VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Spyware, Ransomware, Dropper |
3307.exe
Windows Exe (x86-32)
Created at 2019-11-07T18:20:00
Remarks
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3307.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4035f0 |
Size Of Code | 0xb000 |
Size Of Initialized Data | 0x3a000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-06-11 20:12:20+00:00 |
Version Information (8)
»
CompanyName | Digital Wave Ltd |
FileDescription | Free Audio Converter |
FileVersion | 5,1,7,215 |
InternalName | FreeAudioConverter.exe |
LegalCopyright | Copyright © 2006-2017 Digital Wave Ltd |
OriginalFilename | FreeAudioConverter.exe |
ProductName | Free Studio |
ProductVersion | 5,1,7,215 |
Sections (7)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xa634 | 0xb000 | 0x1000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.72 |
.rdata | 0x40c000 | 0xe62 | 0x1000 | 0xc000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.19 |
.data | 0x40d000 | 0x2395 | 0x1000 | 0xd000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.03 |
PACK | 0x410000 | 0x3bef | 0x4000 | 0xe000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.51 |
.qdata | 0x414000 | 0x127d1 | 0x13000 | 0x12000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.94 |
.rsrc | 0x427000 | 0x1d760 | 0x1e000 | 0x25000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.77 |
.reloc | 0x445000 | 0x886 | 0x1000 | 0x43000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.94 |
Imports (11)
»
CRYPT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptMsgGetAndVerifySigner | 0x0 | 0x40c018 | 0xc8fc | 0xc8fc | 0xb5 |
OLEAUT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VarCyFromUI8 | 0x16f | 0x40c070 | 0xc954 | 0xc954 | - |
KERNEL32.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetLocalTime | 0x0 | 0x40c028 | 0xc90c | 0xc90c | 0x203 |
FlushConsoleInputBuffer | 0x0 | 0x40c02c | 0xc910 | 0xc910 | 0x156 |
SetThreadPriorityBoost | 0x0 | 0x40c030 | 0xc914 | 0xc914 | 0x49a |
GlobalAlloc | 0x0 | 0x40c034 | 0xc918 | 0xc918 | 0x2b3 |
GetConsoleProcessList | 0x0 | 0x40c038 | 0xc91c | 0xc91c | 0x1b1 |
GetCommState | 0x0 | 0x40c03c | 0xc920 | 0xc920 | 0x184 |
CreateMutexW | 0x0 | 0x40c040 | 0xc924 | 0xc924 | 0x9e |
ReleaseMutex | 0x0 | 0x40c044 | 0xc928 | 0xc928 | 0x3fa |
CloseHandle | 0x0 | 0x40c048 | 0xc92c | 0xc92c | 0x52 |
GetFileType | 0x0 | 0x40c04c | 0xc930 | 0xc930 | 0x1f3 |
GetExitCodeProcess | 0x0 | 0x40c050 | 0xc934 | 0xc934 | 0x1df |
HeapAlloc | 0x0 | 0x40c054 | 0xc938 | 0xc938 | 0x2cb |
GetCurrentProcess | 0x0 | 0x40c058 | 0xc93c | 0xc93c | 0x1c0 |
GetTimeZoneInformation | 0x0 | 0x40c05c | 0xc940 | 0xc940 | 0x298 |
GetFileAttributesW | 0x0 | 0x40c060 | 0xc944 | 0xc944 | 0x1ea |
NETAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetShareDel | 0x0 | 0x40c068 | 0xc94c | 0xc94c | 0xec |
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHRegGetBoolUSValueA | 0x0 | 0x40c078 | 0xc95c | 0xc95c | 0xe0 |
ADVAPI32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetSecurityDescriptorOwner | 0x0 | 0x40c000 | 0xc8e4 | 0xc8e4 | 0x14b |
DuplicateTokenEx | 0x0 | 0x40c004 | 0xc8e8 | 0xc8e8 | 0xdf |
NotifyChangeEventLog | 0x0 | 0x40c008 | 0xc8ec | 0xc8ec | 0x1e5 |
USER32.dll (20)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxW | 0x0 | 0x40c080 | 0xc964 | 0xc964 | 0x215 |
GetMenu | 0x0 | 0x40c084 | 0xc968 | 0xc968 | 0x14b |
GetDlgCtrlID | 0x0 | 0x40c088 | 0xc96c | 0xc96c | 0x126 |
FlashWindow | 0x0 | 0x40c08c | 0xc970 | 0xc970 | 0xfb |
DispatchMessageW | 0x0 | 0x40c090 | 0xc974 | 0xc974 | 0xaf |
TranslateAcceleratorW | 0x0 | 0x40c094 | 0xc978 | 0xc978 | 0x2fa |
EnumDisplaySettingsExW | 0x0 | 0x40c098 | 0xc97c | 0xc97c | 0xe9 |
TranslateMessage | 0x0 | 0x40c09c | 0xc980 | 0xc980 | 0x2fc |
ShowWindow | 0x0 | 0x40c0a0 | 0xc984 | 0xc984 | 0x2df |
NotifyWinEvent | 0x0 | 0x40c0a4 | 0xc988 | 0xc988 | 0x21f |
EndDialog | 0x0 | 0x40c0a8 | 0xc98c | 0xc98c | 0xda |
GetForegroundWindow | 0x0 | 0x40c0ac | 0xc990 | 0xc990 | 0x12d |
GetCaretBlinkTime | 0x0 | 0x40c0b0 | 0xc994 | 0xc994 | 0x109 |
InternalGetWindowText | 0x0 | 0x40c0b4 | 0xc998 | 0xc998 | 0x1bc |
IsHungAppWindow | 0x0 | 0x40c0b8 | 0xc99c | 0xc99c | 0x1d0 |
CloseClipboard | 0x0 | 0x40c0bc | 0xc9a0 | 0xc9a0 | 0x49 |
GetDlgItemTextW | 0x0 | 0x40c0c0 | 0xc9a4 | 0xc9a4 | 0x12a |
DrawTextExW | 0x0 | 0x40c0c4 | 0xc9a8 | 0xc9a8 | 0xcf |
LoadStringW | 0x0 | 0x40c0c8 | 0xc9ac | 0xc9ac | 0x1fa |
GetFocus | 0x0 | 0x40c0cc | 0xc9b0 | 0xc9b0 | 0x12c |
GDI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PlayEnhMetaFileRecord | 0x0 | 0x40c020 | 0xc904 | 0xc904 | 0x24a |
ole32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoUninitialize | 0x0 | 0x40c0dc | 0xc9c0 | 0xc9c0 | 0x6c |
CLUSAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetNodeClusterState | 0x0 | 0x40c010 | 0xc8f4 | 0xc8f4 | 0x71 |
WININET.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ReadUrlCacheEntryStream | 0x0 | 0x40c0d4 | 0xc9b8 | 0xc9b8 | 0xc9 |
Memory Dumps (38)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
3307.exe | 1 | 0x01190000 | 0x011D5FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00060000 | 0x00064FFF | First Execution | - | 32-bit | 0x00061E80 |
![]() |
![]() |
...
|
3307.exe | 1 | 0x01190000 | 0x011D5FFF | Content Changed | - | 32-bit | 0x0119113A |
![]() |
![]() |
...
|
3307.exe | 1 | 0x01190000 | 0x011D5FFF | Content Changed | - | 32-bit | 0x0119BD8E |
![]() |
![]() |
...
|
3307.exe | 1 | 0x01190000 | 0x011D5FFF | Content Changed | - | 32-bit | 0x0119D03B |
![]() |
![]() |
...
|
3307.exe | 1 | 0x01190000 | 0x011D5FFF | Content Changed | - | 32-bit | 0x0119EBA4 |
![]() |
![]() |
...
|
3307.exe | 1 | 0x01190000 | 0x011D5FFF | Content Changed | - | 32-bit | 0x01192017 |
![]() |
![]() |
...
|
3307.exe | 1 | 0x01190000 | 0x011D5FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 2 | 0x000D0000 | 0x000D4FFF | First Execution | - | 32-bit | 0x000D1E80 |
![]() |
![]() |
...
|
buffer | 21 | 0x000D0000 | 0x000D4FFF | First Execution | - | 32-bit | 0x000D1E80 |
![]() |
![]() |
...
|
buffer | 22 | 0x000D0000 | 0x000D4FFF | First Execution | - | 32-bit | 0x000D1E80 |
![]() |
![]() |
...
|
buffer | 36 | 0x00060000 | 0x00064FFF | First Execution | - | 32-bit | 0x00061E80 |
![]() |
![]() |
...
|
buffer | 37 | 0x00060000 | 0x00064FFF | First Execution | - | 32-bit | 0x00061E80 |
![]() |
![]() |
...
|
buffer | 41 | 0x00060000 | 0x00064FFF | First Execution | - | 32-bit | 0x00061E80 |
![]() |
![]() |
...
|
buffer | 42 | 0x00120000 | 0x00124FFF | First Execution | - | 32-bit | 0x00121E80 |
![]() |
![]() |
...
|
buffer | 59 | 0x000A0000 | 0x000A4FFF | First Execution | - | 32-bit | 0x000A1E80 |
![]() |
![]() |
...
|
buffer | 65 | 0x00060000 | 0x00064FFF | First Execution | - | 32-bit | 0x00061E80 |
![]() |
![]() |
...
|
buffer | 68 | 0x00060000 | 0x00064FFF | First Execution | - | 32-bit | 0x00061E80 |
![]() |
![]() |
...
|
buffer | 75 | 0x00110000 | 0x00114FFF | First Execution | - | 32-bit | 0x00111E80 |
![]() |
![]() |
...
|
buffer | 78 | 0x000D0000 | 0x000D4FFF | First Execution | - | 32-bit | 0x000D1E80 |
![]() |
![]() |
...
|
buffer | 82 | 0x00060000 | 0x00064FFF | First Execution | - | 32-bit | 0x00061E80 |
![]() |
![]() |
...
|
buffer | 83 | 0x00070000 | 0x00074FFF | First Execution | - | 32-bit | 0x00071E80 |
![]() |
![]() |
...
|
buffer | 84 | 0x000D0000 | 0x000D4FFF | First Execution | - | 32-bit | 0x000D1E80 |
![]() |
![]() |
...
|
buffer | 87 | 0x000D0000 | 0x000D4FFF | First Execution | - | 32-bit | 0x000D1E80 |
![]() |
![]() |
...
|
buffer | 90 | 0x00060000 | 0x00064FFF | First Execution | - | 32-bit | 0x00061E80 |
![]() |
![]() |
...
|
buffer | 97 | 0x00060000 | 0x00064FFF | First Execution | - | 32-bit | 0x00061E80 |
![]() |
![]() |
...
|
buffer | 100 | 0x000D0000 | 0x000D4FFF | First Execution | - | 32-bit | 0x000D1E80 |
![]() |
![]() |
...
|
buffer | 101 | 0x000D0000 | 0x000D4FFF | First Execution | - | 32-bit | 0x000D1E80 |
![]() |
![]() |
...
|
buffer | 104 | 0x000A0000 | 0x000A4FFF | First Execution | - | 32-bit | 0x000A1E80 |
![]() |
![]() |
...
|
buffer | 107 | 0x00190000 | 0x00194FFF | First Execution | - | 32-bit | 0x00191E80 |
![]() |
![]() |
...
|
buffer | 112 | 0x00150000 | 0x00154FFF | First Execution | - | 32-bit | 0x00151E80 |
![]() |
![]() |
...
|
buffer | 115 | 0x00060000 | 0x00064FFF | First Execution | - | 32-bit | 0x00061E80 |
![]() |
![]() |
...
|
buffer | 124 | 0x00060000 | 0x00064FFF | First Execution | - | 32-bit | 0x00061E80 |
![]() |
![]() |
...
|
buffer | 127 | 0x00060000 | 0x00064FFF | First Execution | - | 32-bit | 0x00061E80 |
![]() |
![]() |
...
|
buffer | 132 | 0x001D0000 | 0x001D4FFF | First Execution | - | 32-bit | 0x001D1E80 |
![]() |
![]() |
...
|
buffer | 135 | 0x00060000 | 0x00064FFF | First Execution | - | 32-bit | 0x00061E80 |
![]() |
![]() |
...
|
buffer | 148 | 0x00160000 | 0x00164FFF | First Execution | - | 32-bit | 0x00161E80 |
![]() |
![]() |
...
|
buffer | 155 | 0x00060000 | 0x00064FFF | First Execution | - | 32-bit | 0x00061E80 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Razy.519592 |
Malicious
|
C:\Windows\ehome\ehRecvr.exe:0 | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-20 15:42 (UTC+1) |
Last Seen | 2019-10-31 23:41 (UTC+1) |
PE Information
»
Image Base | 0x140000000 |
Entry Point | 0x140014734 |
Size Of Code | 0x51800 |
Size Of Initialized Data | 0x58c00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 2010-11-20 11:19:01+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Windows Media Center Receiver Service |
FileVersion | 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
InternalName | ehRecvr.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | ehRecvr.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7601.17514 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x140001000 | 0x51768 | 0x51800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.24 |
.rdata | 0x140053000 | 0x50ad4 | 0x50c00 | 0x51c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.98 |
.data | 0x1400a4000 | 0x166c | 0x1200 | 0xa2800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.18 |
.pdata | 0x1400a6000 | 0x4b9c | 0x4c00 | 0xa3a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.64 |
.rsrc | 0x1400ab000 | 0x1260 | 0x1400 | 0xa8600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.97 |
.reloc | 0x1400ad000 | 0x6bc | 0x800 | 0xa9a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.03 |
Imports (12)
»
ADVAPI32.dll (51)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCloseKey | 0x0 | 0x140053000 | 0x97100 | 0x95d00 | 0x230 |
RegQueryInfoKeyW | 0x0 | 0x140053008 | 0x97108 | 0x95d08 | 0x268 |
RegEnumKeyExW | 0x0 | 0x140053010 | 0x97110 | 0x95d10 | 0x24f |
RegOpenKeyExW | 0x0 | 0x140053018 | 0x97118 | 0x95d18 | 0x261 |
RegSetValueExW | 0x0 | 0x140053020 | 0x97120 | 0x95d20 | 0x27e |
RegCreateKeyExW | 0x0 | 0x140053028 | 0x97128 | 0x95d28 | 0x239 |
RegDeleteValueW | 0x0 | 0x140053030 | 0x97130 | 0x95d30 | 0x248 |
RegisterEventSourceW | 0x0 | 0x140053038 | 0x97138 | 0x95d38 | 0x283 |
ReportEventW | 0x0 | 0x140053040 | 0x97140 | 0x95d40 | 0x28f |
DeregisterEventSource | 0x0 | 0x140053048 | 0x97148 | 0x95d48 | 0xdb |
RegDeleteKeyW | 0x0 | 0x140053050 | 0x97150 | 0x95d50 | 0x244 |
OpenSCManagerW | 0x0 | 0x140053058 | 0x97158 | 0x95d58 | 0x1f9 |
OpenServiceW | 0x0 | 0x140053060 | 0x97160 | 0x95d60 | 0x1fb |
CloseServiceHandle | 0x0 | 0x140053068 | 0x97168 | 0x95d68 | 0x57 |
CreateServiceW | 0x0 | 0x140053070 | 0x97170 | 0x95d70 | 0x81 |
ChangeServiceConfig2W | 0x0 | 0x140053078 | 0x97178 | 0x95d78 | 0x4e |
ControlService | 0x0 | 0x140053080 | 0x97180 | 0x95d80 | 0x5c |
DeleteService | 0x0 | 0x140053088 | 0x97188 | 0x95d88 | 0xda |
StartServiceCtrlDispatcherW | 0x0 | 0x140053090 | 0x97190 | 0x95d90 | 0x2c8 |
RegisterServiceCtrlHandlerExW | 0x0 | 0x140053098 | 0x97198 | 0x95d98 | 0x287 |
SetServiceStatus | 0x0 | 0x1400530a0 | 0x971a0 | 0x95da0 | 0x2c0 |
RegQueryValueExW | 0x0 | 0x1400530a8 | 0x971a8 | 0x95da8 | 0x26e |
InitializeSecurityDescriptor | 0x0 | 0x1400530b0 | 0x971b0 | 0x95db0 | 0x177 |
SetSecurityDescriptorDacl | 0x0 | 0x1400530b8 | 0x971b8 | 0x95db8 | 0x2b6 |
AddAccessAllowedAce | 0x0 | 0x1400530c0 | 0x971c0 | 0x95dc0 | 0x10 |
AddAce | 0x0 | 0x1400530c8 | 0x971c8 | 0x95dc8 | 0x16 |
GetAce | 0x0 | 0x1400530d0 | 0x971d0 | 0x95dd0 | 0x123 |
GetAclInformation | 0x0 | 0x1400530d8 | 0x971d8 | 0x95dd8 | 0x124 |
InitializeAcl | 0x0 | 0x1400530e0 | 0x971e0 | 0x95de0 | 0x176 |
GetLengthSid | 0x0 | 0x1400530e8 | 0x971e8 | 0x95de8 | 0x136 |
IsValidSid | 0x0 | 0x1400530f0 | 0x971f0 | 0x95df0 | 0x186 |
LookupAccountNameW | 0x0 | 0x1400530f8 | 0x971f8 | 0x95df8 | 0x18f |
CreateWellKnownSid | 0x0 | 0x140053100 | 0x97200 | 0x95e00 | 0x83 |
RegGetValueW | 0x0 | 0x140053108 | 0x97208 | 0x95e08 | 0x256 |
GetNamedSecurityInfoW | 0x0 | 0x140053110 | 0x97210 | 0x95e10 | 0x142 |
SetEntriesInAclW | 0x0 | 0x140053118 | 0x97218 | 0x95e18 | 0x2a6 |
SetNamedSecurityInfoW | 0x0 | 0x140053120 | 0x97220 | 0x95e20 | 0x2b1 |
RegEnumValueW | 0x0 | 0x140053128 | 0x97228 | 0x95e28 | 0x252 |
RegEnumKeyW | 0x0 | 0x140053130 | 0x97230 | 0x95e30 | 0x250 |
AllocateAndInitializeSid | 0x0 | 0x140053138 | 0x97238 | 0x95e38 | 0x20 |
CheckTokenMembership | 0x0 | 0x140053140 | 0x97240 | 0x95e40 | 0x51 |
FreeSid | 0x0 | 0x140053148 | 0x97248 | 0x95e48 | 0x120 |
SetSecurityDescriptorGroup | 0x0 | 0x140053150 | 0x97250 | 0x95e50 | 0x2b7 |
GetTokenInformation | 0x0 | 0x140053158 | 0x97258 | 0x95e58 | 0x15a |
CopySid | 0x0 | 0x140053160 | 0x97260 | 0x95e60 | 0x76 |
LookupAccountSidW | 0x0 | 0x140053168 | 0x97268 | 0x95e68 | 0x191 |
SetSecurityDescriptorOwner | 0x0 | 0x140053170 | 0x97270 | 0x95e70 | 0x2b8 |
ConvertStringSecurityDescriptorToSecurityDescriptorW | 0x0 | 0x140053178 | 0x97278 | 0x95e78 | 0x72 |
SetSecurityInfo | 0x0 | 0x140053180 | 0x97280 | 0x95e80 | 0x2bb |
GetSecurityDescriptorDacl | 0x0 | 0x140053188 | 0x97288 | 0x95e88 | 0x148 |
OpenProcessToken | 0x0 | 0x140053190 | 0x97290 | 0x95e90 | 0x1f7 |
KERNEL32.dll (78)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryW | 0x0 | 0x1400531a0 | 0x972a0 | 0x95ea0 | 0x342 |
GetModuleHandleW | 0x0 | 0x1400531a8 | 0x972a8 | 0x95ea8 | 0x21c |
lstrcmpiW | 0x0 | 0x1400531b0 | 0x972b0 | 0x95eb0 | 0x559 |
MultiByteToWideChar | 0x0 | 0x1400531b8 | 0x972b8 | 0x95eb8 | 0x369 |
SizeofResource | 0x0 | 0x1400531c0 | 0x972c0 | 0x95ec0 | 0x4c0 |
LoadResource | 0x0 | 0x1400531c8 | 0x972c8 | 0x95ec8 | 0x344 |
FindResourceW | 0x0 | 0x1400531d0 | 0x972d0 | 0x95ed0 | 0x154 |
LoadLibraryExW | 0x0 | 0x1400531d8 | 0x972d8 | 0x95ed8 | 0x341 |
GetModuleFileNameW | 0x0 | 0x1400531e0 | 0x972e0 | 0x95ee0 | 0x218 |
GetProcAddress | 0x0 | 0x1400531e8 | 0x972e8 | 0x95ee8 | 0x24a |
InitializeCriticalSection | 0x0 | 0x1400531f0 | 0x972f0 | 0x95ef0 | 0x2ec |
SetEvent | 0x0 | 0x1400531f8 | 0x972f8 | 0x95ef8 | 0x467 |
Sleep | 0x0 | 0x140053200 | 0x97300 | 0x95f00 | 0x4c1 |
GetProfileIntW | 0x0 | 0x140053208 | 0x97308 | 0x95f08 | 0x25f |
SetPriorityClass | 0x0 | 0x140053210 | 0x97310 | 0x95f10 | 0x489 |
GetCurrentProcess | 0x0 | 0x140053218 | 0x97318 | 0x95f18 | 0x1c6 |
CreateEventW | 0x0 | 0x140053220 | 0x97320 | 0x95f20 | 0x85 |
ResetEvent | 0x0 | 0x140053228 | 0x97328 | 0x95f28 | 0x412 |
HeapSetInformation | 0x0 | 0x140053230 | 0x97330 | 0x95f30 | 0x2dc |
GetCommandLineW | 0x0 | 0x140053238 | 0x97338 | 0x95f38 | 0x18d |
GetTempPathW | 0x0 | 0x140053240 | 0x97340 | 0x95f40 | 0x28b |
OutputDebugStringA | 0x0 | 0x140053248 | 0x97348 | 0x95f48 | 0x38b |
MoveFileExW | 0x0 | 0x140053250 | 0x97350 | 0x95f50 | 0x362 |
EnterCriticalSection | 0x0 | 0x140053258 | 0x97358 | 0x95f58 | 0xf2 |
LeaveCriticalSection | 0x0 | 0x140053260 | 0x97360 | 0x95f60 | 0x33c |
GetTickCount | 0x0 | 0x140053268 | 0x97368 | 0x95f68 | 0x299 |
GetTickCount64 | 0x0 | 0x140053270 | 0x97370 | 0x95f70 | 0x29a |
GetCurrentThreadId | 0x0 | 0x140053278 | 0x97378 | 0x95f78 | 0x1cb |
QueueUserAPC | 0x0 | 0x140053280 | 0x97380 | 0x95f80 | 0x3b2 |
GetCurrentThread | 0x0 | 0x140053288 | 0x97388 | 0x95f88 | 0x1ca |
SleepEx | 0x0 | 0x140053290 | 0x97390 | 0x95f90 | 0x4c4 |
GetSystemTimeAsFileTime | 0x0 | 0x140053298 | 0x97398 | 0x95f98 | 0x27f |
LocalAlloc | 0x0 | 0x1400532a0 | 0x973a0 | 0x95fa0 | 0x347 |
LocalFree | 0x0 | 0x1400532a8 | 0x973a8 | 0x95fa8 | 0x34b |
DuplicateHandle | 0x0 | 0x1400532b0 | 0x973b0 | 0x95fb0 | 0xec |
CreateThread | 0x0 | 0x1400532b8 | 0x973b8 | 0x95fb8 | 0xb4 |
CreateWaitableTimerW | 0x0 | 0x1400532c0 | 0x973c0 | 0x95fc0 | 0xc3 |
CancelWaitableTimer | 0x0 | 0x1400532c8 | 0x973c8 | 0x95fc8 | 0x47 |
CreateDirectoryW | 0x0 | 0x1400532d0 | 0x973d0 | 0x95fd0 | 0x81 |
SetWaitableTimer | 0x0 | 0x1400532d8 | 0x973d8 | 0x95fd8 | 0x4ba |
WaitForSingleObject | 0x0 | 0x1400532e0 | 0x973e0 | 0x95fe0 | 0x509 |
GetExitCodeThread | 0x0 | 0x1400532e8 | 0x973e8 | 0x95fe8 | 0x1e7 |
K32GetModuleBaseNameW | 0x0 | 0x1400532f0 | 0x973f0 | 0x95ff0 | 0x320 |
GetCurrentProcessId | 0x0 | 0x1400532f8 | 0x973f8 | 0x95ff8 | 0x1c7 |
HeapReAlloc | 0x0 | 0x140053300 | 0x97400 | 0x96000 | 0x2db |
OutputDebugStringW | 0x0 | 0x140053308 | 0x97408 | 0x96008 | 0x38c |
WaitForMultipleObjects | 0x0 | 0x140053310 | 0x97410 | 0x96010 | 0x507 |
ExitThread | 0x0 | 0x140053318 | 0x97418 | 0x96018 | 0x120 |
GetFileAttributesW | 0x0 | 0x140053320 | 0x97420 | 0x96020 | 0x1ef |
SetFileAttributesW | 0x0 | 0x140053328 | 0x97428 | 0x96028 | 0x46e |
OpenThread | 0x0 | 0x140053330 | 0x97430 | 0x96030 | 0x387 |
FindFirstFileW | 0x0 | 0x140053338 | 0x97438 | 0x96038 | 0x13f |
DeleteFileW | 0x0 | 0x140053340 | 0x97440 | 0x96040 | 0xd7 |
FindNextFileW | 0x0 | 0x140053348 | 0x97448 | 0x96048 | 0x14b |
FindClose | 0x0 | 0x140053350 | 0x97450 | 0x96050 | 0x134 |
WaitForMultipleObjectsEx | 0x0 | 0x140053358 | 0x97458 | 0x96058 | 0x508 |
FileTimeToSystemTime | 0x0 | 0x140053360 | 0x97460 | 0x96060 | 0x12b |
SystemTimeToTzSpecificLocalTime | 0x0 | 0x140053368 | 0x97468 | 0x96068 | 0x4cd |
SetThreadExecutionState | 0x0 | 0x140053370 | 0x97470 | 0x96070 | 0x4a0 |
GetLocalTime | 0x0 | 0x140053378 | 0x97478 | 0x96078 | 0x207 |
lstrlenA | 0x0 | 0x140053380 | 0x97480 | 0x96080 | 0x561 |
GetLastError | 0x0 | 0x140053388 | 0x97488 | 0x96088 | 0x206 |
lstrlenW | 0x0 | 0x140053390 | 0x97490 | 0x96090 | 0x562 |
FreeLibrary | 0x0 | 0x140053398 | 0x97498 | 0x96098 | 0x168 |
RaiseException | 0x0 | 0x1400533a0 | 0x974a0 | 0x960a0 | 0x3b4 |
DeleteCriticalSection | 0x0 | 0x1400533a8 | 0x974a8 | 0x960a8 | 0xd2 |
GetProcessHeap | 0x0 | 0x1400533b0 | 0x974b0 | 0x960b0 | 0x24f |
HeapFree | 0x0 | 0x1400533b8 | 0x974b8 | 0x960b8 | 0x2d8 |
HeapAlloc | 0x0 | 0x1400533c0 | 0x974c0 | 0x960c0 | 0x2d4 |
CloseHandle | 0x0 | 0x1400533c8 | 0x974c8 | 0x960c8 | 0x52 |
GetVersionExA | 0x0 | 0x1400533d0 | 0x974d0 | 0x960d0 | 0x2ab |
GetStartupInfoW | 0x0 | 0x1400533d8 | 0x974d8 | 0x960d8 | 0x269 |
SetUnhandledExceptionFilter | 0x0 | 0x1400533e0 | 0x974e0 | 0x960e0 | 0x4b3 |
QueryPerformanceCounter | 0x0 | 0x1400533e8 | 0x974e8 | 0x960e8 | 0x3a9 |
TerminateProcess | 0x0 | 0x1400533f0 | 0x974f0 | 0x960f0 | 0x4cf |
UnhandledExceptionFilter | 0x0 | 0x1400533f8 | 0x974f8 | 0x960f8 | 0x4e3 |
EncodeSystemPointer | 0x0 | 0x140053400 | 0x97500 | 0x96100 | 0xef |
DecodeSystemPointer | 0x0 | 0x140053408 | 0x97508 | 0x96108 | 0xcc |
USER32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TranslateMessage | 0x0 | 0x140053418 | 0x97518 | 0x96118 | 0x304 |
PostThreadMessageW | 0x0 | 0x140053420 | 0x97520 | 0x96120 | 0x23d |
SetTimer | 0x0 | 0x140053428 | 0x97528 | 0x96128 | 0x2c1 |
KillTimer | 0x0 | 0x140053430 | 0x97530 | 0x96130 | 0x1e7 |
UnregisterDeviceNotification | 0x0 | 0x140053438 | 0x97538 | 0x96138 | 0x30f |
DispatchMessageW | 0x0 | 0x140053440 | 0x97540 | 0x96140 | 0xaf |
PeekMessageW | 0x0 | 0x140053448 | 0x97548 | 0x96148 | 0x237 |
MsgWaitForMultipleObjectsEx | 0x0 | 0x140053450 | 0x97550 | 0x96150 | 0x221 |
RegisterDeviceNotificationW | 0x0 | 0x140053458 | 0x97558 | 0x96158 | 0x256 |
CharNextW | 0x0 | 0x140053460 | 0x97560 | 0x96160 | 0x31 |
LoadStringW | 0x0 | 0x140053468 | 0x97568 | 0x96168 | 0x1fe |
UnregisterClassA | 0x0 | 0x140053470 | 0x97570 | 0x96170 | 0x30d |
msvcrt.dll (62)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_resetstkoflw | 0x0 | 0x140053480 | 0x97580 | 0x96180 | 0x297 |
_purecall | 0x0 | 0x140053488 | 0x97588 | 0x96188 | 0x28d |
_onexit | 0x0 | 0x140053490 | 0x97590 | 0x96190 | 0x27f |
_wfopen | 0x0 | 0x140053498 | 0x97598 | 0x96198 | 0x3b1 |
_wcsnicmp | 0x0 | 0x1400534a0 | 0x975a0 | 0x961a0 | 0x383 |
_ui64tow | 0x0 | 0x1400534a8 | 0x975a8 | 0x961a8 | 0x325 |
wcscat_s | 0x0 | 0x1400534b0 | 0x975b0 | 0x961b0 | 0x4ee |
memcpy_s | 0x0 | 0x1400534b8 | 0x975b8 | 0x961b8 | 0x481 |
_lock | 0x0 | 0x1400534c0 | 0x975c0 | 0x961c0 | 0x1d5 |
__dllonexit | 0x0 | 0x1400534c8 | 0x975c8 | 0x961c8 | 0x6d |
_unlock | 0x0 | 0x1400534d0 | 0x975d0 | 0x961d0 | 0x330 |
?terminate@@YAXXZ | 0x0 | 0x1400534d8 | 0x975d8 | 0x961d8 | 0x30 |
__set_app_type | 0x0 | 0x1400534e0 | 0x975e0 | 0x961e0 | 0x80 |
_fmode | 0x0 | 0x1400534e8 | 0x975e8 | 0x961e8 | 0x118 |
_commode | 0x0 | 0x1400534f0 | 0x975f0 | 0x961f0 | 0xc4 |
__setusermatherr | 0x0 | 0x1400534f8 | 0x975f8 | 0x961f8 | 0x82 |
calloc | 0x0 | 0x140053500 | 0x97600 | 0x96200 | 0x413 |
_initterm | 0x0 | 0x140053508 | 0x97608 | 0x96208 | 0x16c |
_wcmdln | 0x0 | 0x140053510 | 0x97610 | 0x96210 | 0x371 |
exit | 0x0 | 0x140053518 | 0x97618 | 0x96218 | 0x420 |
_cexit | 0x0 | 0x140053520 | 0x97620 | 0x96220 | 0xb3 |
_exit | 0x0 | 0x140053528 | 0x97628 | 0x96228 | 0xff |
_XcptFilter | 0x0 | 0x140053530 | 0x97630 | 0x96230 | 0x52 |
__wgetmainargs | 0x0 | 0x140053538 | 0x97638 | 0x96238 | 0x8f |
__CxxFrameHandler3 | 0x0 | 0x140053540 | 0x97640 | 0x96240 | 0x57 |
_callnewh | 0x0 | 0x140053548 | 0x97648 | 0x96248 | 0xb1 |
_CxxThrowException | 0x0 | 0x140053550 | 0x97650 | 0x96250 | 0x4c |
??0exception@@QEAA@AEBQEBDH@Z | 0x0 | 0x140053558 | 0x97658 | 0x96258 | 0xb |
__C_specific_handler | 0x0 | 0x140053560 | 0x97660 | 0x96260 | 0x53 |
memset | 0x0 | 0x140053568 | 0x97668 | 0x96268 | 0x484 |
_localtime64 | 0x0 | 0x140053570 | 0x97670 | 0x96270 | 0x1d3 |
wcsftime | 0x0 | 0x140053578 | 0x97678 | 0x96278 | 0x4f5 |
_time64 | 0x0 | 0x140053580 | 0x97680 | 0x96280 | 0x319 |
wcscspn | 0x0 | 0x140053588 | 0x97688 | 0x96288 | 0x4f4 |
_wcsicmp | 0x0 | 0x140053590 | 0x97690 | 0x96290 | 0x379 |
realloc | 0x0 | 0x140053598 | 0x97698 | 0x96298 | 0x497 |
_errno | 0x0 | 0x1400535a0 | 0x976a0 | 0x962a0 | 0xf6 |
??1type_info@@UEAA@XZ | 0x0 | 0x1400535a8 | 0x976a8 | 0x962a8 | 0x12 |
memcpy | 0x0 | 0x1400535b0 | 0x976b0 | 0x962b0 | 0x480 |
fputws | 0x0 | 0x1400535b8 | 0x976b8 | 0x962b8 | 0x438 |
_amsg_exit | 0x0 | 0x1400535c0 | 0x976c0 | 0x962c0 | 0xa0 |
fflush | 0x0 | 0x1400535c8 | 0x976c8 | 0x962c8 | 0x427 |
wcstok_s | 0x0 | 0x1400535d0 | 0x976d0 | 0x962d0 | 0x505 |
??0exception@@QEAA@XZ | 0x0 | 0x1400535d8 | 0x976d8 | 0x962d8 | 0xd |
memmove_s | 0x0 | 0x1400535e0 | 0x976e0 | 0x962e0 | 0x483 |
free | 0x0 | 0x1400535e8 | 0x976e8 | 0x962e8 | 0x43a |
malloc | 0x0 | 0x1400535f0 | 0x976f0 | 0x962f0 | 0x474 |
wcsncpy_s | 0x0 | 0x1400535f8 | 0x976f8 | 0x962f8 | 0x4fb |
??0exception@@QEAA@AEBQEBD@Z | 0x0 | 0x140053600 | 0x97700 | 0x96300 | 0xa |
??1exception@@UEAA@XZ | 0x0 | 0x140053608 | 0x97708 | 0x96308 | 0x11 |
?what@exception@@UEBAPEBDXZ | 0x0 | 0x140053610 | 0x97710 | 0x96310 | 0x32 |
??0exception@@QEAA@AEBV0@@Z | 0x0 | 0x140053618 | 0x97718 | 0x96318 | 0xc |
wcsstr | 0x0 | 0x140053620 | 0x97720 | 0x96320 | 0x502 |
_itow_s | 0x0 | 0x140053628 | 0x97728 | 0x96328 | 0x1c9 |
wcsncmp | 0x0 | 0x140053630 | 0x97730 | 0x96330 | 0x4f9 |
swprintf_s | 0x0 | 0x140053638 | 0x97738 | 0x96338 | 0x4ca |
_vsnwprintf | 0x0 | 0x140053640 | 0x97740 | 0x96340 | 0x358 |
wcschr | 0x0 | 0x140053648 | 0x97748 | 0x96348 | 0x4ef |
fclose | 0x0 | 0x140053650 | 0x97750 | 0x96350 | 0x424 |
iswalpha | 0x0 | 0x140053658 | 0x97758 | 0x96358 | 0x45d |
wcscpy_s | 0x0 | 0x140053660 | 0x97760 | 0x96360 | 0x4f3 |
floor | 0x0 | 0x140053668 | 0x97768 | 0x96368 | 0x42d |
ole32.dll (20)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoTaskMemFree | 0x0 | 0x140053678 | 0x97778 | 0x96378 | 0x6c |
CoRevertToSelf | 0x0 | 0x140053680 | 0x97780 | 0x96380 | 0x62 |
CoImpersonateClient | 0x0 | 0x140053688 | 0x97788 | 0x96388 | 0x41 |
CoFreeUnusedLibrariesEx | 0x0 | 0x140053690 | 0x97790 | 0x96390 | 0x22 |
CLSIDFromString | 0x0 | 0x140053698 | 0x97798 | 0x96398 | 0xc |
CoWaitForMultipleHandles | 0x0 | 0x1400536a0 | 0x977a0 | 0x963a0 | 0x77 |
StringFromCLSID | 0x0 | 0x1400536a8 | 0x977a8 | 0x963a8 | 0x1b4 |
CoCreateGuid | 0x0 | 0x1400536b0 | 0x977b0 | 0x963b0 | 0x13 |
CoDisconnectObject | 0x0 | 0x1400536b8 | 0x977b8 | 0x963b8 | 0x1a |
CoInitialize | 0x0 | 0x1400536c0 | 0x977c0 | 0x963c0 | 0x42 |
CoRevokeClassObject | 0x0 | 0x1400536c8 | 0x977c8 | 0x963c8 | 0x63 |
CoRegisterClassObject | 0x0 | 0x1400536d0 | 0x977d0 | 0x963d0 | 0x57 |
CoUninitialize | 0x0 | 0x1400536d8 | 0x977d8 | 0x963d8 | 0x70 |
CoInitializeEx | 0x0 | 0x1400536e0 | 0x977e0 | 0x963e0 | 0x43 |
CoSuspendClassObjects | 0x0 | 0x1400536e8 | 0x977e8 | 0x963e8 | 0x69 |
StringFromGUID2 | 0x0 | 0x1400536f0 | 0x977f0 | 0x963f0 | 0x1b5 |
CoCreateInstance | 0x0 | 0x1400536f8 | 0x977f8 | 0x963f8 | 0x14 |
CoTaskMemAlloc | 0x0 | 0x140053700 | 0x97800 | 0x96400 | 0x6b |
CoTaskMemRealloc | 0x0 | 0x140053708 | 0x97808 | 0x96408 | 0x6d |
CoInitializeSecurity | 0x0 | 0x140053710 | 0x97810 | 0x96410 | 0x44 |
OLEAUT32.dll (20)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysAllocStringByteLen | 0x96 | 0x140053720 | 0x97820 | 0x96420 | - |
VarUI4FromStr | 0x115 | 0x140053728 | 0x97828 | 0x96428 | - |
SysStringLen | 0x7 | 0x140053730 | 0x97830 | 0x96430 | - |
SysAllocString | 0x2 | 0x140053738 | 0x97838 | 0x96438 | - |
VariantInit | 0x8 | 0x140053740 | 0x97840 | 0x96440 | - |
VariantClear | 0x9 | 0x140053748 | 0x97848 | 0x96448 | - |
SysAllocStringLen | 0x4 | 0x140053750 | 0x97850 | 0x96450 | - |
SafeArrayGetLBound | 0x14 | 0x140053758 | 0x97858 | 0x96458 | - |
SafeArrayGetUBound | 0x13 | 0x140053760 | 0x97860 | 0x96460 | - |
SafeArrayAccessData | 0x17 | 0x140053768 | 0x97868 | 0x96468 | - |
SafeArrayUnaccessData | 0x18 | 0x140053770 | 0x97870 | 0x96470 | - |
SafeArrayGetElement | 0x19 | 0x140053778 | 0x97878 | 0x96478 | - |
SafeArrayCreate | 0xf | 0x140053780 | 0x97880 | 0x96480 | - |
DispCallFunc | 0x92 | 0x140053788 | 0x97888 | 0x96488 | - |
SafeArrayRedim | 0x28 | 0x140053790 | 0x97890 | 0x96490 | - |
VarBstrCat | 0x139 | 0x140053798 | 0x97898 | 0x96498 | - |
SysFreeString | 0x6 | 0x1400537a0 | 0x978a0 | 0x964a0 | - |
SysStringByteLen | 0x95 | 0x1400537a8 | 0x978a8 | 0x964a8 | - |
VarBstrCmp | 0x13a | 0x1400537b0 | 0x978b0 | 0x964b0 | - |
SafeArrayDestroy | 0x10 | 0x1400537b8 | 0x978b8 | 0x964b8 | - |
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFileExistsW | 0x0 | 0x1400537c8 | 0x978c8 | 0x964c8 | 0x45 |
VERSION.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFileVersionInfoW | 0x0 | 0x1400537d8 | 0x978d8 | 0x964d8 | 0x6 |
VerQueryValueA | 0x0 | 0x1400537e0 | 0x978e0 | 0x964e0 | 0xd |
GetFileVersionInfoSizeW | 0x0 | 0x1400537e8 | 0x978e8 | 0x964e8 | 0x5 |
ehTrace.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ehTraceEvent | 0x0 | 0x1400537f8 | 0x978f8 | 0x964f8 | 0x17 |
ehRegisterTraceGUIDs | 0x0 | 0x140053800 | 0x97900 | 0x96500 | 0x14 |
ehFreeEventBuffer | 0x0 | 0x140053808 | 0x97908 | 0x96508 | 0x11 |
ehUnregisterTraceGUIDs | 0x0 | 0x140053810 | 0x97910 | 0x96510 | 0x1c |
ehAllocateEventBuffer | 0x0 | 0x140053818 | 0x97918 | 0x96518 | 0x10 |
SHELL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetKnownFolderPath | 0x0 | 0x140053828 | 0x97928 | 0x96528 | 0xcd |
SHCreateDirectoryExW | 0x0 | 0x140053830 | 0x97930 | 0x96530 | 0x8d |
ntdll.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlCaptureContext | 0x0 | 0x140053840 | 0x97940 | 0x96540 | 0x27b |
RtlLookupFunctionEntry | 0x0 | 0x140053848 | 0x97948 | 0x96548 | 0x402 |
RtlVirtualUnwind | 0x0 | 0x140053850 | 0x97950 | 0x96550 | 0x4f1 |
slc.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SLGetWindowsInformationDWORD | 0x0 | 0x140053860 | 0x97960 | 0x96560 | 0x17 |
Exports (12)
»
Api name | EAT Address | Ordinal |
---|---|---|
CETWProvider_Initialize | 0x4cda0 | 0x1 |
CETWProvider_TraceCriticalCall | 0x4d534 | 0x2 |
CETWProvider_TraceEHomeEvent | 0x4d5f8 | 0x3 |
CETWProvider_TraceErrorEvent | 0x4d140 | 0x4 |
CETWProvider_TraceErrorLevel | 0x4d264 | 0x5 |
CETWProvider_TraceEventID | 0x4d454 | 0x6 |
CETWProvider_TraceInfo | 0x4ced4 | 0x7 |
CETWProvider_TracePerfMarkerEnd | 0x4d08c | 0x8 |
CETWProvider_TracePerfMarkerStart | 0x4cfd8 | 0x9 |
CETWProvider_TraceTextLevel | 0x4cf90 | 0xa |
CETWProvider_TraceVideoSize | 0x4d3e0 | 0xb |
CETWProvider_Uninitialize | 0x4ce6c | 0xc |
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.0riz0n | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.0riz0n | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.0riz0n | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.0riz0n | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.0riz0n | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.0riz0n | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.0riz0n | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.0riz0n | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.0riz0n | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.0riz0n | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.0riz0n | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.0riz0n | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.0riz0n | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.0riz0n | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.0riz0n | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.0riz0n | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\Tor781B.tmp | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.0riz0n_readme | Dropped File | Text |
Unknown
|
...
|
»