec | 0x2248ec | 0x0 |
GetWindowThreadProcessId | 0x0 | 0x62eca8 | 0x22e4f0 | 0x2248f0 | 0x0 |
RedrawWindow | 0x0 | 0x62ecac | 0x22e4f4 | 0x2248f4 | 0x0 |
GetDC | 0x0 | 0x62ecb0 | 0x22e4f8 | 0x2248f8 | 0x0 |
GetFocus | 0x0 | 0x62ecb4 | 0x22e4fc | 0x2248fc | 0x0 |
SetFocus | 0x0 | 0x62ecb8 | 0x22e500 | 0x224900 | 0x0 |
EndPaint | 0x0 | 0x62ecbc | 0x22e504 | 0x224904 | 0x0 |
ReleaseDC | 0x0 | 0x62ecc0 | 0x22e508 | 0x224908 | 0x0 |
MsgWaitForMultipleObjectsEx | 0x0 | 0x62ecc4 | 0x22e50c | 0x22490c | 0x0 |
LoadKeyboardLayoutW | 0x0 | 0x62ecc8 | 0x22e510 | 0x224910 | 0x0 |
GetClassLongW | 0x0 | 0x62eccc | 0x22e514 | 0x224914 | 0x0 |
ActivateKeyboardLayout | 0x0 | 0x62ecd0 | 0x22e518 | 0x224918 | 0x0 |
GetParent | 0x0 | 0x62ecd4 | 0x22e51c | 0x22491c | 0x0 |
DrawTextW | 0x0 | 0x62ecd8 | 0x22e520 | 0x224920 | 0x0 |
SetScrollRange | 0x0 | 0x62ecdc | 0x22e524 | 0x224924 | 0x0 |
MonitorFromRect | 0x0 | 0x62ece0 | 0x22e528 | 0x224928 | 0x0 |
InsertMenuItemW | 0x0 | 0x62ece4 | 0x22e52c | 0x22492c | 0x0 |
PeekMessageA | 0x0 | 0x62ece8 | 0x22e530 | 0x224930 | 0x0 |
GetPropW | 0x0 | 0x62ecec | 0x22e534 | 0x224934 | 0x0 |
SetClassLongW | 0x0 | 0x62ecf0 | 0x22e538 | 0x224938 | 0x0 |
MessageBoxW | 0x0 | 0x62ecf4 | 0x22e53c | 0x22493c | 0x0 |
MessageBeep | 0x0 | 0x62ecf8 | 0x22e540 | 0x224940 | 0x0 |
SetPropW | 0x0 | 0x62ecfc | 0x22e544 | 0x224944 | 0x0 |
RemovePropW | 0x0 | 0x62ed00 | 0x22e548 | 0x224948 | 0x0 |
UpdateWindow | 0x0 | 0x62ed04 | 0x22e54c | 0x22494c | 0x0 |
GetSubMenu | 0x0 | 0x62ed08 | 0x22e550 | 0x224950 | 0x0 |
MsgWaitForMultipleObjects | 0x0 | 0x62ed0c | 0x22e554 | 0x224954 | 0x0 |
DestroyMenu | 0x0 | 0x62ed10 | 0x22e558 | 0x224958 | 0x0 |
DestroyIcon | 0x0 | 0x62ed14 | 0x22e55c | 0x22495c | 0x0 |
SetWindowsHookExW | 0x0 | 0x62ed18 | 0x22e560 | 0x224960 | 0x0 |
EmptyClipboard | 0x0 | 0x62ed1c | 0x22e564 | 0x224964 | 0x0 |
IsWindowVisible | 0x0 | 0x62ed20 | 0x22e568 | 0x224968 | 0x0 |
DispatchMessageA | 0x0 | 0x62ed24 | 0x22e56c | 0x22496c | 0x0 |
UnregisterClassW | 0x0 | 0x62ed28 | 0x22e570 | 0x224970 | 0x0 |
GetTopWindow | 0x0 | 0x62ed2c | 0x22e574 | 0x224974 | 0x0 |
SendMessageW | 0x0 | 0x62ed30 | 0x22e578 | 0x224978 | 0x0 |
AdjustWindowRectEx | 0x0 | 0x62ed34 | 0x22e57c | 0x22497c | 0x0 |
DrawIcon | 0x0 | 0x62ed38 | 0x22e580 | 0x224980 | 0x0 |
IsWindow | 0x0 | 0x62ed3c | 0x22e584 | 0x224984 | 0x0 |
EnumThreadWindows | 0x0 | 0x62ed40 | 0x22e588 | 0x224988 | 0x0 |
InvalidateRect | 0x0 | 0x62ed44 | 0x22e58c | 0x22498c | 0x0 |
GetKeyboardState | 0x0 | 0x62ed48 | 0x22e590 | 0x224990 | 0x0 |
DrawFrameControl | 0x0 | 0x62ed4c | 0x22e594 | 0x224994 | 0x0 |
ScreenToClient | 0x0 | 0x62ed50 | 0x22e598 | 0x224998 | 0x0 |
SetCursor | 0x0 | 0x62ed54 | 0x22e59c | 0x22499c | 0x0 |
CreateIcon | 0x0 | 0x62ed58 | 0x22e5a0 | 0x2249a0 | 0x0 |
CreateMenu | 0x0 | 0x62ed5c | 0x22e5a4 | 0x2249a4 | 0x0 |
LoadStringW | 0x0 | 0x62ed60 | 0x22e5a8 | 0x2249a8 | 0x0 |
CharLowerW | 0x0 | 0x62ed64 | 0x22e5ac | 0x2249ac | 0x0 |
SetWindowRgn | 0x0 | 0x62ed68 | 0x22e5b0 | 0x2249b0 | 0x0 |
SetWindowPos | 0x0 | 0x62ed6c | 0x22e5b4 | 0x2249b4 | 0x0 |
GetMenuItemCount | 0x0 | 0x62ed70 | 0x22e5b8 | 0x2249b8 | 0x0 |
RemoveMenu | 0x0 | 0x62ed74 | 0x22e5bc | 0x2249bc | 0x0 |
GetSysColorBrush | 0x0 | 0x62ed78 | 0x22e5c0 | 0x2249c0 | 0x0 |
GetKeyboardLayoutNameW | 0x0 | 0x62ed7c | 0x22e5c4 | 0x2249c4 | 0x0 |
GetWindowDC | 0x0 | 0x62ed80 | 0x22e5c8 | 0x2249c8 | 0x0 |
TranslateMessage | 0x0 | 0x62ed84 | 0x22e5cc | 0x2249cc | 0x0 |
OpenClipboard | 0x0 | 0x62ed88 | 0x22e5d0 | 0x2249d0 | 0x0 |
DrawTextExW | 0x0 | 0x62ed8c | 0x22e5d4 | 0x2249d4 | 0x0 |
MapWindowPoints | 0x0 | 0x62ed90 | 0x22e5d8 | 0x2249d8 | 0x0 |
EnumDisplayMonitors | 0x0 | 0x62ed94 | 0x22e5dc | 0x2249dc | 0x0 |
CallWindowProcW | 0x0 | 0x62ed98 | 0x22e5e0 | 0x2249e0 | 0x0 |
CloseClipboard | 0x0 | 0x62ed9c | 0x22e5e4 | 0x2249e4 | 0x0 |
DestroyCursor | 0x0 | 0x62eda0 | 0x22e5e8 | 0x2249e8 | 0x0 |
GetScrollInfo | 0x0 | 0x62eda4 | 0x22e5ec | 0x2249ec | 0x0 |
SetWindowTextW | 0x0 | 0x62eda8 | 0x22e5f0 | 0x2249f0 | 0x0 |
GetMessageExtraInfo | 0x0 | 0x62edac | 0x22e5f4 | 0x2249f4 | 0x0 |
EnableScrollBar | 0x0 | 0x62edb0 | 0x22e5f8 | 0x2249f8 | 0x0 |
GetSysColor | 0x0 | 0x62edb4 | 0x22e5fc | 0x2249fc | 0x0 |
TrackPopupMenu | 0x0 | 0x62edb8 | 0x22e600 | 0x224a00 | 0x0 |
CopyIcon | 0x0 | 0x62edbc | 0x22e604 | 0x224a04 | 0x0 |
DrawIconEx | 0x0 | 0x62edc0 | 0x22e608 | 0x224a08 | 0x0 |
PostQuitMessage | 0x0 | 0x62edc4 | 0x22e60c | 0x224a0c | 0x0 |
GetClassNameW | 0x0 | 0x62edc8 | 0x22e610 | 0x224a10 | 0x0 |
ShowScrollBar | 0x0 | 0x62edcc | 0x22e614 | 0x224a14 | 0x0 |
EnableMenuItem | 0x0 | 0x62edd0 | 0x22e618 | 0x224a18 | 0x0 |
GetIconInfo | 0x0 | 0x62edd4 | 0x22e61c | 0x224a1c | 0x0 |
GetMessagePos | 0x0 | 0x62edd8 | 0x22e620 | 0x224a20 | 0x0 |
SetScrollInfo | 0x0 | 0x62eddc | 0x22e624 | 0x224a24 | 0x0 |
GetKeyNameTextW | 0x0 | 0x62ede0 | 0x22e628 | 0x224a28 | 0x0 |
GetDesktopWindow | 0x0 | 0x62ede4 | 0x22e62c | 0x224a2c | 0x0 |
GetCursorPos | 0x0 | 0x62ede8 | 0x22e630 | 0x224a30 | 0x0 |
SetCursorPos | 0x0 | 0x62edec | 0x22e634 | 0x224a34 | 0x0 |
HideCaret | 0x0 | 0x62edf0 | 0x22e638 | 0x224a38 | 0x0 |
GetMenu | 0x0 | 0x62edf4 | 0x22e63c | 0x224a3c | 0x0 |
GetMenuState | 0x0 | 0x62edf8 | 0x22e640 | 0x224a40 | 0x0 |
SetMenu | 0x0 | 0x62edfc | 0x22e644 | 0x224a44 | 0x0 |
SetRect | 0x0 | 0x62ee00 | 0x22e648 | 0x224a48 | 0x0 |
GetKeyState | 0x0 | 0x62ee04 | 0x22e64c | 0x224a4c | 0x0 |
FindWindowExW | 0x0 | 0x62ee08 | 0x22e650 | 0x224a50 | 0x0 |
MonitorFromPoint | 0x0 | 0x62ee0c | 0x22e654 | 0x224a54 | 0x0 |
SystemParametersInfoW | 0x0 | 0x62ee10 | 0x22e658 | 0x224a58 | 0x0 |
LoadIconW | 0x0 | 0x62ee14 | 0x22e65c | 0x224a5c | 0x0 |
GetCursor | 0x0 | 0x62ee18 | 0x22e660 | 0x224a60 | 0x0 |
GetWindow | 0x0 | 0x62ee1c | 0x22e664 | 0x224a64 | 0x0 |
GetWindowLongW | 0x0 | 0x62ee20 | 0x22e668 | 0x224a68 | 0x0 |
GetWindowRect | 0x0 | 0x62ee24 | 0x22e66c | 0x224a6c | 0x0 |
InsertMenuW | 0x0 | 0x62ee28 | 0x22e670 | 0x224a70 | 0x0 |
KillTimer | 0x0 | 0x62ee2c | 0x22e674 | 0x224a74 | 0x0 |
WaitMessage | 0x0 | 0x62ee30 | 0x22e678 | 0x224a78 | 0x0 |
IsWindowEnabled | 0x0 | 0x62ee34 | 0x22e67c | 0x224a7c | 0x0 |
IsDialogMessageA | 0x0 | 0x62ee38 | 0x22e680 | 0x224a80 | 0x0 |
TranslateMDISysAccel | 0x0 | 0x62ee3c | 0x22e684 | 0x224a84 | 0x0 |
GetWindowPlacement | 0x0 | 0x62ee40 | 0x22e688 | 0x224a88 | 0x0 |
FindWindowW | 0x0 | 0x62ee44 | 0x22e68c | 0x224a8c | 0x0 |
DeleteMenu | 0x0 | 0x62ee48 | 0x22e690 | 0x224a90 | 0x0 |
GetKeyboardLayout | 0x0 | 0x62ee4c | 0x22e694 | 0x224a94 | 0x0 |
oleaut32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x0 | 0x62ee54 | 0x22e69c | 0x224a9c | 0x0 |
VariantClear | 0x0 | 0x62ee58 | 0x22e6a0 | 0x224aa0 | 0x0 |
VariantInit | 0x0 | 0x62ee5c | 0x22e6a4 | 0x224aa4 | 0x0 |
GetErrorInfo | 0x0 | 0x62ee60 | 0x22e6a8 | 0x224aa8 | 0x0 |
SysReAllocStringLen | 0x0 | 0x62ee64 | 0x22e6ac | 0x224aac | 0x0 |
SafeArrayCreate | 0x0 | 0x62ee68 | 0x22e6b0 | 0x224ab0 | 0x0 |
SysAllocStringLen | 0x0 | 0x62ee6c | 0x22e6b4 | 0x224ab4 | 0x0 |
SafeArrayPtrOfIndex | 0x0 | 0x62ee70 | 0x22e6b8 | 0x224ab8 | 0x0 |
SafeArrayGetUBound | 0x0 | 0x62ee74 | 0x22e6bc | 0x224abc | 0x0 |
SafeArrayGetLBound | 0x0 | 0x62ee78 | 0x22e6c0 | 0x224ac0 | 0x0 |
VariantCopy | 0x0 | 0x62ee7c | 0x22e6c4 | 0x224ac4 | 0x0 |
VariantChangeType | 0x0 | 0x62ee80 | 0x22e6c8 | 0x224ac8 | 0x0 |
netapi32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetWkstaGetInfo | 0x0 | 0x62ee88 | 0x22e6d0 | 0x224ad0 | 0x0 |
NetApiBufferFree | 0x0 | 0x62ee8c | 0x22e6d4 | 0x224ad4 | 0x0 |
advapi32.dll (17)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegSetValueExW | 0x0 | 0x62ee94 | 0x22e6dc | 0x224adc | 0x0 |
RegConnectRegistryW | 0x0 | 0x62ee98 | 0x22e6e0 | 0x224ae0 | 0x0 |
RegEnumKeyExW | 0x0 | 0x62ee9c | 0x22e6e4 | 0x224ae4 | 0x0 |
RegLoadKeyW | 0x0 | 0x62eea0 | 0x22e6e8 | 0x224ae8 | 0x0 |
RegDeleteKeyW | 0x0 | 0x62eea4 | 0x22e6ec | 0x224aec | 0x0 |
RegOpenKeyExW | 0x0 | 0x62eea8 | 0x22e6f0 | 0x224af0 | 0x0 |
RegQueryInfoKeyW | 0x0 | 0x62eeac | 0x22e6f4 | 0x224af4 | 0x0 |
RegUnLoadKeyW | 0x0 | 0x62eeb0 | 0x22e6f8 | 0x224af8 | 0x0 |
RegSaveKeyW | 0x0 | 0x62eeb4 | 0x22e6fc | 0x224afc | 0x0 |
RegDeleteValueW | 0x0 | 0x62eeb8 | 0x22e700 | 0x224b00 | 0x0 |
RegReplaceKeyW | 0x0 | 0x62eebc | 0x22e704 | 0x224b04 | 0x0 |
RegFlushKey | 0x0 | 0x62eec0 | 0x22e708 | 0x224b08 | 0x0 |
RegQueryValueExW | 0x0 | 0x62eec4 | 0x22e70c | 0x224b0c | 0x0 |
RegEnumValueW | 0x0 | 0x62eec8 | 0x22e710 | 0x224b10 | 0x0 |
RegCloseKey | 0x0 | 0x62eecc | 0x22e714 | 0x224b14 | 0x0 |
RegCreateKeyExW | 0x0 | 0x62eed0 | 0x22e718 | 0x224b18 | 0x0 |
RegRestoreKeyW | 0x0 | 0x62eed4 | 0x22e71c | 0x224b1c | 0x0 |
gdi32.dll (96)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Pie | 0x0 | 0x62eedc | 0x22e724 | 0x224b24 | 0x0 |
SetBkMode | 0x0 | 0x62eee0 | 0x22e728 | 0x224b28 | 0x0 |
CreateCompatibleBitmap | 0x0 | 0x62eee4 | 0x22e72c | 0x224b2c | 0x0 |
GetEnhMetaFileHeader | 0x0 | 0x62eee8 | 0x22e730 | 0x224b30 | 0x0 |
RectVisible | 0x0 | 0x62eeec | 0x22e734 | 0x224b34 | 0x0 |
AngleArc | 0x0 | 0x62eef0 | 0x22e738 | 0x224b38 | 0x0 |
SetAbortProc | 0x0 | 0x62eef4 | 0x22e73c | 0x224b3c | 0x0 |
SetTextColor | 0x0 | 0x62eef8 | 0x22e740 | 0x224b40 | 0x0 |
StretchBlt | 0x0 | 0x62eefc | 0x22e744 | 0x224b44 | 0x0 |
RoundRect | 0x0 | 0x62ef00 | 0x22e748 | 0x224b48 | 0x0 |
RestoreDC | 0x0 | 0x62ef04 | 0x22e74c | 0x224b4c | 0x0 |
SetRectRgn | 0x0 | 0x62ef08 | 0x22e750 | 0x224b50 | 0x0 |
GetTextMetricsW | 0x0 | 0x62ef0c | 0x22e754 | 0x224b54 | 0x0 |
GetWindowOrgEx | 0x0 | 0x62ef10 | 0x22e758 | 0x224b58 | 0x0 |
CreatePalette | 0x0 | 0x62ef14 | 0x22e75c | 0x224b5c | 0x0 |
PolyBezierTo | 0x0 | 0x62ef18 | 0x22e760 | 0x224b60 | 0x0 |
CreateICW | 0x0 | 0x62ef1c | 0x22e764 | 0x224b64 | 0x0 |
CreateDCW | 0x0 | 0x62ef20 | 0x22e768 | 0x224b68 | 0x0 |
GetStockObject | 0x0 | 0x62ef24 | 0x22e76c | 0x224b6c | 0x0 |
CreateSolidBrush | 0x0 | 0x62ef28 | 0x22e770 | 0x224b70 | 0x0 |
Polygon | 0x0 | 0x62ef2c | 0x22e774 | 0x224b74 | 0x0 |
MoveToEx | 0x0 | 0x62ef30 | 0x22e778 | 0x224b78 | 0x0 |
PlayEnhMetaFile | 0x0 | 0x62ef34 | 0x22e77c | 0x224b7c | 0x0 |
Ellipse | 0x0 | 0x62ef38 | 0x22e780 | 0x224b80 | 0x0 |
StartPage | 0x0 | 0x62ef3c | 0x22e784 | 0x224b84 | 0x0 |
GetBitmapBits | 0x0 | 0x62ef40 | 0x22e788 | 0x224b88 | 0x0 |
StartDocW | 0x0 | 0x62ef44 | 0x22e78c | 0x224b8c | 0x0 |
GetSystemPaletteEntries | 0x0 | 0x62ef48 | 0x22e790 | 0x224b90 | 0x0 |
GetEnhMetaFileBits | 0x0 | 0x62ef4c | 0x22e794 | 0x224b94 | 0x0 |
AbortDoc | 0x0 | 0x62ef50 | 0x22e798 | 0x224b98 | 0x0 |
GetEnhMetaFilePaletteEntries | 0x0 | 0x62ef54 | 0x22e79c | 0x224b9c | 0x0 |
CreatePenIndirect | 0x0 | 0x62ef58 | 0x22e7a0 | 0x224ba0 | 0x0 |
CreateFontIndirectW | 0x0 | 0x62ef5c | 0x22e7a4 | 0x224ba4 | 0x0 |
PolyBezier | 0x0 | 0x62ef60 | 0x22e7a8 | 0x224ba8 | 0x0 |
EndDoc | 0x0 | 0x62ef64 | 0x22e7ac | 0x224bac | 0x0 |
GetObjectW | 0x0 | 0x62ef68 | 0x22e7b0 | 0x224bb0 | 0x0 |
GetWinMetaFileBits | 0x0 | 0x62ef6c | 0x22e7b4 | 0x224bb4 | 0x0 |
SetROP2 | 0x0 | 0x62ef70 | 0x22e7b8 | 0x224bb8 | 0x0 |
GetEnhMetaFileDescriptionW | 0x0 | 0x62ef74 | 0x22e7bc | 0x224bbc | 0x0 |
ArcTo | 0x0 | 0x62ef78 | 0x22e7c0 | 0x224bc0 | 0x0 |
Arc | 0x0 | 0x62ef7c | 0x22e7c4 | 0x224bc4 | 0x0 |
SelectPalette | 0x0 | 0x62ef80 | 0x22e7c8 | 0x224bc8 | 0x0 |
ExcludeClipRect | 0x0 | 0x62ef84 | 0x22e7cc | 0x224bcc | 0x0 |
MaskBlt | 0x0 | 0x62ef88 | 0x22e7d0 | 0x224bd0 | 0x0 |
SetWindowOrgEx | 0x0 | 0x62ef8c | 0x22e7d4 | 0x224bd4 | 0x0 |
EndPage | 0x0 | 0x62ef90 | 0x22e7d8 | 0x224bd8 | 0x0 |
DeleteEnhMetaFile | 0x0 | 0x62ef94 | 0x22e7dc | 0x224bdc | 0x0 |
Chord | 0x0 | 0x62ef98 | 0x22e7e0 | 0x224be0 | 0x0 |
SetDIBits | 0x0 | 0x62ef9c | 0x22e7e4 | 0x224be4 | 0x0 |
SetViewportOrgEx | 0x0 | 0x62efa0 | 0x22e7e8 | 0x224be8 | 0x0 |
CreateRectRgn | 0x0 | 0x62efa4 | 0x22e7ec | 0x224bec | 0x0 |
RealizePalette | 0x0 | 0x62efa8 | 0x22e7f0 | 0x224bf0 | 0x0 |
SetDIBColorTable | 0x0 | 0x62efac | 0x22e7f4 | 0x224bf4 | 0x0 |
GetDIBColorTable | 0x0 | 0x62efb0 | 0x22e7f8 | 0x224bf8 | 0x0 |
CreateBrushIndirect | 0x0 | 0x62efb4 | 0x22e7fc | 0x224bfc | 0x0 |
PatBlt | 0x0 | 0x62efb8 | 0x22e800 | 0x224c00 | 0x0 |
SetEnhMetaFileBits | 0x0 | 0x62efbc | 0x22e804 | 0x224c04 | 0x0 |
Rectangle | 0x0 | 0x62efc0 | 0x22e808 | 0x224c08 | 0x0 |
SaveDC | 0x0 | 0x62efc4 | 0x22e80c | 0x224c0c | 0x0 |
DeleteDC | 0x0 | 0x62efc8 | 0x22e810 | 0x224c10 | 0x0 |
FrameRgn | 0x0 | 0x62efcc | 0x22e814 | 0x224c14 | 0x0 |
BitBlt | 0x0 | 0x62efd0 | 0x22e818 | 0x224c18 | 0x0 |
GetDeviceCaps | 0x0 | 0x62efd4 | 0x22e81c | 0x224c1c | 0x0 |
GetTextExtentPoint32W | 0x0 | 0x62efd8 | 0x22e820 | 0x224c20 | 0x0 |
GetClipBox | 0x0 | 0x62efdc | 0x22e824 | 0x224c24 | 0x0 |
IntersectClipRect | 0x0 | 0x62efe0 | 0x22e828 | 0x224c28 | 0x0 |
Polyline | 0x0 | 0x62efe4 | 0x22e82c | 0x224c2c | 0x0 |
CreateBitmap | 0x0 | 0x62efe8 | 0x22e830 | 0x224c30 | 0x0 |
SetWinMetaFileBits | 0x0 | 0x62efec | 0x22e834 | 0x224c34 | 0x0 |
GetStretchBltMode | 0x0 | 0x62eff0 | 0x22e838 | 0x224c38 | 0x0 |
CreateDIBitmap | 0x0 | 0x62eff4 | 0x22e83c | 0x224c3c | 0x0 |
SetStretchBltMode | 0x0 | 0x62eff8 | 0x22e840 | 0x224c40 | 0x0 |
GetDIBits | 0x0 | 0x62effc | 0x22e844 | 0x224c44 | 0x0 |
CreateDIBSection | 0x0 | 0x62f000 | 0x22e848 | 0x224c48 | 0x0 |
LineTo | 0x0 | 0x62f004 | 0x22e84c | 0x224c4c | 0x0 |
GetRgnBox | 0x0 | 0x62f008 | 0x22e850 | 0x224c50 | 0x0 |
EnumFontsW | 0x0 | 0x62f00c | 0x22e854 | 0x224c54 | 0x0 |
CreateHalftonePalette | 0x0 | 0x62f010 | 0x22e858 | 0x224c58 | 0x0 |
SelectObject | 0x0 | 0x62f014 | 0x22e85c | 0x224c5c | 0x0 |
DeleteObject | 0x0 | 0x62f018 | 0x22e860 | 0x224c60 | 0x0 |
ExtFloodFill | 0x0 | 0x62f01c | 0x22e864 | 0x224c64 | 0x0 |
UnrealizeObject | 0x0 | 0x62f020 | 0x22e868 | 0x224c68 | 0x0 |
CopyEnhMetaFileW | 0x0 | 0x62f024 | 0x22e86c | 0x224c6c | 0x0 |
SetBkColor | 0x0 | 0x62f028 | 0x22e870 | 0x224c70 | 0x0 |
CreateCompatibleDC | 0x0 | 0x62f02c | 0x22e874 | 0x224c74 | 0x0 |
GetBrushOrgEx | 0x0 | 0x62f030 | 0x22e878 | 0x224c78 | 0x0 |
GetCurrentPositionEx | 0x0 | 0x62f034 | 0x22e87c | 0x224c7c | 0x0 |
GetTextExtentPointW | 0x0 | 0x62f038 | 0x22e880 | 0x224c80 | 0x0 |
ExtTextOutW | 0x0 | 0x62f03c | 0x22e884 | 0x224c84 | 0x0 |
SetBrushOrgEx | 0x0 | 0x62f040 | 0x22e888 | 0x224c88 | 0x0 |
GetPixel | 0x0 | 0x62f044 | 0x22e88c | 0x224c8c | 0x0 |
GdiFlush | 0x0 | 0x62f048 | 0x22e890 | 0x224c90 | 0x0 |
SetPixel | 0x0 | 0x62f04c | 0x22e894 | 0x224c94 | 0x0 |
EnumFontFamiliesExW | 0x0 | 0x62f050 | 0x22e898 | 0x224c98 | 0x0 |
StretchDIBits | 0x0 | 0x62f054 | 0x22e89c | 0x224c9c | 0x0 |
GetPaletteEntries | 0x0 | 0x62f058 | 0x22e8a0 | 0x224ca0 | 0x0 |
Exports (3)
»
Api name | EAT Address | Ordinal |
---|---|---|
TMethodImplementationIntercept | 0xd7ebc | 0x3 |
__dbk_fcall_wrapper | 0x11084 | 0x2 |
dbkFCallWrapperAddr | 0x22963c | 0x1 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
svchost.exe | 3 | 0x00400000 | 0x00670FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 3 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230FE2 |
![]() |
![]() |
...
|
buffer | 3 | 0x00230000 | 0x00230FFF | Content Changed | - | 32-bit | 0x00230FE2 |
![]() |
![]() |
...
|
svchost.exe | 3 | 0x00400000 | 0x00670FFF | Final Dump | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Trojan.Heur.yU0@riXijEli |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Ztarter.exe | Sample File | Binary |
Blacklisted
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-12-19 10:30 (UTC+1) |
Last Seen | 2019-12-19 12:19 (UTC+1) |
Names | Win32.Trojan.Wacatac |
Families | Wacatac |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x668d20 |
Size Of Code | 0x267400 |
Size Of Initialized Data | 0x64600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-12-19 08:39:46+00:00 |
Packer | BobSoft Mini Delphi -> BoB / BobSoft |
Version Information (5)
»
FileDescription | Ztarter |
FileVersion | 1.0.0.0 |
ProductName | Ztarter |
ProductVersion | 1.0.0.0 |
ProgramID | com.embarcadero.Ztarter |
Sections (11)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2655ec | 0x265600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.48 |
.itext | 0x667000 | 0x1da8 | 0x1e00 | 0x265a00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.14 |
.data | 0x669000 | 0x8f6c | 0x9000 | 0x267800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.22 |
.bss | 0x672000 | 0x1a094 | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x68d000 | 0x32aa | 0x3400 | 0x270800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.2 |
.didata | 0x691000 | 0xb5e | 0xc00 | 0x273c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.15 |
.edata | 0x692000 | 0x99 | 0x200 | 0x274800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.89 |
.tls | 0x693000 | 0x54 | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rdata | 0x694000 | 0x5d | 0x200 | 0x274a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.37 |
.reloc | 0x695000 | 0x35b48 | 0x35c00 | 0x274c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.72 |
.rsrc | 0x6cb000 | 0x21600 | 0x21600 | 0x2aa800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.53 |
Imports (13)
»
winspool.drv (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DocumentPropertiesW | 0x0 | 0x68d8f8 | 0x28d118 | 0x270918 | 0x0 |
ClosePrinter | 0x0 | 0x68d8fc | 0x28d11c | 0x27091c | 0x0 |
OpenPrinterW | 0x0 | 0x68d900 | 0x28d120 | 0x270920 | 0x0 |
GetDefaultPrinterW | 0x0 | 0x68d904 | 0x28d124 | 0x270924 | 0x0 |
EnumPrintersW | 0x0 | 0x68d908 | 0x28d128 | 0x270928 | 0x0 |
comctl32.dll (35)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_GetImageInfo | 0x0 | 0x68d910 | 0x28d130 | 0x270930 | 0x0 |
FlatSB_SetScrollInfo | 0x0 | 0x68d914 | 0x28d134 | 0x270934 | 0x0 |
ImageList_DragMove | 0x0 | 0x68d918 | 0x28d138 | 0x270938 | 0x0 |
ImageList_Destroy | 0x0 | 0x68d91c | 0x28d13c | 0x27093c | 0x0 |
_TrackMouseEvent | 0x0 | 0x68d920 | 0x28d140 | 0x270940 | 0x0 |
ImageList_DragShowNolock | 0x0 | 0x68d924 | 0x28d144 | 0x270944 | 0x0 |
ImageList_Add | 0x0 | 0x68d928 | 0x28d148 | 0x270948 | 0x0 |
FlatSB_SetScrollProp | 0x0 | 0x68d92c | 0x28d14c | 0x27094c | 0x0 |
ImageList_GetDragImage | 0x0 | 0x68d930 | 0x28d150 | 0x270950 | 0x0 |
ImageList_Create | 0x0 | 0x68d934 | 0x28d154 | 0x270954 | 0x0 |
ImageList_EndDrag | 0x0 | 0x68d938 | 0x28d158 | 0x270958 | 0x0 |
ImageList_DrawEx | 0x0 | 0x68d93c | 0x28d15c | 0x27095c | 0x0 |
ImageList_SetImageCount | 0x0 | 0x68d940 | 0x28d160 | 0x270960 | 0x0 |
FlatSB_GetScrollPos | 0x0 | 0x68d944 | 0x28d164 | 0x270964 | 0x0 |
FlatSB_SetScrollPos | 0x0 | 0x68d948 | 0x28d168 | 0x270968 | 0x0 |
InitializeFlatSB | 0x0 | 0x68d94c | 0x28d16c | 0x27096c | 0x0 |
ImageList_Copy | 0x0 | 0x68d950 | 0x28d170 | 0x270970 | 0x0 |
FlatSB_GetScrollInfo | 0x0 | 0x68d954 | 0x28d174 | 0x270974 | 0x0 |
ImageList_Write | 0x0 | 0x68d958 | 0x28d178 | 0x270978 | 0x0 |
ImageList_SetBkColor | 0x0 | 0x68d95c | 0x28d17c | 0x27097c | 0x0 |
ImageList_GetBkColor | 0x0 | 0x68d960 | 0x28d180 | 0x270980 | 0x0 |
ImageList_BeginDrag | 0x0 | 0x68d964 | 0x28d184 | 0x270984 | 0x0 |
ImageList_GetIcon | 0x0 | 0x68d968 | 0x28d188 | 0x270988 | 0x0 |
ImageList_Replace | 0x0 | 0x68d96c | 0x28d18c | 0x27098c | 0x0 |
ImageList_GetImageCount | 0x0 | 0x68d970 | 0x28d190 | 0x270990 | 0x0 |
ImageList_DragEnter | 0x0 | 0x68d974 | 0x28d194 | 0x270994 | 0x0 |
ImageList_GetIconSize | 0x0 | 0x68d978 | 0x28d198 | 0x270998 | 0x0 |
ImageList_SetIconSize | 0x0 | 0x68d97c | 0x28d19c | 0x27099c | 0x0 |
ImageList_Read | 0x0 | 0x68d980 | 0x28d1a0 | 0x2709a0 | 0x0 |
ImageList_DragLeave | 0x0 | 0x68d984 | 0x28d1a4 | 0x2709a4 | 0x0 |
ImageList_LoadImageW | 0x0 | 0x68d988 | 0x28d1a8 | 0x2709a8 | 0x0 |
ImageList_Draw | 0x0 | 0x68d98c | 0x28d1ac | 0x2709ac | 0x0 |
ImageList_Remove | 0x0 | 0x68d990 | 0x28d1b0 | 0x2709b0 | 0x0 |
ImageList_ReplaceIcon | 0x0 | 0x68d994 | 0x28d1b4 | 0x2709b4 | 0x0 |
ImageList_SetOverlayImage | 0x0 | 0x68d998 | 0x28d1b8 | 0x2709b8 | 0x0 |
shell32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Shell_NotifyIconW | 0x0 | 0x68d9a0 | 0x28d1c0 | 0x2709c0 | 0x0 |
ShellExecuteW | 0x0 | 0x68d9a4 | 0x28d1c4 | 0x2709c4 | 0x0 |
user32.dll (192)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CopyImage | 0x0 | 0x68d9ac | 0x28d1cc | 0x2709cc | 0x0 |
SetMenuItemInfoW | 0x0 | 0x68d9b0 | 0x28d1d0 | 0x2709d0 | 0x0 |
GetMenuItemInfoW | 0x0 | 0x68d9b4 | 0x28d1d4 | 0x2709d4 | 0x0 |
DefFrameProcW | 0x0 | 0x68d9b8 | 0x28d1d8 | 0x2709d8 | 0x0 |
GetDlgCtrlID | 0x0 | 0x68d9bc | 0x28d1dc | 0x2709dc | 0x0 |
FrameRect | 0x0 | 0x68d9c0 | 0x28d1e0 | 0x2709e0 | 0x0 |
RegisterWindowMessageW | 0x0 | 0x68d9c4 | 0x28d1e4 | 0x2709e4 | 0x0 |
GetMenuStringW | 0x0 | 0x68d9c8 | 0x28d1e8 | 0x2709e8 | 0x0 |
FillRect | 0x0 | 0x68d9cc | 0x28d1ec | 0x2709ec | 0x0 |
SendMessageA | 0x0 | 0x68d9d0 | 0x28d1f0 | 0x2709f0 | 0x0 |
EnumWindows | 0x0 | 0x68d9d4 | 0x28d1f4 | 0x2709f4 | 0x0 |
ShowOwnedPopups | 0x0 | 0x68d9d8 | 0x28d1f8 | 0x2709f8 | 0x0 |
GetClassInfoExW | 0x0 | 0x68d9dc | 0x28d1fc | 0x2709fc | 0x0 |
GetClassInfoW | 0x0 | 0x68d9e0 | 0x28d200 | 0x270a00 | 0x0 |
GetScrollRange | 0x0 | 0x68d9e4 | 0x28d204 | 0x270a04 | 0x0 |
SetActiveWindow | 0x0 | 0x68d9e8 | 0x28d208 | 0x270a08 | 0x0 |
GetActiveWindow | 0x0 | 0x68d9ec | 0x28d20c | 0x270a0c | 0x0 |
DrawEdge | 0x0 | 0x68d9f0 | 0x28d210 | 0x270a10 | 0x0 |
GetKeyboardLayoutList | 0x0 | 0x68d9f4 | 0x28d214 | 0x270a14 | 0x0 |
LoadBitmapW | 0x0 | 0x68d9f8 | 0x28d218 | 0x270a18 | 0x0 |
EnumChildWindows | 0x0 | 0x68d9fc | 0x28d21c | 0x270a1c | 0x0 |
UnhookWindowsHookEx | 0x0 | 0x68da00 | 0x28d220 | 0x270a20 | 0x0 |
SetCapture | 0x0 | 0x68da04 | 0x28d224 | 0x270a24 | 0x0 |
GetCapture | 0x0 | 0x68da08 | 0x28d228 | 0x270a28 | 0x0 |
ShowCaret | 0x0 | 0x68da0c | 0x28d22c | 0x270a2c | 0x0 |
CreatePopupMenu | 0x0 | 0x68da10 | 0x28d230 | 0x270a30 | 0x0 |
GetMenuItemID | 0x0 | 0x68da14 | 0x28d234 | 0x270a34 | 0x0 |
CharLowerBuffW | 0x0 | 0x68da18 | 0x28d238 | 0x270a38 | 0x0 |
PostMessageW | 0x0 | 0x68da1c | 0x28d23c | 0x270a3c | 0x0 |
SetWindowLongW | 0x0 | 0x68da20 | 0x28d240 | 0x270a40 | 0x0 |
IsZoomed | 0x0 | 0x68da24 | 0x28d244 | 0x270a44 | 0x0 |
SetParent | 0x0 | 0x68da28 | 0x28d248 | 0x270a48 | 0x0 |
DrawMenuBar | 0x0 | 0x68da2c | 0x28d24c | 0x270a4c | 0x0 |
GetClientRect | 0x0 | 0x68da30 | 0x28d250 | 0x270a50 | 0x0 |
IsChild | 0x0 | 0x68da34 | 0x28d254 | 0x270a54 | 0x0 |
IsIconic | 0x0 | 0x68da38 | 0x28d258 | 0x270a58 | 0x0 |
CallNextHookEx | 0x0 | 0x68da3c | 0x28d25c | 0x270a5c | 0x0 |
ShowWindow | 0x0 | 0x68da40 | 0x28d260 | 0x270a60 | 0x0 |
GetWindowTextW | 0x0 | 0x68da44 | 0x28d264 | 0x270a64 | 0x0 |
SetForegroundWindow | 0x0 | 0x68da48 | 0x28d268 | 0x270a68 | 0x0 |
IsDialogMessageW | 0x0 | 0x68da4c | 0x28d26c | 0x270a6c | 0x0 |
DestroyWindow | 0x0 | 0x68da50 | 0x28d270 | 0x270a70 | 0x0 |
RegisterClassW | 0x0 | 0x68da54 | 0x28d274 | 0x270a74 | 0x0 |
EndMenu | 0x0 | 0x68da58 | 0x28d278 | 0x270a78 | 0x0 |
CharNextW | 0x0 | 0x68da5c | 0x28d27c | 0x270a7c | 0x0 |
GetFocus | 0x0 | 0x68da60 | 0x28d280 | 0x270a80 | 0x0 |
GetDC | 0x0 | 0x68da64 | 0x28d284 | 0x270a84 | 0x0 |
SetFocus | 0x0 | 0x68da68 | 0x28d288 | 0x270a88 | 0x0 |
ReleaseDC | 0x0 | 0x68da6c | 0x28d28c | 0x270a8c | 0x0 |
GetClassLongW | 0x0 | 0x68da70 | 0x28d290 | 0x270a90 | 0x0 |
SetScrollRange | 0x0 | 0x68da74 | 0x28d294 | 0x270a94 | 0x0 |
DrawTextW | 0x0 | 0x68da78 | 0x28d298 | 0x270a98 | 0x0 |
PeekMessageA | 0x0 | 0x68da7c | 0x28d29c | 0x270a9c | 0x0 |
MessageBeep | 0x0 | 0x68da80 | 0x28d2a0 | 0x270aa0 | 0x0 |
SetClassLongW | 0x0 | 0x68da84 | 0x28d2a4 | 0x270aa4 | 0x0 |
RemovePropW | 0x0 | 0x68da88 | 0x28d2a8 | 0x270aa8 | 0x0 |
GetSubMenu | 0x0 | 0x68da8c | 0x28d2ac | 0x270aac | 0x0 |
DestroyIcon | 0x0 | 0x68da90 | 0x28d2b0 | 0x270ab0 | 0x0 |
IsWindowVisible | 0x0 | 0x68da94 | 0x28d2b4 | 0x270ab4 | 0x0 |
PtInRect | 0x0 | 0x68da98 | 0x28d2b8 | 0x270ab8 | 0x0 |
DispatchMessageA | 0x0 | 0x68da9c | 0x28d2bc | 0x270abc | 0x0 |
UnregisterClassW | 0x0 | 0x68daa0 | 0x28d2c0 | 0x270ac0 | 0x0 |
GetTopWindow | 0x0 | 0x68daa4 | 0x28d2c4 | 0x270ac4 | 0x0 |
SendMessageW | 0x0 | 0x68daa8 | 0x28d2c8 | 0x270ac8 | 0x0 |
GetComboBoxInfo | 0x0 | 0x68daac | 0x28d2cc | 0x270acc | 0x0 |
LoadStringW | 0x0 | 0x68dab0 | 0x28d2d0 | 0x270ad0 | 0x0 |
CreateMenu | 0x0 | 0x68dab4 | 0x28d2d4 | 0x270ad4 | 0x0 |
CharLowerW | 0x0 | 0x68dab8 | 0x28d2d8 | 0x270ad8 | 0x0 |
SetWindowPos | 0x0 | 0x68dabc | 0x28d2dc | 0x270adc | 0x0 |
SetWindowRgn | 0x0 | 0x68dac0 | 0x28d2e0 | 0x270ae0 | 0x0 |
GetMenuItemCount | 0x0 | 0x68dac4 | 0x28d2e4 | 0x270ae4 | 0x0 |
GetSysColorBrush | 0x0 | 0x68dac8 | 0x28d2e8 | 0x270ae8 | 0x0 |
GetWindowDC | 0x0 | 0x68dacc | 0x28d2ec | 0x270aec | 0x0 |
DrawTextExW | 0x0 | 0x68dad0 | 0x28d2f0 | 0x270af0 | 0x0 |
GetScrollInfo | 0x0 | 0x68dad4 | 0x28d2f4 | 0x270af4 | 0x0 |
SetWindowTextW | 0x0 | 0x68dad8 | 0x28d2f8 | 0x270af8 | 0x0 |
GetMessageExtraInfo | 0x0 | 0x68dadc | 0x28d2fc | 0x270afc | 0x0 |
GetSysColor | 0x0 | 0x68dae0 | 0x28d300 | 0x270b00 | 0x0 |
EnableScrollBar | 0x0 | 0x68dae4 | 0x28d304 | 0x270b04 | 0x0 |
TrackPopupMenu | 0x0 | 0x68dae8 | 0x28d308 | 0x270b08 | 0x0 |
DrawIconEx | 0x0 | 0x68daec | 0x28d30c | 0x270b0c | 0x0 |
GetClassNameW | 0x0 | 0x68daf0 | 0x28d310 | 0x270b10 | 0x0 |
GetMessagePos | 0x0 | 0x68daf4 | 0x28d314 | 0x270b14 | 0x0 |
GetIconInfo | 0x0 | 0x68daf8 | 0x28d318 | 0x270b18 | 0x0 |
SetScrollInfo | 0x0 | 0x68dafc | 0x28d31c | 0x270b1c | 0x0 |
GetKeyNameTextW | 0x0 | 0x68db00 | 0x28d320 | 0x270b20 | 0x0 |
GetDesktopWindow | 0x0 | 0x68db04 | 0x28d324 | 0x270b24 | 0x0 |
SetCursorPos | 0x0 | 0x68db08 | 0x28d328 | 0x270b28 | 0x0 |
GetCursorPos | 0x0 | 0x68db0c | 0x28d32c | 0x270b2c | 0x0 |
SetMenu | 0x0 | 0x68db10 | 0x28d330 | 0x270b30 | 0x0 |
GetMenuState | 0x0 | 0x68db14 | 0x28d334 | 0x270b34 | 0x0 |
GetMenu | 0x0 | 0x68db18 | 0x28d338 | 0x270b38 | 0x0 |
SetRect | 0x0 | 0x68db1c | 0x28d33c | 0x270b3c | 0x0 |
GetKeyState | 0x0 | 0x68db20 | 0x28d340 | 0x270b40 | 0x0 |
IsRectEmpty | 0x0 | 0x68db24 | 0x28d344 | 0x270b44 | 0x0 |
GetCursor | 0x0 | 0x68db28 | 0x28d348 | 0x270b48 | 0x0 |
KillTimer | 0x0 | 0x68db2c | 0x28d34c | 0x270b4c | 0x0 |
WaitMessage | 0x0 | 0x68db30 | 0x28d350 | 0x270b50 | 0x0 |
TranslateMDISysAccel | 0x0 | 0x68db34 | 0x28d354 | 0x270b54 | 0x0 |
GetWindowPlacement | 0x0 | 0x68db38 | 0x28d358 | 0x270b58 | 0x0 |
GetMenuItemRect | 0x0 | 0x68db3c | 0x28d35c | 0x270b5c | 0x0 |
CreateIconIndirect | 0x0 | 0x68db40 | 0x28d360 | 0x270b60 | 0x0 |
CreateWindowExW | 0x0 | 0x68db44 | 0x28d364 | 0x270b64 | 0x0 |
GetDCEx | 0x0 | 0x68db48 | 0x28d368 | 0x270b68 | 0x0 |
PeekMessageW | 0x0 | 0x68db4c | 0x28d36c | 0x270b6c | 0x0 |
MonitorFromWindow | 0x0 | 0x68db50 | 0x28d370 | 0x270b70 | 0x0 |
SetTimer | 0x0 | 0x68db54 | 0x28d374 | 0x270b74 | 0x0 |
WindowFromPoint | 0x0 | 0x68db58 | 0x28d378 | 0x270b78 | 0x0 |
BeginPaint | 0x0 | 0x68db5c | 0x28d37c | 0x270b7c | 0x0 |
RegisterClipboardFormatW | 0x0 | 0x68db60 | 0x28d380 | 0x270b80 | 0x0 |
MapVirtualKeyW | 0x0 | 0x68db64 | 0x28d384 | 0x270b84 | 0x0 |
OffsetRect | 0x0 | 0x68db68 | 0x28d388 | 0x270b88 | 0x0 |
IsWindowUnicode | 0x0 | 0x68db6c | 0x28d38c | 0x270b8c | 0x0 |
DispatchMessageW | 0x0 | 0x68db70 | 0x28d390 | 0x270b90 | 0x0 |
CreateAcceleratorTableW | 0x0 | 0x68db74 | 0x28d394 | 0x270b94 | 0x0 |
DefMDIChildProcW | 0x0 | 0x68db78 | 0x28d398 | 0x270b98 | 0x0 |
GetSystemMenu | 0x0 | 0x68db7c | 0x28d39c | 0x270b9c | 0x0 |
SetScrollPos | 0x0 | 0x68db80 | 0x28d3a0 | 0x270ba0 | 0x0 |
GetScrollPos | 0x0 | 0x68db84 | 0x28d3a4 | 0x270ba4 | 0x0 |
InflateRect | 0x0 | 0x68db88 | 0x28d3a8 | 0x270ba8 | 0x0 |
DrawFocusRect | 0x0 | 0x68db8c | 0x28d3ac | 0x270bac | 0x0 |
ReleaseCapture | 0x0 | 0x68db90 | 0x28d3b0 | 0x270bb0 | 0x0 |
LoadCursorW | 0x0 | 0x68db94 | 0x28d3b4 | 0x270bb4 | 0x0 |
ScrollWindow | 0x0 | 0x68db98 | 0x28d3b8 | 0x270bb8 | 0x0 |
GetLastActivePopup | 0x0 | 0x68db9c | 0x28d3bc | 0x270bbc | 0x0 |
GetSystemMetrics | 0x0 | 0x68dba0 | 0x28d3c0 | 0x270bc0 | 0x0 |
CharUpperBuffW | 0x0 | 0x68dba4 | 0x28d3c4 | 0x270bc4 | 0x0 |
SetClipboardData | 0x0 | 0x68dba8 | 0x28d3c8 | 0x270bc8 | 0x0 |
GetClipboardData | 0x0 | 0x68dbac | 0x28d3cc | 0x270bcc | 0x0 |
ClientToScreen | 0x0 | 0x68dbb0 | 0x28d3d0 | 0x270bd0 | 0x0 |
SetWindowPlacement | 0x0 | 0x68dbb4 | 0x28d3d4 | 0x270bd4 | 0x0 |
GetMonitorInfoW | 0x0 | 0x68dbb8 | 0x28d3d8 | 0x270bd8 | 0x0 |
CheckMenuItem | 0x0 | 0x68dbbc | 0x28d3dc | 0x270bdc | 0x0 |
CharUpperW | 0x0 | 0x68dbc0 | 0x28d3e0 | 0x270be0 | 0x0 |
DefWindowProcW | 0x0 | 0x68dbc4 | 0x28d3e4 | 0x270be4 | 0x0 |
GetForegroundWindow | 0x0 | 0x68dbc8 | 0x28d3e8 | 0x270be8 | 0x0 |
EnableWindow | 0x0 | 0x68dbcc | 0x28d3ec | 0x270bec | 0x0 |
GetWindowThreadProcessId | 0x0 | 0x68dbd0 | 0x28d3f0 | 0x270bf0 | 0x0 |
RedrawWindow | 0x0 | 0x68dbd4 | 0x28d3f4 | 0x270bf4 | 0x0 |
EndPaint | 0x0 | 0x68dbd8 | 0x28d3f8 | 0x270bf8 | 0x0 |
MsgWaitForMultipleObjectsEx | 0x0 | 0x68dbdc | 0x28d3fc | 0x270bfc | 0x0 |
LoadKeyboardLayoutW | 0x0 | 0x68dbe0 | 0x28d400 | 0x270c00 | 0x0 |
ActivateKeyboardLayout | 0x0 | 0x68dbe4 | 0x28d404 | 0x270c04 | 0x0 |
GetParent | 0x0 | 0x68dbe8 | 0x28d408 | 0x270c08 | 0x0 |
InsertMenuItemW | 0x0 | 0x68dbec | 0x28d40c | 0x270c0c | 0x0 |
MonitorFromRect | 0x0 | 0x68dbf0 | 0x28d410 | 0x270c10 | 0x0 |
GetPropW | 0x0 | 0x68dbf4 | 0x28d414 | 0x270c14 | 0x0 |
MessageBoxW | 0x0 | 0x68dbf8 | 0x28d418 | 0x270c18 | 0x0 |
SetPropW | 0x0 | 0x68dbfc | 0x28d41c | 0x270c1c | 0x0 |
UpdateWindow | 0x0 | 0x68dc00 | 0x28d420 | 0x270c20 | 0x0 |
MsgWaitForMultipleObjects | 0x0 | 0x68dc04 | 0x28d424 | 0x270c24 | 0x0 |
DestroyMenu | 0x0 | 0x68dc08 | 0x28d428 | 0x270c28 | 0x0 |
SetWindowsHookExW | 0x0 | 0x68dc0c | 0x28d42c | 0x270c2c | 0x0 |
EmptyClipboard | 0x0 | 0x68dc10 | 0x28d430 | 0x270c30 | 0x0 |
GetDlgItem | 0x0 | 0x68dc14 | 0x28d434 | 0x270c34 | 0x0 |
AdjustWindowRectEx | 0x0 | 0x68dc18 | 0x28d438 | 0x270c38 | 0x0 |
IsWindow | 0x0 | 0x68dc1c | 0x28d43c | 0x270c3c | 0x0 |
DrawIcon | 0x0 | 0x68dc20 | 0x28d440 | 0x270c40 | 0x0 |
EnumThreadWindows | 0x0 | 0x68dc24 | 0x28d444 | 0x270c44 | 0x0 |
InvalidateRect | 0x0 | 0x68dc28 | 0x28d448 | 0x270c48 | 0x0 |
GetKeyboardState | 0x0 | 0x68dc2c | 0x28d44c | 0x270c4c | 0x0 |
ScreenToClient | 0x0 | 0x68dc30 | 0x28d450 | 0x270c50 | 0x0 |
DrawFrameControl | 0x0 | 0x68dc34 | 0x28d454 | 0x270c54 | 0x0 |
SetCursor | 0x0 | 0x68dc38 | 0x28d458 | 0x270c58 | 0x0 |
CreateIcon | 0x0 | 0x68dc3c | 0x28d45c | 0x270c5c | 0x0 |
RemoveMenu | 0x0 | 0x68dc40 | 0x28d460 | 0x270c60 | 0x0 |
GetKeyboardLayoutNameW | 0x0 | 0x68dc44 | 0x28d464 | 0x270c64 | 0x0 |
OpenClipboard | 0x0 | 0x68dc48 | 0x28d468 | 0x270c68 | 0x0 |
TranslateMessage | 0x0 | 0x68dc4c | 0x28d46c | 0x270c6c | 0x0 |
MapWindowPoints | 0x0 | 0x68dc50 | 0x28d470 | 0x270c70 | 0x0 |
EnumDisplayMonitors | 0x0 | 0x68dc54 | 0x28d474 | 0x270c74 | 0x0 |
CallWindowProcW | 0x0 | 0x68dc58 | 0x28d478 | 0x270c78 | 0x0 |
CloseClipboard | 0x0 | 0x68dc5c | 0x28d47c | 0x270c7c | 0x0 |
DestroyCursor | 0x0 | 0x68dc60 | 0x28d480 | 0x270c80 | 0x0 |
CopyIcon | 0x0 | 0x68dc64 | 0x28d484 | 0x270c84 | 0x0 |
PostQuitMessage | 0x0 | 0x68dc68 | 0x28d488 | 0x270c88 | 0x0 |
ShowScrollBar | 0x0 | 0x68dc6c | 0x28d48c | 0x270c8c | 0x0 |
EnableMenuItem | 0x0 | 0x68dc70 | 0x28d490 | 0x270c90 | 0x0 |
HideCaret | 0x0 | 0x68dc74 | 0x28d494 | 0x270c94 | 0x0 |
FindWindowExW | 0x0 | 0x68dc78 | 0x28d498 | 0x270c98 | 0x0 |
LoadIconW | 0x0 | 0x68dc7c | 0x28d49c | 0x270c9c | 0x0 |
SystemParametersInfoW | 0x0 | 0x68dc80 | 0x28d4a0 | 0x270ca0 | 0x0 |
MonitorFromPoint | 0x0 | 0x68dc84 | 0x28d4a4 | 0x270ca4 | 0x0 |
GetWindow | 0x0 | 0x68dc88 | 0x28d4a8 | 0x270ca8 | 0x0 |
GetWindowRect | 0x0 | 0x68dc8c | 0x28d4ac | 0x270cac | 0x0 |
GetWindowLongW | 0x0 | 0x68dc90 | 0x28d4b0 | 0x270cb0 | 0x0 |
InsertMenuW | 0x0 | 0x68dc94 | 0x28d4b4 | 0x270cb4 | 0x0 |
IsWindowEnabled | 0x0 | 0x68dc98 | 0x28d4b8 | 0x270cb8 | 0x0 |
IsDialogMessageA | 0x0 | 0x68dc9c | 0x28d4bc | 0x270cbc | 0x0 |
FindWindowW | 0x0 | 0x68dca0 | 0x28d4c0 | 0x270cc0 | 0x0 |
GetKeyboardLayout | 0x0 | 0x68dca4 | 0x28d4c4 | 0x270cc4 | 0x0 |
DeleteMenu | 0x0 | 0x68dca8 | 0x28d4c8 | 0x270cc8 | 0x0 |
version.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFileVersionInfoSizeW | 0x0 | 0x68dcb0 | 0x28d4d0 | 0x270cd0 | 0x0 |
VerQueryValueW | 0x0 | 0x68dcb4 | 0x28d4d4 | 0x270cd4 | 0x0 |
GetFileVersionInfoW | 0x0 | 0x68dcb8 | 0x28d4d8 | 0x270cd8 | 0x0 |
URLMON.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
URLDownloadToFileW | 0x0 | 0x68dcc0 | 0x28d4e0 | 0x270ce0 | 0x0 |
oleaut32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x0 | 0x68dcc8 | 0x28d4e8 | 0x270ce8 | 0x0 |
VariantClear | 0x0 | 0x68dccc | 0x28d4ec | 0x270cec | 0x0 |
VariantInit | 0x0 | 0x68dcd0 | 0x28d4f0 | 0x270cf0 | 0x0 |
GetErrorInfo | 0x0 | 0x68dcd4 | 0x28d4f4 | 0x270cf4 | 0x0 |
SysReAllocStringLen | 0x0 | 0x68dcd8 | 0x28d4f8 | 0x270cf8 | 0x0 |
SafeArrayCreate | 0x0 | 0x68dcdc | 0x28d4fc | 0x270cfc | 0x0 |
SysAllocStringLen | 0x0 | 0x68dce0 | 0x28d500 | 0x270d00 | 0x0 |
SafeArrayPtrOfIndex | 0x0 | 0x68dce4 | 0x28d504 | 0x270d04 | 0x0 |
SafeArrayGetUBound | 0x0 | 0x68dce8 | 0x28d508 | 0x270d08 | 0x0 |
SafeArrayGetLBound | 0x0 | 0x68dcec | 0x28d50c | 0x270d0c | 0x0 |
VariantCopy | 0x0 | 0x68dcf0 | 0x28d510 | 0x270d10 | 0x0 |
VariantChangeType | 0x0 | 0x68dcf4 | 0x28d514 | 0x270d14 | 0x0 |
advapi32.dll (17)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegSetValueExW | 0x0 | 0x68dcfc | 0x28d51c | 0x270d1c | 0x0 |
RegConnectRegistryW | 0x0 | 0x68dd00 | 0x28d520 | 0x270d20 | 0x0 |
RegEnumKeyExW | 0x0 | 0x68dd04 | 0x28d524 | 0x270d24 | 0x0 |
RegLoadKeyW | 0x0 | 0x68dd08 | 0x28d528 | 0x270d28 | 0x0 |
RegDeleteKeyW | 0x0 | 0x68dd0c | 0x28d52c | 0x270d2c | 0x0 |
RegOpenKeyExW | 0x0 | 0x68dd10 | 0x28d530 | 0x270d30 | 0x0 |
RegQueryInfoKeyW | 0x0 | 0x68dd14 | 0x28d534 | 0x270d34 | 0x0 |
RegUnLoadKeyW | 0x0 | 0x68dd18 | 0x28d538 | 0x270d38 | 0x0 |
RegSaveKeyW | 0x0 | 0x68dd1c | 0x28d53c | 0x270d3c | 0x0 |
RegDeleteValueW | 0x0 | 0x68dd20 | 0x28d540 | 0x270d40 | 0x0 |
RegReplaceKeyW | 0x0 | 0x68dd24 | 0x28d544 | 0x270d44 | 0x0 |
RegFlushKey | 0x0 | 0x68dd28 | 0x28d548 | 0x270d48 | 0x0 |
RegQueryValueExW | 0x0 | 0x68dd2c | 0x28d54c | 0x270d4c | 0x0 |
RegEnumValueW | 0x0 | 0x68dd30 | 0x28d550 | 0x270d50 | 0x0 |
RegCloseKey | 0x0 | 0x68dd34 | 0x28d554 | 0x270d54 | 0x0 |
RegCreateKeyExW | 0x0 | 0x68dd38 | 0x28d558 | 0x270d58 | 0x0 |
RegRestoreKeyW | 0x0 | 0x68dd3c | 0x28d55c | 0x270d5c | 0x0 |
netapi32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetWkstaGetInfo | 0x0 | 0x68dd44 | 0x28d564 | 0x270d64 | 0x0 |
NetApiBufferFree | 0x0 | 0x68dd48 | 0x28d568 | 0x270d68 | 0x0 |
msvcrt.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
memcpy | 0x0 | 0x68dd50 | 0x28d570 | 0x270d70 | 0x0 |
memset | 0x0 | 0x68dd54 | 0x28d574 | 0x270d74 | 0x0 |
kernel32.dll (107)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetACP | 0x0 | 0x68dd5c | 0x28d57c | 0x270d7c | 0x0 |
LocalFree | 0x0 | 0x68dd60 | 0x28d580 | 0x270d80 | 0x0 |
CloseHandle | 0x0 | 0x68dd64 | 0x28d584 | 0x270d84 | 0x0 |
SizeofResource | 0x0 | 0x68dd68 | 0x28d588 | 0x270d88 | 0x0 |
GetCurrentProcessId | 0x0 | 0x68dd6c | 0x28d58c | 0x270d8c | 0x0 |
VirtualProtect | 0x0 | 0x68dd70 | 0x28d590 | 0x270d90 | 0x0 |
QueryPerformanceFrequency | 0x0 | 0x68dd74 | 0x28d594 | 0x270d94 | 0x0 |
IsDebuggerPresent | 0x0 | 0x68dd78 | 0x28d598 | 0x270d98 | 0x0 |
VirtualFree | 0x0 | 0x68dd7c | 0x28d59c | 0x270d9c | 0x0 |
GetFullPathNameW | 0x0 | 0x68dd80 | 0x28d5a0 | 0x270da0 | 0x0 |
ExitProcess | 0x0 | 0x68dd84 | 0x28d5a4 | 0x270da4 | 0x0 |
HeapAlloc | 0x0 | 0x68dd88 | 0x28d5a8 | 0x270da8 | 0x0 |
GetCPInfoExW | 0x0 | 0x68dd8c | 0x28d5ac | 0x270dac | 0x0 |
RtlUnwind | 0x0 | 0x68dd90 | 0x28d5b0 | 0x270db0 | 0x0 |
GetCPInfo | 0x0 | 0x68dd94 | 0x28d5b4 | 0x270db4 | 0x0 |
EnumSystemLocalesW | 0x0 | 0x68dd98 | 0x28d5b8 | 0x270db8 | 0x0 |
GetStdHandle | 0x0 | 0x68dd9c | 0x28d5bc | 0x270dbc | 0x0 |
GetModuleHandleW | 0x0 | 0x68dda0 | 0x28d5c0 | 0x270dc0 | 0x0 |
FreeLibrary | 0x0 | 0x68dda4 | 0x28d5c4 | 0x270dc4 | 0x0 |
TryEnterCriticalSection | 0x0 | 0x68dda8 | 0x28d5c8 | 0x270dc8 | 0x0 |
HeapDestroy | 0x0 | 0x68ddac | 0x28d5cc | 0x270dcc | 0x0 |
ReadFile | 0x0 | 0x68ddb0 | 0x28d5d0 | 0x270dd0 | 0x0 |
HeapSize | 0x0 | 0x68ddb4 | 0x28d5d4 | 0x270dd4 | 0x0 |
GetLastError | 0x0 | 0x68ddb8 | 0x28d5d8 | 0x270dd8 | 0x0 |
GetModuleFileNameW | 0x0 | 0x68ddbc | 0x28d5dc | 0x270ddc | 0x0 |
SetLastError | 0x0 | 0x68ddc0 | 0x28d5e0 | 0x270de0 | 0x0 |
GlobalAlloc | 0x0 | 0x68ddc4 | 0x28d5e4 | 0x270de4 | 0x0 |
GlobalUnlock | 0x0 | 0x68ddc8 | 0x28d5e8 | 0x270de8 | 0x0 |
FindResourceW | 0x0 | 0x68ddcc | 0x28d5ec | 0x270dec | 0x0 |
CreateThread | 0x0 | 0x68ddd0 | 0x28d5f0 | 0x270df0 | 0x0 |
CompareStringW | 0x0 | 0x68ddd4 | 0x28d5f4 | 0x270df4 | 0x0 |
LoadLibraryA | 0x0 | 0x68ddd8 | 0x28d5f8 | 0x270df8 | 0x0 |
ResetEvent | 0x0 | 0x68dddc | 0x28d5fc | 0x270dfc | 0x0 |
MulDiv | 0x0 | 0x68dde0 | 0x28d600 | 0x270e00 | 0x0 |
FreeResource | 0x0 | 0x68dde4 | 0x28d604 | 0x270e04 | 0x0 |
GetVersion | 0x0 | 0x68dde8 | 0x28d608 | 0x270e08 | 0x0 |
RaiseException | 0x0 | 0x68ddec | 0x28d60c | 0x270e0c | 0x0 |
GlobalAddAtomW | 0x0 | 0x68ddf0 | 0x28d610 | 0x270e10 | 0x0 |
FormatMessageW | 0x0 | 0x68ddf4 | 0x28d614 | 0x270e14 | 0x0 |
SwitchToThread | 0x0 | 0x68ddf8 | 0x28d618 | 0x270e18 | 0x0 |
GetExitCodeThread | 0x0 | 0x68ddfc | 0x28d61c | 0x270e1c | 0x0 |
GetCurrentThread | 0x0 | 0x68de00 | 0x28d620 | 0x270e20 | 0x0 |
LoadLibraryExW | 0x0 | 0x68de04 | 0x28d624 | 0x270e24 | 0x0 |
LockResource | 0x0 | 0x68de08 | 0x28d628 | 0x270e28 | 0x0 |
GetCurrentThreadId | 0x0 | 0x68de0c | 0x28d62c | 0x270e2c | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x68de10 | 0x28d630 | 0x270e30 | 0x0 |
VirtualQuery | 0x0 | 0x68de14 | 0x28d634 | 0x270e34 | 0x0 |
GlobalFindAtomW | 0x0 | 0x68de18 | 0x28d638 | 0x270e38 | 0x0 |
VirtualQueryEx | 0x0 | 0x68de1c | 0x28d63c | 0x270e3c | 0x0 |
GlobalFree | 0x0 | 0x68de20 | 0x28d640 | 0x270e40 | 0x0 |
Sleep | 0x0 | 0x68de24 | 0x28d644 | 0x270e44 | 0x0 |
EnterCriticalSection | 0x0 | 0x68de28 | 0x28d648 | 0x270e48 | 0x0 |
SetFilePointer | 0x0 | 0x68de2c | 0x28d64c | 0x270e4c | 0x0 |
LoadResource | 0x0 | 0x68de30 | 0x28d650 | 0x270e50 | 0x0 |
SuspendThread | 0x0 | 0x68de34 | 0x28d654 | 0x270e54 | 0x0 |
GetTickCount | 0x0 | 0x68de38 | 0x28d658 | 0x270e58 | 0x0 |
GetStartupInfoW | 0x0 | 0x68de3c | 0x28d65c | 0x270e5c | 0x0 |
GlobalDeleteAtom | 0x0 | 0x68de40 | 0x28d660 | 0x270e60 | 0x0 |
GetFileAttributesW | 0x0 | 0x68de44 | 0x28d664 | 0x270e64 | 0x0 |
InitializeCriticalSection | 0x0 | 0x68de48 | 0x28d668 | 0x270e68 | 0x0 |
GetThreadPriority | 0x0 | 0x68de4c | 0x28d66c | 0x270e6c | 0x0 |
GetCurrentProcess | 0x0 | 0x68de50 | 0x28d670 | 0x270e70 | 0x0 |
SetThreadPriority | 0x0 | 0x68de54 | 0x28d674 | 0x270e74 | 0x0 |
GlobalLock | 0x0 | 0x68de58 | 0x28d678 | 0x270e78 | 0x0 |
VirtualAlloc | 0x0 | 0x68de5c | 0x28d67c | 0x270e7c | 0x0 |
GetSystemInfo | 0x0 | 0x68de60 | 0x28d680 | 0x270e80 | 0x0 |
GetCommandLineW | 0x0 | 0x68de64 | 0x28d684 | 0x270e84 | 0x0 |
LeaveCriticalSection | 0x0 | 0x68de68 | 0x28d688 | 0x270e88 | 0x0 |
GetProcAddress | 0x0 | 0x68de6c | 0x28d68c | 0x270e8c | 0x0 |
ResumeThread | 0x0 | 0x68de70 | 0x28d690 | 0x270e90 | 0x0 |
GetVersionExW | 0x0 | 0x68de74 | 0x28d694 | 0x270e94 | 0x0 |
VerifyVersionInfoW | 0x0 | 0x68de78 | 0x28d698 | 0x270e98 | 0x0 |
HeapCreate | 0x0 | 0x68de7c | 0x28d69c | 0x270e9c | 0x0 |
VerSetConditionMask | 0x0 | 0x68de80 | 0x28d6a0 | 0x270ea0 | 0x0 |
GetDiskFreeSpaceW | 0x0 | 0x68de84 | 0x28d6a4 | 0x270ea4 | 0x0 |
FindFirstFileW | 0x0 | 0x68de88 | 0x28d6a8 | 0x270ea8 | 0x0 |
GetUserDefaultUILanguage | 0x0 | 0x68de8c | 0x28d6ac | 0x270eac | 0x0 |
lstrlenW | 0x0 | 0x68de90 | 0x28d6b0 | 0x270eb0 | 0x0 |
QueryPerformanceCounter | 0x0 | 0x68de94 | 0x28d6b4 | 0x270eb4 | 0x0 |
SetEndOfFile | 0x0 | 0x68de98 | 0x28d6b8 | 0x270eb8 | 0x0 |
HeapFree | 0x0 | 0x68de9c | 0x28d6bc | 0x270ebc | 0x0 |
WideCharToMultiByte | 0x0 | 0x68dea0 | 0x28d6c0 | 0x270ec0 | 0x0 |
FindClose | 0x0 | 0x68dea4 | 0x28d6c4 | 0x270ec4 | 0x0 |
MultiByteToWideChar | 0x0 | 0x68dea8 | 0x28d6c8 | 0x270ec8 | 0x0 |
LoadLibraryW | 0x0 | 0x68deac | 0x28d6cc | 0x270ecc | 0x0 |
SetEvent | 0x0 | 0x68deb0 | 0x28d6d0 | 0x270ed0 | 0x0 |
CreateFileW | 0x0 | 0x68deb4 | 0x28d6d4 | 0x270ed4 | 0x0 |
GetLocaleInfoW | 0x0 | 0x68deb8 | 0x28d6d8 | 0x270ed8 | 0x0 |
EnumResourceNamesW | 0x0 | 0x68debc | 0x28d6dc | 0x270edc | 0x0 |
GetLocalTime | 0x0 | 0x68dec0 | 0x28d6e0 | 0x270ee0 | 0x0 |
GetEnvironmentVariableW | 0x0 | 0x68dec4 | 0x28d6e4 | 0x270ee4 | 0x0 |
WaitForSingleObject | 0x0 | 0x68dec8 | 0x28d6e8 | 0x270ee8 | 0x0 |
WriteFile | 0x0 | 0x68decc | 0x28d6ec | 0x270eec | 0x0 |
ExitThread | 0x0 | 0x68ded0 | 0x28d6f0 | 0x270ef0 | 0x0 |
DeleteCriticalSection | 0x0 | 0x68ded4 | 0x28d6f4 | 0x270ef4 | 0x0 |
TlsGetValue | 0x0 | 0x68ded8 | 0x28d6f8 | 0x270ef8 | 0x0 |
GetDateFormatW | 0x0 | 0x68dedc | 0x28d6fc | 0x270efc | 0x0 |
SetErrorMode | 0x0 | 0x68dee0 | 0x28d700 | 0x270f00 | 0x0 |
IsValidLocale | 0x0 | 0x68dee4 | 0x28d704 | 0x270f04 | 0x0 |
TlsSetValue | 0x0 | 0x68dee8 | 0x28d708 | 0x270f08 | 0x0 |
GetSystemDefaultUILanguage | 0x0 | 0x68deec | 0x28d70c | 0x270f0c | 0x0 |
EnumCalendarInfoW | 0x0 | 0x68def0 | 0x28d710 | 0x270f10 | 0x0 |
LocalAlloc | 0x0 | 0x68def4 | 0x28d714 | 0x270f14 | 0x0 |
CreateEventW | 0x0 | 0x68def8 | 0x28d718 | 0x270f18 | 0x0 |
WaitForMultipleObjectsEx | 0x0 | 0x68defc | 0x28d71c | 0x270f1c | 0x0 |
SetThreadLocale | 0x0 | 0x68df00 | 0x28d720 | 0x270f20 | 0x0 |
GetThreadLocale | 0x0 | 0x68df04 | 0x28d724 | 0x270f24 | 0x0 |
ole32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IsEqualGUID | 0x0 | 0x68df0c | 0x28d72c | 0x270f2c | 0x0 |
OleInitialize | 0x0 | 0x68df10 | 0x28d730 | 0x270f30 | 0x0 |
OleUninitialize | 0x0 | 0x68df14 | 0x28d734 | 0x270f34 | 0x0 |
CoInitialize | 0x0 | 0x68df18 | 0x28d738 | 0x270f38 | 0x0 |
CoCreateInstance | 0x0 | 0x68df1c | 0x28d73c | 0x270f3c | 0x0 |
CoUninitialize | 0x0 | 0x68df20 | 0x28d740 | 0x270f40 | 0x0 |
CoTaskMemFree | 0x0 | 0x68df24 | 0x28d744 | 0x270f44 | 0x0 |
CoTaskMemAlloc | 0x0 | 0x68df28 | 0x28d748 | 0x270f48 | 0x0 |
gdi32.dll (105)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Pie | 0x0 | 0x68df30 | 0x28d750 | 0x270f50 | 0x0 |
SetBkMode | 0x0 | 0x68df34 | 0x28d754 | 0x270f54 | 0x0 |
CreateCompatibleBitmap | 0x0 | 0x68df38 | 0x28d758 | 0x270f58 | 0x0 |
GetEnhMetaFileHeader | 0x0 | 0x68df3c | 0x28d75c | 0x270f5c | 0x0 |
RectVisible | 0x0 | 0x68df40 | 0x28d760 | 0x270f60 | 0x0 |
AngleArc | 0x0 | 0x68df44 | 0x28d764 | 0x270f64 | 0x0 |
SetAbortProc | 0x0 | 0x68df48 | 0x28d768 | 0x270f68 | 0x0 |
GetTextColor | 0x0 | 0x68df4c | 0x28d76c | 0x270f6c | 0x0 |
SetTextColor | 0x0 | 0x68df50 | 0x28d770 | 0x270f70 | 0x0 |
StretchBlt | 0x0 | 0x68df54 | 0x28d774 | 0x270f74 | 0x0 |
RoundRect | 0x0 | 0x68df58 | 0x28d778 | 0x270f78 | 0x0 |
RestoreDC | 0x0 | 0x68df5c | 0x28d77c | 0x270f7c | 0x0 |
SetRectRgn | 0x0 | 0x68df60 | 0x28d780 | 0x270f80 | 0x0 |
GetTextMetricsW | 0x0 | 0x68df64 | 0x28d784 | 0x270f84 | 0x0 |
GetWindowOrgEx | 0x0 | 0x68df68 | 0x28d788 | 0x270f88 | 0x0 |
CreatePalette | 0x0 | 0x68df6c | 0x28d78c | 0x270f8c | 0x0 |
PolyBezierTo | 0x0 | 0x68df70 | 0x28d790 | 0x270f90 | 0x0 |
CreateICW | 0x0 | 0x68df74 | 0x28d794 | 0x270f94 | 0x0 |
CreateDCW | 0x0 | 0x68df78 | 0x28d798 | 0x270f98 | 0x0 |
GetStockObject | 0x0 | 0x68df7c | 0x28d79c | 0x270f9c | 0x0 |
CreateSolidBrush | 0x0 | 0x68df80 | 0x28d7a0 | 0x270fa0 | 0x0 |
GetBkMode | 0x0 | 0x68df84 | 0x28d7a4 | 0x270fa4 | 0x0 |
Polygon | 0x0 | 0x68df88 | 0x28d7a8 | 0x270fa8 | 0x0 |
MoveToEx | 0x0 | 0x68df8c | 0x28d7ac | 0x270fac | 0x0 |
PlayEnhMetaFile | 0x0 | 0x68df90 | 0x28d7b0 | 0x270fb0 | 0x0 |
Ellipse | 0x0 | 0x68df94 | 0x28d7b4 | 0x270fb4 | 0x0 |
StartPage | 0x0 | 0x68df98 | 0x28d7b8 | 0x270fb8 | 0x0 |
GetBitmapBits | 0x0 | 0x68df9c | 0x28d7bc | 0x270fbc | 0x0 |
StartDocW | 0x0 | 0x68dfa0 | 0x28d7c0 | 0x270fc0 | 0x0 |
AbortDoc | 0x0 | 0x68dfa4 | 0x28d7c4 | 0x270fc4 | 0x0 |
GetSystemPaletteEntries | 0x0 | 0x68dfa8 | 0x28d7c8 | 0x270fc8 | 0x0 |
GetEnhMetaFileBits | 0x0 | 0x68dfac | 0x28d7cc | 0x270fcc | 0x0 |
GetEnhMetaFilePaletteEntries | 0x0 | 0x68dfb0 | 0x28d7d0 | 0x270fd0 | 0x0 |
CreatePenIndirect | 0x0 | 0x68dfb4 | 0x28d7d4 | 0x270fd4 | 0x0 |
CreateFontIndirectW | 0x0 | 0x68dfb8 | 0x28d7d8 | 0x270fd8 | 0x0 |
PolyBezier | 0x0 | 0x68dfbc | 0x28d7dc | 0x270fdc | 0x0 |
EndDoc | 0x0 | 0x68dfc0 | 0x28d7e0 | 0x270fe0 | 0x0 |
GetObjectW | 0x0 | 0x68dfc4 | 0x28d7e4 | 0x270fe4 | 0x0 |
GetCurrentObject | 0x0 | 0x68dfc8 | 0x28d7e8 | 0x270fe8 | 0x0 |
GetWinMetaFileBits | 0x0 | 0x68dfcc | 0x28d7ec | 0x270fec | 0x0 |
SetROP2 | 0x0 | 0x68dfd0 | 0x28d7f0 | 0x270ff0 | 0x0 |
GetEnhMetaFileDescriptionW | 0x0 | 0x68dfd4 | 0x28d7f4 | 0x270ff4 | 0x0 |
ArcTo | 0x0 | 0x68dfd8 | 0x28d7f8 | 0x270ff8 | 0x0 |
Arc | 0x0 | 0x68dfdc | 0x28d7fc | 0x270ffc | 0x0 |
SelectPalette | 0x0 | 0x68dfe0 | 0x28d800 | 0x271000 | 0x0 |
SetGraphicsMode | 0x0 | 0x68dfe4 | 0x28d804 | 0x271004 | 0x0 |
ExcludeClipRect | 0x0 | 0x68dfe8 | 0x28d808 | 0x271008 | 0x0 |
MaskBlt | 0x0 | 0x68dfec | 0x28d80c | 0x27100c | 0x0 |
SetWindowOrgEx | 0x0 | 0x68dff0 | 0x28d810 | 0x271010 | 0x0 |
EndPage | 0x0 | 0x68dff4 | 0x28d814 | 0x271014 | 0x0 |
DeleteEnhMetaFile | 0x0 | 0x68dff8 | 0x28d818 | 0x271018 | 0x0 |
Chord | 0x0 | 0x68dffc | 0x28d81c | 0x27101c | 0x0 |
SetDIBits | 0x0 | 0x68e000 | 0x28d820 | 0x271020 | 0x0 |
GetViewportOrgEx | 0x0 | 0x68e004 | 0x28d824 | 0x271024 | 0x0 |
SetViewportOrgEx | 0x0 | 0x68e008 | 0x28d828 | 0x271028 | 0x0 |
CreateRectRgn | 0x0 | 0x68e00c | 0x28d82c | 0x27102c | 0x0 |
RealizePalette | 0x0 | 0x68e010 | 0x28d830 | 0x271030 | 0x0 |
SetDIBColorTable | 0x0 | 0x68e014 | 0x28d834 | 0x271034 | 0x0 |
GetDIBColorTable | 0x0 | 0x68e018 | 0x28d838 | 0x271038 | 0x0 |
CreateBrushIndirect | 0x0 | 0x68e01c | 0x28d83c | 0x27103c | 0x0 |
PatBlt | 0x0 | 0x68e020 | 0x28d840 | 0x271040 | 0x0 |
SetEnhMetaFileBits | 0x0 | 0x68e024 | 0x28d844 | 0x271044 | 0x0 |
Rectangle | 0x0 | 0x68e028 | 0x28d848 | 0x271048 | 0x0 |
SaveDC | 0x0 | 0x68e02c | 0x28d84c | 0x27104c | 0x0 |
DeleteDC | 0x0 | 0x68e030 | 0x28d850 | 0x271050 | 0x0 |
BitBlt | 0x0 | 0x68e034 | 0x28d854 | 0x271054 | 0x0 |
SetWorldTransform | 0x0 | 0x68e038 | 0x28d858 | 0x271058 | 0x0 |
FrameRgn | 0x0 | 0x68e03c | 0x28d85c | 0x27105c | 0x0 |
GetDeviceCaps | 0x0 | 0x68e040 | 0x28d860 | 0x271060 | 0x0 |
GetTextExtentPoint32W | 0x0 | 0x68e044 | 0x28d864 | 0x271064 | 0x0 |
GetClipBox | 0x0 | 0x68e048 | 0x28d868 | 0x271068 | 0x0 |
IntersectClipRect | 0x0 | 0x68e04c | 0x28d86c | 0x27106c | 0x0 |
Polyline | 0x0 | 0x68e050 | 0x28d870 | 0x271070 | 0x0 |
CreateBitmap | 0x0 | 0x68e054 | 0x28d874 | 0x271074 | 0x0 |
CombineRgn | 0x0 | 0x68e058 | 0x28d878 | 0x271078 | 0x0 |
SetWinMetaFileBits | 0x0 | 0x68e05c | 0x28d87c | 0x27107c | 0x0 |
GetStretchBltMode | 0x0 | 0x68e060 | 0x28d880 | 0x271080 | 0x0 |
CreateDIBitmap | 0x0 | 0x68e064 | 0x28d884 | 0x271084 | 0x0 |
SetStretchBltMode | 0x0 | 0x68e068 | 0x28d888 | 0x271088 | 0x0 |
GetDIBits | 0x0 | 0x68e06c | 0x28d88c | 0x27108c | 0x0 |
CreateDIBSection | 0x0 | 0x68e070 | 0x28d890 | 0x271090 | 0x0 |
ExtCreateRegion | 0x0 | 0x68e074 | 0x28d894 | 0x271094 | 0x0 |
LineTo | 0x0 | 0x68e078 | 0x28d898 | 0x271098 | 0x0 |
GetRgnBox | 0x0 | 0x68e07c | 0x28d89c | 0x27109c | 0x0 |
EnumFontsW | 0x0 | 0x68e080 | 0x28d8a0 | 0x2710a0 | 0x0 |
CreateHalftonePalette | 0x0 | 0x68e084 | 0x28d8a4 | 0x2710a4 | 0x0 |
SelectObject | 0x0 | 0x68e088 | 0x28d8a8 | 0x2710a8 | 0x0 |
DeleteObject | 0x0 | 0x68e08c | 0x28d8ac | 0x2710ac | 0x0 |
ExtFloodFill | 0x0 | 0x68e090 | 0x28d8b0 | 0x2710b0 | 0x0 |
UnrealizeObject | 0x0 | 0x68e094 | 0x28d8b4 | 0x2710b4 | 0x0 |
CopyEnhMetaFileW | 0x0 | 0x68e098 | 0x28d8b8 | 0x2710b8 | 0x0 |
SetBkColor | 0x0 | 0x68e09c | 0x28d8bc | 0x2710bc | 0x0 |
CreateCompatibleDC | 0x0 | 0x68e0a0 | 0x28d8c0 | 0x2710c0 | 0x0 |
GetBrushOrgEx | 0x0 | 0x68e0a4 | 0x28d8c4 | 0x2710c4 | 0x0 |
GetCurrentPositionEx | 0x0 | 0x68e0a8 | 0x28d8c8 | 0x2710c8 | 0x0 |
CreateRoundRectRgn | 0x0 | 0x68e0ac | 0x28d8cc | 0x2710cc | 0x0 |
GetTextExtentPointW | 0x0 | 0x68e0b0 | 0x28d8d0 | 0x2710d0 | 0x0 |
ExtTextOutW | 0x0 | 0x68e0b4 | 0x28d8d4 | 0x2710d4 | 0x0 |
SetBrushOrgEx | 0x0 | 0x68e0b8 | 0x28d8d8 | 0x2710d8 | 0x0 |
GetPixel | 0x0 | 0x68e0bc | 0x28d8dc | 0x2710dc | 0x0 |
GdiFlush | 0x0 | 0x68e0c0 | 0x28d8e0 | 0x2710e0 | 0x0 |
SetPixel | 0x0 | 0x68e0c4 | 0x28d8e4 | 0x2710e4 | 0x0 |
EnumFontFamiliesExW | 0x0 | 0x68e0c8 | 0x28d8e8 | 0x2710e8 | 0x0 |
StretchDIBits | 0x0 | 0x68e0cc | 0x28d8ec | 0x2710ec | 0x0 |
GetPaletteEntries | 0x0 | 0x68e0d0 | 0x28d8f0 | 0x2710f0 | 0x0 |
Exports (3)
»
Api name | EAT Address | Ordinal |
---|---|---|
TMethodImplementationIntercept | 0xda408 | 0x3 |
__dbk_fcall_wrapper | 0x1069c | 0x2 |
dbkFCallWrapperAddr | 0x27563c | 0x1 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
ztarter.exe | 1 | 0x00400000 | 0x006ECFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x002B0000 | 0x002B0FFF | First Execution | - | 32-bit | 0x002B0FE2 |
![]() |
![]() |
...
|
buffer | 1 | 0x002B0000 | 0x002B0FFF | Content Changed | - | 32-bit | 0x002B0FC8 |
![]() |
![]() |
...
|
ztarter.exe | 1 | 0x00400000 | 0x006ECFFF | Final Dump | - | 32-bit | - |
![]() |
![]() |
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\-4ij7y-zIo-dhcoiIV.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\-vbAQ74ugAbPjkEt.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\0C4Q3lCUGrjgBWBW_0y.flv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\0osVjDZjBJvKoUQGP.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\1H7TVT25t.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\2hc0nLdqeXfTqNl.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\304-.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\3VRMss5BV-ngBLL642x.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\5WmPRJ5suanW.mkv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\5_dX0Aaaa76daX6ovV1f.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\7Q9liHaXsdf.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\7xqky_KR1phllF0lUBH.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\7ZPfBAbmM5yoEBSb3T.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\8eWaTb.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\8mJLvTqgcpH-zx5.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\9zcK9yFvhp38_3ycric.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\AalPBDgDSgBqLTp 4TZ.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\adim4yK7GC8JdG2.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\aWeYTbu-8Qx30.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\b3Wd.ots.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\bas277gWUmBLlLIEKTn.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\biGPbmuUIxOTke.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\BLitS9HIT9Qz.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\BQPd1Wx n.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\BvoMVx.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\BZ9fqjq_C0.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ccKqRvGHdONou.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\cGWVj3zjOM.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CO u8DbP08g8.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\D-ZBvd0l.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Dy5IW1xWAqSu23GIuS.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\e6OEO.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\eI7QTrX.flv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\gsQ-EPB.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Ia7vXnn.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\i_4q7DX_I75G.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\JPFZDi_iA.mkv.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\jrQlzJ0Gbx.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ju-g2y7wqsKhm.ots.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\JuzpETj0m5mSI_GD8URT.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\JZ8ftz1nduVAZau6pD1J.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\kf0cD8ISIQxuHW_XccTx.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\kgYaSl_t9.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\KjT4 HwzgaTQ5.flv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\kviaNKI4z6o.ots.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\maHvK_h22n001r8G.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\MFW8IZ.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\mn7dUzVEpT7myW.flv.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Mq6WDLR_stC6S.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\My Pictures.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\M_3Qky P 4q7L.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\N1mlh_LBIUTsWGpL.mkv.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\n3ype.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\nmLnE9JG9deI.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\n_x6gNftmTgsMiPC2h.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\O-Rd72Ki9uU-FgTEP 8.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\OGRcAwhxVhr5uaOlpptg.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\PfT_29aBkkq.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\pp2-cOmu2l2wp3nZR.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\QYrNt_.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\RfWBl.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Roaming.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\RpdwIZgl7_.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\rQP15tFZwPwBe-xpD8mB.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Ryd7aiOIUUjfakeRLt.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\sMK-BdQ8kydKz0.mkv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\sn5vakIDi6gvvQd 6.flv.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\SWxPvncg.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\T1wMLVSOJ3WHBc5IDz.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\T3ly_ORHtP2pYU8ne7X.flv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\thwDny9tMpkljL.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\tsg7m_edB5q-IyPB_Uz.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\tujdUs.flv.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\tVb2C4KAiQm_.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\uqXgy7 qD9ZrbV_ur.ots.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\UU WaPfo-9Vt J3.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\vB-uMh7aVn8iO-cSyY.mkv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\v_FG7ud1BH-KZPy09.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\V_J Zwq52Ighi.flv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\xVrbOB.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\yTrX8T6qEOaWaHd93_.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\yZ_qbMH0dwR hFM992.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\zFyDIL2q.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\zGvXwHlK4-1z.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ZroSs UxTGYvhkTzvhb.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\_DBoxYrZjyO.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\_i1E0MyIa7bKl4brAwby.ots.lnk.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\_We7 IhKAkd3i.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\RAwb Q.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EaRTC6ALkAKwp34VQ\2hc0nLdqeXfTqNl\lD4T0jw2Q6.jpg.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EaRTC6ALkAKwp34VQ\GSlIX-wE3J\JZ8ftz1nduVAZau6pD1J.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EaRTC6ALkAKwp34VQ\GSlIX-wE3J\ucQXAw25ykhb0B5VMNx.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\PCQbPMub0D\908--r3sgGXaQQ.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\PCQbPMub0D\R9 umVY3s S.png.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\PCQbPMub0D\RfWBl.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\PCQbPMub0D\SWxPvncg.jpg.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\thwDny9tMpkljL\b7r81_Scu_.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zAupK0t\kgYaSl_t9.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zAupK0t\Ryd7aiOIUUjfakeRLt.png.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zAupK0t\yZ_qbMH0dwR hFM992.gif.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zAupK0t\_DBoxYrZjyO.gif.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\-qsMQ8oIACs5c5i5Ui.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\5jp0nTVZcIPwKdnvx6.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\82dvFSVj1i4MetTL.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Ed YmmgXUPEE0QtKMw.wav.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FMsp.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\8mJLvTqgcpH-zx5\R6O_-2m.mp3.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\8mJLvTqgcpH-zx5\TdxPn0J.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\8mJLvTqgcpH-zx5\zWKyoNetE\Alu-gLjTHy0.wav.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\8mJLvTqgcpH-zx5\zWKyoNetE\S4QDLec4ri6xhS-e7xZx.mp3.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\8mJLvTqgcpH-zx5\zWKyoNetE\Xa6dqDXAiBT.mp3.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rQP15tFZwPwBe-xpD8mB\9 PusT_xUl8yxwQc5.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rQP15tFZwPwBe-xpD8mB\hZ8y9cVu_SLf7UwSI\2A0DLKOFhEu5rZhVLsaa.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rQP15tFZwPwBe-xpD8mB\hZ8y9cVu_SLf7UwSI\5j3T.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rQP15tFZwPwBe-xpD8mB\hZ8y9cVu_SLf7UwSI\HqV0pMbvvY.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rQP15tFZwPwBe-xpD8mB\OJ6PNr\b4gt1wUJEZj.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rQP15tFZwPwBe-xpD8mB\OJ6PNr\mA9-.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\-vk7O.mp4.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\7KTLrr.avi.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\bNjaz.swf.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\mn7dUzVEpT7myW.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\eI7QTrX.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\gelf7T_E0h.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\JEKNUD R6LeQqq907mjy.mkv.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\ol6zlcAm4.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\rBVR.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\S7H dN43m9UROqOa-N.avi.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\t6M5.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\tujdUs.flv.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\UEfz0xncbCAxVBW_BJZV.mkv.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\maHvK_h22n001r8G\yJyNSGoNWgeIH.mp4.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\maHvK_h22n001r8G\-4ij7y-zIo-dhcoiIV\5WmPRJ5suanW.mkv.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\maHvK_h22n001r8G\-4ij7y-zIo-dhcoiIV\eBQGIu.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\maHvK_h22n001r8G\-4ij7y-zIo-dhcoiIV\TVSIDkjkr9GfjtwR.swf.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\maHvK_h22n001r8G\-4ij7y-zIo-dhcoiIV\AalPBDgDSgBqLTp 4TZ\JPFZDi_iA.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\maHvK_h22n001r8G\-4ij7y-zIo-dhcoiIV\AalPBDgDSgBqLTp 4TZ\Q-XQdp271EKlSpC.mkv.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\304-.xls.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\75ATlPjUQW.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\adim4yK7GC8JdG2.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BQPd1Wx n.xlsx.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\e6OEO.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gsQ-EPB.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\i_4q7DX_I75G.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\K6Fg-D7HYSFMMUE-mo.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\LM5ox.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Q7YgBSupm4tFcrhh.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\UU WaPfo-9Vt J3.pps | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\QDgIqb7kwW\Vy34OJ3fIYHqzOmF_.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\QDgIqb7kwW\2Su5IHZx-\7Q9liHaXsdf.docx.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\QDgIqb7kwW\2Su5IHZx-\OwPoo8f7 R.doc.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\0MuspYycE4HM8zyuw.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\1ZDZeKwO.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\2Su5IHZx-.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\4sJkr706m2YQI.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\5IDq.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\5igNP.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\75ATlPjUQW.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\8fTFRoJWao5.ots.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\9F_umu6e.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\b7r81_Scu_.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\BiRcK.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\cD17.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\cSALEuB-e.flv.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CThkRua8DGcy8Z3z3pOJ.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\DhCgge2gD0JtlCIZ6g.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\DzW9r_NQT.flv.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\eBQGIu.mkv.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ECv RTfReX.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\eZeXpyHo6-2BapYTUu.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\GbKks8NyOc3CEP.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\gelf7T_E0h.mkv.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\h9Zg.mkv.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\hZ8y9cVu_SLf7UwSI.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\JVyf.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\K6Fg-D7HYSFMMUE-mo.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\lD4T0jw2Q6.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\LM5ox.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\LYXJ.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\MWmp1xmM8xsMui.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\My Music.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\My Videos.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\mZiqtoI5-CUDhQFEL.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\OJ6PNr.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\OJlBF0pBs.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ovLe8xyIEfAbQ.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\OwPoo8f7 R.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\PCQbPMub0D.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Q7YgBSupm4tFcrhh.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\qADM55YkNC5.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\QDgIqb7kwW.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\QTdyC7KZmvwR.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\R9 umVY3s S.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\RAwb Q.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\rBVR.mkv.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\sdHHfCv04Sz375nv.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\sePzVh.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\SoYt-rrIjdE5BbmIf5WS.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\TdynWW3NMOli7eh33s.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\THTxDDVtYDMIzykk3K.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\U-CMugAGR6Y1R8GcK9.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ucQXAw25ykhb0B5VMNx.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\UEfz0xncbCAxVBW_BJZV.mkv.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\VsvgMblZ.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Vy34OJ3fIYHqzOmF_.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\y2KG4nPdxt.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\YaB2.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\YdacGeTA.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\zAupK0t.lnk.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\zWKyoNetE.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\9F_umu6e.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\SoYt-rrIjdE5BbmIf5WS.bmp.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\tsg7m_edB5q-IyPB_Uz.bmp.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZroSs UxTGYvhkTzvhb.jpg.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EaRTC6ALkAKwp34VQ\2hc0nLdqeXfTqNl\eZeXpyHo6-2BapYTUu.gif.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EaRTC6ALkAKwp34VQ\2hc0nLdqeXfTqNl\VsvgMblZ.bmp.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EaRTC6ALkAKwp34VQ\GSlIX-wE3J\YaB2.png.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EaRTC6ALkAKwp34VQ\PfT_29aBkkq\7xqky_KR1phllF0lUBH.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EaRTC6ALkAKwp34VQ\PfT_29aBkkq\cD17.jpg.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EaRTC6ALkAKwp34VQ\PfT_29aBkkq\MYYdIUQVESzF5yk.bmp.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EaRTC6ALkAKwp34VQ\PfT_29aBkkq\y2KG4nPdxt.bmp.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EaRTC6ALkAKwp34VQ\zGvXwHlK4-1z\-vbAQ74ugAbPjkEt.jpg.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EaRTC6ALkAKwp34VQ\zGvXwHlK4-1z\n_x6gNftmTgsMiPC2h.bmp.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\PCQbPMub0D\cGWVj3zjOM.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\PCQbPMub0D\MWmp1xmM8xsMui\Dy5IW1xWAqSu23GIuS.png.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\PCQbPMub0D\MWmp1xmM8xsMui\LYXJ.bmp.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\PCQbPMub0D\MWmp1xmM8xsMui\YdacGeTA.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\-c9KV4u0veAyezl.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\DKdwTNXjmeWg9.wav.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\hw2y.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\8mJLvTqgcpH-zx5\zWKyoNetE\r5lrOCXC7xed.mp3.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rQP15tFZwPwBe-xpD8mB\hZ8y9cVu_SLf7UwSI\Csd0.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rQP15tFZwPwBe-xpD8mB\OJ6PNr\V1K 45gc8vgXNc8CT.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\6y6A68kA8H.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\eY5CTJo11te26D.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\KjT4 HwzgaTQ5.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\sn5vakIDi6gvvQd 6.flv.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\C-flingYTURAdr0.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\hV0evDP.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\maHvK_h22n001r8G\6ulWcr3Xhn_as0bd87.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\maHvK_h22n001r8G\DzW9r_NQT.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\maHvK_h22n001r8G\h9Zg.mkv.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\maHvK_h22n001r8G\ijdz6BW1MN-tNdRFNN.mkv.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\maHvK_h22n001r8G\lVAuwOohxgl-3h1Jjv.avi.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\maHvK_h22n001r8G\V_J Zwq52Ighi.flv.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\maHvK_h22n001r8G\-4ij7y-zIo-dhcoiIV\-GXQ5Lbgzz3YUKdy.swf.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\maHvK_h22n001r8G\-4ij7y-zIo-dhcoiIV\JoZda8UuU66Z8AW q.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MFW8IZ\maHvK_h22n001r8G\-4ij7y-zIo-dhcoiIV\AalPBDgDSgBqLTp 4TZ\b53_noBMJxMq3W.avi.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\1ZDZeKwO.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\9zcK9yFvhp38_3ycric.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\GbKks8NyOc3CEP.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\n3ype.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\pp2-cOmu2l2wp3nZR.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\yTrX8T6qEOaWaHd93_.pptx.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\QDgIqb7kwW\Ia7vXnn.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows\System32\drivers\etc\host | Dropped File | Text |
Not Queried
|
...
|
»