Malware Uses JAR | Grouped Behavior
Try VMRay Analyzer
Involved Hosts

Host Resolved to Country City Protocol
N3EErvtwsM
adom2.com.br
carvas32ltda.com
carva32ssa.com
bandeivacomercial.com
bandeivacomercio.com
187.191.100.112 BR TCP
localhost 127.0.0.1 HTTP
Monitored Processes
Behavior Information - Grouped by Category
Process #1: java.exe
(Host: 12432, Network: 8)
+
Information Value
ID / OS PID #1 / 0xb6c
OS Parent PID 0x4f0 (c:\windows\explorer.exe)
Initial Working Directory C:\Users\DSsDPMx042\Desktop
File Name c:\program files\java\jre1.8.0_92\bin\java.exe
Command Line "C:\Program Files\Java\jre1.8.0_92\bin\java.exe" -jar "C:\Users\DSsDPMx042\Desktop\Duplicata0.jar"
Monitor Start Time: 00:00:08, Reason: Analysis Target
Unmonitor End Time: 00:00:30, Reason: Terminated
Monitor Duration 00:00:22
OS Thread IDs
# 1
0x B70
# 2
0x BC0
# 3
0x BC4
# 4
0x BC8
# 5
0x BCC
# 6
0x BD8
# 7
0x BD0
# 8
0x BD4
# 9
0x BE0
# 10
0x BDC
# 11
0x BE4
# 12
0x BEC
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00042fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
private_0x00000000000c0000 0x000c0000 0x000c0fff Private Memory Readable, Writable True False False
private_0x00000000000d0000 0x000d0000 0x000d0fff Private Memory Readable, Writable True False False
private_0x00000000000e0000 0x000e0000 0x0012ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000130000 0x00130000 0x001f7fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000200000 0x00200000 0x00200fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000210000 0x00210000 0x00211fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000220000 0x00220000 0x00226fff Pagefile Backed Memory Readable True False False
private_0x0000000000230000 0x00230000 0x0032ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000330000 0x00330000 0x00430fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000440000 0x00440000 0x00441fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000450000 0x00450000 0x00450fff Private Memory Readable True False False
private_0x0000000000460000 0x00460000 0x00460fff Private Memory Readable, Writable True False False
private_0x0000000000470000 0x00470000 0x004bffff Private Memory Readable, Writable True False False
private_0x00000000004c0000 0x004c0000 0x004cffff Private Memory Readable, Writable True False False
2924 0x004d0000 0x004dffff Memory Mapped File Readable, Writable True False False
private_0x00000000004e0000 0x004e0000 0x0055ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000560000 0x00560000 0x00560fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000590000 0x00590000 0x0059ffff Private Memory Readable, Writable True False False
private_0x00000000005a0000 0x005a0000 0x0069ffff Private Memory Readable, Writable True False False
pagefile_0x00000000006a0000 0x006a0000 0x00a92fff Pagefile Backed Memory Readable True False False
private_0x0000000000aa0000 0x00aa0000 0x00b9ffff Private Memory Readable, Writable True False False
private_0x0000000000ba0000 0x00ba0000 0x00bfffff Private Memory Readable, Writable True False False
private_0x0000000000c10000 0x00c10000 0x00c1ffff Private Memory Readable, Writable True False False
private_0x0000000000c20000 0x00c20000 0x00caffff Private Memory Readable, Writable True False False
private_0x0000000000cb0000 0x00cb0000 0x00cfffff Private Memory Readable, Writable True False False
private_0x0000000000d40000 0x00d40000 0x00d8ffff Private Memory Readable, Writable True False False
java.exe 0x00da0000 0x00dd2fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000de0000 0x00de0000 0x019dffff Pagefile Backed Memory Readable True False False
SortDefault.nls 0x019e0000 0x01caefff Memory Mapped File Readable False False False
private_0x0000000001cb0000 0x01cb0000 0x03caffff Private Memory Readable, Writable True False False
private_0x0000000003cb0000 0x03cb0000 0x03cfffff Private Memory Readable, Writable True False False
kernel32.dll.mui 0x03d00000 0x03dbffff Memory Mapped File Readable, Writable False False False
private_0x0000000003e00000 0x03e00000 0x13dfffff Private Memory Readable, Writable True False False
classes.jsa 0x13e00000 0x143affff Memory Mapped File Readable False False False
private_0x00000000143b0000 0x143b0000 0x1480ffff Private Memory Readable, Writable True False False
private_0x0000000014810000 0x14810000 0x1485ffff Private Memory Readable, Writable True False False
private_0x0000000014870000 0x14870000 0x148bffff Private Memory Readable, Writable True False False
private_0x00000000148d0000 0x148d0000 0x1491ffff Private Memory Readable, Writable True False False
private_0x0000000014990000 0x14990000 0x149dffff Private Memory Readable, Writable True False False
classes.jsa 0x14a00000 0x14f6ffff Memory Mapped File Readable, Writable False False False
private_0x0000000014fb0000 0x14fb0000 0x14ffffff Private Memory Readable, Writable True False False
private_0x0000000015000000 0x15000000 0x151fffff Private Memory Readable, Writable True False False
private_0x0000000015290000 0x15290000 0x1529ffff Private Memory Readable, Writable True False False
private_0x00000000152b0000 0x152b0000 0x152bffff Private Memory Readable, Writable True False False
private_0x0000000015380000 0x15380000 0x153bffff Private Memory Readable, Writable True False False
private_0x0000000015400000 0x15400000 0x1544ffff Private Memory Readable, Writable True False False
private_0x0000000015450000 0x15450000 0x1554ffff Private Memory Readable, Writable True False False
classes.jsa 0x15600000 0x156bffff Memory Mapped File Readable, Writable False False False
private_0x0000000015800000 0x15800000 0x1580ffff Private Memory Readable, Writable True False False
private_0x0000000015940000 0x15940000 0x1597ffff Private Memory Readable, Writable True False False
jvm.dll 0x6d510000 0x6d8dafff Memory Mapped File Readable, Writable, Executable False False False
msvcr100.dll 0x6dee0000 0x6df9efff Memory Mapped File Readable, Writable, Executable False False False
net.dll 0x6e0b0000 0x6e0c5fff Memory Mapped File Readable, Writable, Executable True False False
zip.dll 0x6e0d0000 0x6e0e2fff Memory Mapped File Readable, Writable, Executable True False False
java.dll 0x6e0f0000 0x6e110fff Memory Mapped File Readable, Writable, Executable True False False
pnrpnsp.dll 0x6f1d0000 0x6f1e1fff Memory Mapped File Readable, Writable, Executable False False False
winrnr.dll 0x6f270000 0x6f277fff Memory Mapped File Readable, Writable, Executable False False False
NapiNSP.dll 0x6f280000 0x6f28ffff Memory Mapped File Readable, Writable, Executable False False False
verify.dll 0x6f9b0000 0x6f9bbfff Memory Mapped File Readable, Writable, Executable True False False
winmm.dll 0x70ef0000 0x70f21fff Memory Mapped File Readable, Writable, Executable False False False
FWPUCLNT.DLL 0x721e0000 0x72217fff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x72300000 0x72306fff Memory Mapped File Readable, Writable, Executable False False False
IPHLPAPI.DLL 0x72310000 0x7232bfff Memory Mapped File Readable, Writable, Executable False False False
rasadhlp.dll 0x72350000 0x72355fff Memory Mapped File Readable, Writable, Executable False False False
wsock32.dll 0x72f00000 0x72f06fff Memory Mapped File Readable, Writable, Executable False False False
nlaapi.dll 0x73850000 0x7385ffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x74110000 0x742adfff Memory Mapped File Readable, Writable, Executable False False False
version.dll 0x748a0000 0x748a8fff Memory Mapped File Readable, Writable, Executable False False False
WSHTCPIP.DLL 0x74930000 0x74934fff Memory Mapped File Readable, Writable, Executable False False False
dnsapi.dll 0x74ca0000 0x74ce3fff Memory Mapped File Readable, Writable, Executable False False False
wship6.dll 0x74dd0000 0x74dd5fff Memory Mapped File Readable, Writable, Executable False False False
mswsock.dll 0x74de0000 0x74e1bfff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x75350000 0x7535afff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x759e0000 0x76629fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x76a90000 0x76bebfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76d70000 0x76dc6fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x77340000 0x77345fff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x77360000 0x77364fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x773f0000 0x77424fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffd4000 0x7ffd4000 0x7ffd4fff Private Memory Readable, Writable True False False
private_0x000000007ffd5000 0x7ffd5000 0x7ffd5fff Private Memory Readable, Writable True False False
private_0x000000007ffd6000 0x7ffd6000 0x7ffd6fff Private Memory Readable, Writable True False False
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory Readable, Writable True False False
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory Readable, Writable True False False
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory Readable, Writable True False False
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory Readable, Writable True False False
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory Readable, Writable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Created Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\public\n3eg\id 0.01 KB (7 bytes) MD5: 97558baebf6eb308ff83d8fe474e294a
SHA1: 954cfe56df08de38d177d12bab69170cf1674b03
SHA256: 7a788184a2507c5de3f4cfc973810695d3ca41e29c6e90a21f87d419e1601c94
False
c:\users\public\n3eg\idw 0.00 KB (2 bytes) MD5: 26657d5ff9020d2abefe558796b99584
SHA1: 6fb84aed32facd1299ee1e77c8fd2b1a6352669e
SHA256: 7b1a278f5abe8e9da907fc9c29dfd432d60dc76e17b0fabab659d2a508bc65c4
False
c:\users\public\n3eg\n3eg1.zip 1.58 MB (1661608 bytes) MD5: 16dbf6ce67e389a442ce8d032637654d
SHA1: 0b4068e0d543bb6cd9e549df207a3069a7e18388
SHA256: 555a58f9a1d235b075fa645a058a5b93215bd27432a4c8e120f4310eb8655c47
False
c:\users\public\n3eg\n3eg2.zip 730.94 KB (748483 bytes) MD5: 7088647800a215d2d77570ff3f999e74
SHA1: aad42e745069e801900a01f1fd897b82067f988e
SHA256: 572d8553fc28c6cdd680aa782cd73d2e6cbd7316145f060a3986a7ce0e40515e
False
c:\users\public\n3eg\n3eg4.zip 411.42 KB (421293 bytes) MD5: d5a2e7e6f866f119cd9fe3b3d6232acc
SHA1: 8af3b0406e8e6780cea28a603f46ef2eec7d2b9f
SHA256: 09973947c6b59a27d5adf9ce1d0b2edf342a18ae746d58dec72cc24b31d46a59
False
c:\users\public\n3eg\ljkg4 452.50 KB (463360 bytes) MD5: 9c413a78860adeb716ce3a6c9c90aeb3
SHA1: 3b12a0e1afae98db7e665ea6bc45b1c7bf875b30
SHA256: 8be47f70911221c257dd2def3ce76a1d4db6d26685de6fbc16409baeb8ba8722
False
c:\users\public\n3eg\n3eg4.51n3e 452.50 KB (463360 bytes) MD5: 9c413a78860adeb716ce3a6c9c90aeb3
SHA1: 3b12a0e1afae98db7e665ea6bc45b1c7bf875b30
SHA256: 8be47f70911221c257dd2def3ce76a1d4db6d26685de6fbc16409baeb8ba8722
False
c:\users\public\n3eg\ljkg1 2.56 MB (2689537 bytes) MD5: 8eaa07e05c7f46d1c2949d11c9ba645d
SHA1: 1dc6bc4043ce00b856bfe462147064b34ae16dc2
SHA256: 866218b20d0ebcae237e288cf8616d7a9293c974a1df14ec8f7c37b7ee0dd7e4
False
c:\users\public\n3eg\n3eg1.51n3e 2.56 MB (2689537 bytes) MD5: 8eaa07e05c7f46d1c2949d11c9ba645d
SHA1: 1dc6bc4043ce00b856bfe462147064b34ae16dc2
SHA256: 866218b20d0ebcae237e288cf8616d7a9293c974a1df14ec8f7c37b7ee0dd7e4
False
c:\users\public\n3eg\ljkg2 1.29 MB (1356288 bytes) MD5: 23adce0295127671e5bc3c4c9d1e2eb7
SHA1: cf28f7c38c1a3e17458e6b7eb1dc38baef72d290
SHA256: 7cfbfff8aaf3bd0cc707e61a075a1f45644f422f9d1c55573edec637c27b6534
False
c:\users\public\n3eg\n3eg2.51n3e 1.29 MB (1356288 bytes) MD5: 23adce0295127671e5bc3c4c9d1e2eb7
SHA1: cf28f7c38c1a3e17458e6b7eb1dc38baef72d290
SHA256: 7cfbfff8aaf3bd0cc707e61a075a1f45644f422f9d1c55573edec637c27b6534
False
Modified Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\dssdpmx042\.oracle_jre_usage\90737d32e3abaa4.timestamp 0.05 KB (50 bytes) MD5: 9fffd4e723eebc43d03333c1a4413ab4
SHA1: 5a93ce0f655c05c5318bfbdb488e6eceaf29d96e
SHA256: 48d355d323548fb06decc335335b6deb3155b593756826c6771ff9d25743ea63
False
Host Behavior
File (12418)
+
Operation Filename Additional Information Success Count Logfile
CREATE c:\program files\java\jre1.8.0_92\lib\rt.jar desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\program files\java\jre1.8.0_92\lib\ext\meta-index desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\dssdpmx042\.oracle_jre_usage\90737d32e3abaa4.timestamp desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\dssdpmx042\desktop\duplicata0.jar share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = OPEN_EXISTING, file_attributes = FILE_FLAG_BACKUP_SEMANTICS True 3
Fn
CREATE c:\users\dssdpmx042\desktop\duplicata0.jar desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 2
Fn
CREATE c:\program files\java\jre1.8.0_92\lib\meta-index desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\program files\java\jre1.8.0_92\lib\security\java.security desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\id desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\idw desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\program files\java\jre1.8.0_92\lib\net.properties desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\n3eg1.zip desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\n3eg2.zip desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\n3eg4.zip desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\n3eg4.zip desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\ljkg4 desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\n3eg1.zip desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\ljkg1 desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\n3eg2.zip desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\ljkg2 desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 4 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 128 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 7 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 1896818 True 1
Fn
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 160 True 50
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 30 True 50
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 363 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 120 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 1671 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\ext\meta-index size = 8192 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\ext\meta-index size = 8192 True 1
Fn
READ c:\users\dssdpmx042\desktop\duplicata0.jar size = 4 True 2
Fn
Data
READ c:\users\dssdpmx042\desktop\duplicata0.jar size = 128 True 2
Fn
Data
READ c:\users\dssdpmx042\desktop\duplicata0.jar size = 1188 True 2
Fn
Data
READ c:\users\dssdpmx042\desktop\duplicata0.jar size = 160 True 10
Fn
Data
READ c:\users\dssdpmx042\desktop\duplicata0.jar size = 30 True 10
Fn
Data
READ c:\users\dssdpmx042\desktop\duplicata0.jar size = 123 True 5
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 1016 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 1132 True 2
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 985 True 1
Fn
Data
READ c:\users\dssdpmx042\desktop\duplicata0.jar size = 2339 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\meta-index size = 8192 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\meta-index size = 8192 True 1
Fn
READ c:\users\dssdpmx042\desktop\duplicata0.jar size = 352 True 1
Fn
Data
READ c:\users\dssdpmx042\desktop\duplicata0.jar size = 561 True 1
Fn
Data
READ c:\users\dssdpmx042\desktop\duplicata0.jar size = 879 True 1
Fn
Data
READ c:\users\dssdpmx042\desktop\duplicata0.jar size = 755 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 2044 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 2423 True 1
Fn
Data
READ c:\users\dssdpmx042\desktop\duplicata0.jar size = 91 True 2
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 1157 True 1
Fn
Data
READ c:\users\dssdpmx042\desktop\duplicata0.jar size = 8192 True 2
Fn
Data
READ c:\users\dssdpmx042\desktop\duplicata0.jar size = 3879 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\security\java.security size = 8192 True 3
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\security\java.security size = 8192 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\security\java.security size = 8192 True 1
Fn
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 44725 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 800 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 1085 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 792 True 2
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 1194 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 1127 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 737 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\net.properties size = 8192 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\net.properties size = 8192 True 1
Fn
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 16003 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 4482 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 973 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 4050 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 975 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 3674 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 621 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 751 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 1874 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 7198 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 920 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 1936 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 281 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 748 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 2693 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 3379 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 3246 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 100 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 2082 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 2282 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 683 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 681 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 2654 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 1459 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 1396 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 285 True 1
Fn
Data
READ c:\users\public\n3eg\n3eg4.zip size = 30 True 1
Fn
Data
READ c:\users\public\n3eg\n3eg4.zip size = 5 True 1
Fn
Data
READ c:\users\public\n3eg\n3eg4.zip size = 512 True 822
Fn
Data
READ c:\users\public\n3eg\n3eg4.zip size = 512 True 1
Fn
Data
READ c:\users\public\n3eg\n3eg1.zip size = 30 True 1
Fn
Data
READ c:\users\public\n3eg\n3eg1.zip size = 5 True 1
Fn
Data
READ c:\users\public\n3eg\n3eg1.zip size = 512 True 3245
Fn
Data
READ c:\users\public\n3eg\n3eg1.zip size = 512 True 1
Fn
Data
READ c:\users\public\n3eg\n3eg2.zip size = 30 True 1
Fn
Data
READ c:\users\public\n3eg\n3eg2.zip size = 5 True 1
Fn
Data
READ c:\users\public\n3eg\n3eg2.zip size = 512 True 1461
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 1124 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 3434 True 1
Fn
Data
READ c:\users\public\n3eg\n3eg2.zip size = 512 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 6089 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 8451 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 1067 True 1
Fn
Data
READ c:\program files\java\jre1.8.0_92\lib\rt.jar size = 1873 True 1
Fn
Data
OPEN STD_OUTPUT_HANDLE True 3
Fn
OPEN STD_ERROR_HANDLE True 3
Fn
OPEN STD_INPUT_HANDLE True 2
Fn
WRITE c:\users\dssdpmx042\.oracle_jre_usage\90737d32e3abaa4.timestamp size = 50 True 1
Fn
Data
WRITE c:\users\public\n3eg\id size = 7 True 1
Fn
Data
WRITE c:\users\public\n3eg\idw size = 2 True 1
Fn
Data
WRITE c:\users\public\n3eg\n3eg1.zip size = 1661608 True 1
Fn
WRITE c:\users\public\n3eg\n3eg2.zip size = 748483 True 1
Fn
Data
WRITE c:\users\public\n3eg\n3eg4.zip size = 421293 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 1024 True 22
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 142 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 930 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 806 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 882 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 761 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 830 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 913 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 812 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 638 True 19
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 614 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 633 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 730 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 738 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 747 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 715 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 859 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 741 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 687 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 926 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 779 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 867 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 834 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 407 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 1 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 285 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 673 True 11
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 808 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 719 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 701 True 12
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 706 True 12
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 667 True 14
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 651 True 12
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 746 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 756 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 855 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 987 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 763 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 700 True 11
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 836 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 842 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 868 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 909 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 751 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 871 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 876 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 754 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 885 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 774 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 827 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 21 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 211 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 1009 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 709 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 946 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 794 True 11
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 63 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 879 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 62 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 77 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 847 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 851 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 532 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 296 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 936 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 908 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 968 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 1000 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 964 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 884 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 939 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 811 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 838 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 959 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 869 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 873 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 804 True 11
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 786 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 787 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 805 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 1019 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 11 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 759 True 11
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 902 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 29 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 76 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 982 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 449 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 552 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 567 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 587 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 634 True 12
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 684 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 603 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 802 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 583 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 496 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 141 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 516 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 479 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 538 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 490 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 495 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 492 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 494 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 493 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 488 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 491 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 505 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 512 True 668
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 507 True 27
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 467 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg4 size = 511 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 831 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 701 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 681 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 753 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 911 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 783 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 760 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 802 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 953 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 903 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1024 True 551
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 675 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 232 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 325 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 695 True 14
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 845 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 602 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 565 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 544 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 585 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 607 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 591 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 578 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 569 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 595 True 11
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 637 True 14
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 588 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 563 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 587 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 547 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 566 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 596 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 598 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 571 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 485 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 623 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 632 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 610 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 622 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 581 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 606 True 12
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 608 True 11
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 638 True 16
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 600 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 620 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 614 True 16
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 641 True 18
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 646 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 580 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 590 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 659 True 11
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 604 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 660 True 16
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 763 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 680 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 676 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 653 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 592 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 634 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 642 True 12
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 723 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 628 True 14
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 712 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 664 True 23
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 747 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 727 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 682 True 12
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 115 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 512 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 26 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 931 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 939 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 13 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 776 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 724 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 44 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 185 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 241 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 106 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 132 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 230 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 508 True 12
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 270 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 703 True 20
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 809 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 734 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 806 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 685 True 14
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 864 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 938 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 283 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 361 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 558 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 982 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 826 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 767 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 213 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 749 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 961 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 287 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 906 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1006 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 827 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 609 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 553 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 589 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 560 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 584 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 611 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 594 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 586 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 639 True 14
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 601 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 603 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 717 True 14
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 457 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 543 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 559 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 605 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 633 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 617 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 741 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 684 True 14
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 612 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 619 True 14
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 672 True 12
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 744 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 670 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 702 True 17
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 662 True 16
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 650 True 22
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 669 True 16
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 636 True 20
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 708 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 705 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 654 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 652 True 14
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 698 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 707 True 16
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 770 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 752 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 84 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 210 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 630 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 616 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 651 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 658 True 23
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 805 True 12
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 781 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 788 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 699 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 862 True 11
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 792 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 935 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 775 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 686 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 667 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 564 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 739 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 649 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 673 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 656 True 14
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 640 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 817 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 668 True 14
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 713 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 754 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 655 True 14
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 629 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 700 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 573 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 688 True 11
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 572 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 735 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 967 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 964 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 945 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 866 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 850 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 897 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 975 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 138 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 159 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 388 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 162 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 876 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 48 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 161 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 927 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 937 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 128 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 19 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 110 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 237 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 274 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 258 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 4 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 60 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 709 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 461 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 731 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 693 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 647 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 759 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 715 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 674 True 20
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 690 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 777 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 838 True 11
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 219 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 455 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 339 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 983 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 294 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 615 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 269 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 81 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 107 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 849 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 627 True 14
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 959 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 32 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 890 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 990 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 66 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 665 True 17
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 687 True 12
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 679 True 19
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 842 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1012 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 721 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 839 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 952 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 758 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 813 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 905 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1020 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 82 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1017 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 57 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 67 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 53 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 199 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 130 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 47 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 145 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 29 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 689 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 835 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 671 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 720 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 374 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 538 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 579 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 800 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 780 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 745 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 657 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 750 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 963 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 958 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 114 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 118 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 618 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 836 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 885 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 793 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 706 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 973 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 491 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 965 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 208 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 332 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 987 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 807 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 71 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 913 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 183 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 333 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 520 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 271 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 23 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 519 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 212 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 50 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 70 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 250 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 178 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 420 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 907 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 133 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 251 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 150 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 255 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 981 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 231 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 928 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 253 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 318 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 785 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 722 True 11
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 765 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 599 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 582 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 554 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 678 True 12
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 692 True 14
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 261 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 746 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 666 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 991 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 870 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 272 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 930 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 986 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 779 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 36 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 15 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 824 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 999 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 880 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 774 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 12 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 189 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 863 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 116 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 976 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 75 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 297 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 970 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 100 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 778 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 811 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 944 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 884 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 950 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1016 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 510 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 96 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 820 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 854 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 825 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 901 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 49 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 27 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 89 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1018 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 127 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 204 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 164 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 195 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 252 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 163 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 196 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 284 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 408 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 344 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 217 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 402 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 240 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 288 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 954 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 921 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 238 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 370 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 211 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 103 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 79 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 376 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 855 True 11
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 129 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 170 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 917 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 531 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 546 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 40 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 194 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 51 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 182 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1014 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 46 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 184 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 488 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 260 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 135 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 41 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 742 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 635 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 718 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 926 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 898 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 843 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 966 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 899 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 626 True 16
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 888 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 786 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 960 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 631 True 12
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 663 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 625 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 728 True 12
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 859 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 481 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 696 True 15
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 875 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 714 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 790 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 979 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 955 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 142 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 525 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 355 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 853 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 470 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 439 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 551 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 962 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 925 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 302 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 909 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 307 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 8 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 291 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 932 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 155 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 202 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 438 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 136 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1003 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 167 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 214 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 733 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 278 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 496 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 841 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 108 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 9 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 574 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 20 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 951 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 101 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 34 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 645 True 17
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 993 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 172 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 423 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 507 True 13
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 380 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 58 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 915 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 871 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 126 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 286 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 856 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1021 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 5 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 14 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 732 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 111 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 730 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 872 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 91 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 755 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 691 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 948 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 621 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 487 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 583 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 851 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 7 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 65 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 798 True 10
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 550 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 18 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 45 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 736 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 858 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 882 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 829 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 555 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 570 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 121 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 808 True 8
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 867 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1005 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 833 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 497 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 968 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 782 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 540 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 743 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 874 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 810 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 94 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 887 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 207 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 59 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 131 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 64 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1009 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 934 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 998 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 356 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 224 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 460 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 860 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 30 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 301 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 141 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 373 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 68 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 63 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 419 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 348 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1001 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 120 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 342 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 228 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 166 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 175 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 168 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 148 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 181 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 985 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1008 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 737 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 893 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 896 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 399 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 801 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 904 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 994 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 346 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 920 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 359 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 218 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 88 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 227 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 292 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 533 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 206 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 244 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 401 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 536 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 834 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 80 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 799 True 9
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 819 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 908 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 738 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 762 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 873 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 113 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 910 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 537 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 552 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 541 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 28 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 947 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 830 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 492 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 704 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 791 True 6
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 495 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 331 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 83 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 140 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 62 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 22 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 369 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 493 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 424 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 400 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 303 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 449 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 389 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 334 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 345 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 442 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 314 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 393 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 528 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 437 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 443 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 409 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 315 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 366 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 464 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 486 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 192 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 193 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 337 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 478 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 384 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 200 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 452 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 523 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 368 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 422 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 191 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 427 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 539 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 177 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 335 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 174 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 336 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 321 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 902 True 5
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 458 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 768 True 7
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 43 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 787 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 847 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1011 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 772 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 828 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 794 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 277 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 575 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 726 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 795 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 971 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 282 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 418 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 24 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 924 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 556 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 268 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 320 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 943 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 891 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1004 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 832 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 972 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 929 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 561 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 351 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 117 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 803 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 900 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 42 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 524 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 509 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 281 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 429 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 102 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 984 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 494 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 490 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 1000 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 941 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 484 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 220 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 169 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 293 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 549 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 372 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 122 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 257 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 916 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 134 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 450 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 480 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 386 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 246 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 375 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 371 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 304 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 289 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg1 size = 341 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 1024 True 533
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 982 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 320 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 438 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 305 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 974 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 1017 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 55 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 290 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 435 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 150 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 159 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 260 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 267 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 381 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 429 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 461 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 170 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 523 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 11 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 990 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 817 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 354 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 223 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 49 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 84 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 86 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 79 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 318 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 361 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 151 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 1009 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 400 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 72 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 258 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 140 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 133 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 256 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 29 True 3
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 48 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 68 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 131 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 261 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 91 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 167 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 1022 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 103 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 927 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 526 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 219 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 951 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 908 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 862 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 311 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 356 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 316 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 562 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 182 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 324 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 210 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 1016 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 347 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 343 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 241 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 63 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 294 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 321 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 337 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 92 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 317 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 259 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 392 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 323 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 456 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 510 True 4
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 292 True 2
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 476 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 457 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 174 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 442 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 147 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 209 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 31 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 192 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 250 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 98 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 407 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 242 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 372 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 184 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 148 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 230 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 46 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 401 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 270 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 441 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 916 True 1
Fn
Data
WRITE c:\users\public\n3eg\ljkg2 size = 117 True 1
Fn
Data
For performance reasons, the remaining 9 entries are omitted.
Click to download all 1009 entries as text file (0.39 MB).
Process (1)
+
Operation Process Name Additional Information Success Count Logfile
CREATE regsvr32.exe \s \"C:\Users\Public\N3Eg\N3Eg2.51N3E\" #96 os_tid = 0xbfc, os_pid = 0xbf8, creation_flags = CREATE_UNICODE_ENVIRONMENT, CREATE_NO_WINDOW, startup_flags = STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
Module (12)
+
Operation Module Additional Information Success Count Logfile
LOAD SHELL32.dll base_address = 0x759e0000 True 1
Fn
GET_HANDLE c:\program files\java\jre1.8.0_92\bin\client\jvm.dll base_address = 0x6d510000 True 2
Fn
GET_HANDLE c:\windows\system32\kernel32.dll base_address = 0x75900000 True 1
Fn
GET_HANDLE c:\program files\java\jre1.8.0_92\bin\java.exe base_address = 0xda0000 True 4
Fn
GET_FILENAME c:\program files\java\jre1.8.0_92\bin\client\jvm.dll file_name = C:\Program Files\Java\jre1.8.0_92\bin\client\jvm.dll True 1
Fn
GET_PROC_ADDRESS c:\program files\java\jre1.8.0_92\bin\client\jvm.dll function = JVM_GetVersionInfo, address = 0x6d60fed0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\shell32.dll function = SHGetKnownFolderPath, address = 0x75a94ca0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetFinalPathNameByHandleW, address = 0x75934e2a True 1
Fn
System (1)
+
Operation Information Success Count Logfile
GET_INFO type = Hardware Information True 1
Fn
Network Behavior
HTTP Session (1)
+
Remote Address Remote Port Username Password Success Count
80 True 1
HTTP Request (3)
+
Method URL Success Count
GET http://None/nosoanfhtympkl50tre/ljk32g1.txt True 3
DNS (3)
+
Operation Host Additional Information Success Count Logfile
GET_HOSTNAME N3EErvtwsM True 1
Fn
RESOLVE_NAME N3EErvtwsM True 1
Fn
RESOLVE_NAME adom2.com.br True 1
Fn
TCP Outgoing Connection (1)
+
Remote Address Remote Port L7Protocol Success Count
80 True 1
Process #2: regsvr32.exe
(Host: 90, Network: 0)
+
Information Value
ID / OS PID #2 / 0xbf8
OS Parent PID 0xb6c (c:\program files\java\jre1.8.0_92\bin\java.exe)
Initial Working Directory C:\Users\DSsDPMx042\Desktop
File Name c:\windows\system32\regsvr32.exe
Command Line regsvr32.exe /s \"C:\\Users\\Public\\N3Eg\\N3Eg2.51N3E\" #96
Monitor Start Time: 00:00:26, Reason: Child Process
Unmonitor End Time: 00:00:30, Reason: Terminated
Monitor Duration 00:00:04
OS Thread IDs
# 13
0x BFC
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00041fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
pagefile_0x00000000000c0000 0x000c0000 0x000c1fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000000d0000 0x000d0000 0x000dffff Private Memory Readable, Writable True False False
pagefile_0x00000000000e0000 0x000e0000 0x001a7fff Pagefile Backed Memory Readable True False False
regsvr32.exe.mui 0x001b0000 0x001b1fff Memory Mapped File Readable, Writable False False False
private_0x00000000001c0000 0x001c0000 0x001c0fff Private Memory Readable, Writable True False False
private_0x00000000001d0000 0x001d0000 0x001d0fff Private Memory Readable, Writable True False False
pagefile_0x00000000001f0000 0x001f0000 0x001f1fff Pagefile Backed Memory Readable True False False
private_0x0000000000200000 0x00200000 0x0023ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000240000 0x00240000 0x00340fff Pagefile Backed Memory Readable True False False
private_0x0000000000350000 0x00350000 0x0044ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000450000 0x00450000 0x0052efff Pagefile Backed Memory Readable True False False
private_0x0000000000610000 0x00610000 0x0064ffff Private Memory Readable, Writable True False False
regsvr32.exe 0x006a0000 0x006a6fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x00000000006b0000 0x006b0000 0x012affff Pagefile Backed Memory Readable True False False
N3Eg2.51N3E 0x012b0000 0x01404fff Memory Mapped File Readable, Writable, Executable True True False
private_0x0000000001410000 0x01410000 0x0154ffff Private Memory Readable, Writable True False False
SortDefault.nls 0x01550000 0x0181efff Memory Mapped File Readable False False False
uxtheme.dll 0x74090000 0x740cffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x74110000 0x742adfff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x752a0000 0x752abfff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x76a90000 0x76bebfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76d70000 0x76dc6fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x76ee0000 0x76f6efff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Host Behavior
Process (1)
+
Operation Process Name Additional Information Success Count Logfile
OPEN c:\windows\explorer.exe os_pid = 0x4f0, desired_access = PROCESS_ALL_ACCESS True 1
Fn
Memory (2)
+
Operation Address Additional Information Success Count Logfile
ALLOC 0x4fd0000 process_name = c:\windows\explorer.exe, os_pid = 0x4f0, size = 66, allocation_type = MEM_COMMIT, protection = PAGE_READWRITE True 1
Fn
WRITE 0x4fd0000 process_name = c:\windows\explorer.exe, os_pid = 0x4f0, size = 66 True 1
Fn
Data
Thread (1)
+
Operation Process Name Additional Information Success Count Logfile
CREATE c:\windows\explorer.exe os_tid = 0xc00, os_pid = 0x4f0, proc_address = 0x75953c01, flags = THREAD_RUNS_IMMEDIATELY True 1
Fn
Module (73)
+
Operation Module Additional Information Success Count Logfile
LOAD kernel32.dll base_address = 0x75900000 True 3
Fn
GET_HANDLE c:\windows\system32\kernel32.dll base_address = 0x75900000 True 7
Fn
GET_HANDLE c:\windows\system32\oleaut32.dll base_address = 0x76ee0000 True 1
Fn
GET_FILENAME C:\Users\Public\N3Eg\N3Eg2.51N3E True 1
Fn
GET_FILENAME C:\Windows\system32\regsvr32.exe True 3
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetThreadPreferredUILanguages, address = 0x759422d7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetThreadPreferredUILanguages, address = 0x7593e627 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetThreadUILanguage, address = 0x7593ae42 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetNativeSystemInfo, address = 0x7593be77 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetDiskFreeSpaceExW, address = 0x7593de40 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VariantChangeTypeEx, address = 0x76ee4c28 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarNeg, address = 0x76f5c802 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarNot, address = 0x76f5ec66 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarAdd, address = 0x76f05934 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarSub, address = 0x76f5d332 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarMul, address = 0x76f5dbd4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarDiv, address = 0x76f5e405 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarIdiv, address = 0x76f5f00a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarMod, address = 0x76f5f15e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarAnd, address = 0x76f05a98 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarOr, address = 0x76f5ecfa True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarXor, address = 0x76f5ee2e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarCmp, address = 0x76efb0dc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarI4FromStr, address = 0x76ef6fab True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarR4FromStr, address = 0x76f001a0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarR8FromStr, address = 0x76ef699e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarDateFromStr, address = 0x76f06ba7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarCyFromStr, address = 0x76f26c12 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarBoolFromStr, address = 0x76efdbd1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarBstrFromCy, address = 0x76f07fdc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarBstrFromDate, address = 0x76ef7a2a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarBstrFromBool, address = 0x76f00355 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = InitializeConditionVariable, address = 0x77259981 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WakeConditionVariable, address = 0x772a5a7b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WakeAllConditionVariable, address = 0x772245a5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SleepConditionVariableCS, address = 0x759318be True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CreateToolhelp32Snapshot, address = 0x7593f731 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Heap32ListFirst, address = 0x759902e7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Heap32ListNext, address = 0x75990391 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Heap32First, address = 0x75990429 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Heap32Next, address = 0x75990614 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Toolhelp32ReadProcessMemory, address = 0x75990819 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Process32First, address = 0x7596443d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Process32Next, address = 0x75964505 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Process32FirstW, address = 0x7593fa35 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Process32NextW, address = 0x7593faca True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Thread32First, address = 0x75967e4c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Thread32Next, address = 0x75967edc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Module32First, address = 0x75990859 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Module32Next, address = 0x75990942 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Module32FirstW, address = 0x7593c59e True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Module32NextW, address = 0x7593c11f True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = VirtualAllocEx, address = 0x7593c1b6 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WriteProcessMemory, address = 0x7593c1de True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CreateRemoteThread, address = 0x7598f33b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = OpenProcess, address = 0x759459d7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LoadLibraryW, address = 0x75953c01 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetLogicalProcessorInformation, address = 0x75932004 True 2
Fn
Registry (12)
+
Operation Key Additional Information Success Count Logfile
OPEN_KEY HKEY_CURRENT_USER\Software\Embarcadero\Locales False 2
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Embarcadero\Locales False 2
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\CodeGear\Locales False 2
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\CodeGear\Locales False 2
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Borland\Locales False 2
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Borland\Delphi\Locales False 2
Fn
System (1)
+
Operation Information Success Count Logfile
GET_INFO type = Hardware Information True 1
Fn
Process #3: explorer.exe
(Host: 890, Network: 22)
+
Information Value
ID / OS PID #3 / 0x4f0
OS Parent PID 0xffffffffffffffff (Unknown)
Initial Working Directory C:\Windows\system32
File Name c:\windows\explorer.exe
Command Line C:\Windows\Explorer.EXE
Monitor Start Time: 00:00:29, Reason: Injection
Unmonitor End Time: 00:03:50, Reason: Terminated
Monitor Duration 00:03:21
OS Thread IDs
# 14
0x AB8
# 15
0x 9DC
# 16
0x 9D0
# 17
0x 9C4
# 18
0x 9B8
# 19
0x 9B4
# 20
0x 988
# 21
0x 93C
# 22
0x 91C
# 23
0x 914
# 24
0x 8C8
# 25
0x 4BC
# 26
0x 6A0
# 27
0x 678
# 28
0x 670
# 29
0x 658
# 30
0x 654
# 31
0x 5FC
# 32
0x 5E8
# 33
0x 5E0
# 34
0x 5C8
# 35
0x 5C4
# 36
0x 5C0
# 37
0x 5BC
# 38
0x 5B8
# 39
0x 5AC
# 40
0x 5A8
# 41
0x 5A4
# 42
0x 59C
# 43
0x 528
# 44
0x 524
# 45
0x 51C
# 46
0x 518
# 47
0x 514
# 48
0x 4FC
# 49
0x 4F4
# 50
0x C00
# 51
0x C04
# 52
0x C28
# 53
0x CAC
# 81
0x F00
# 94
0x F7C
# 101
0x 48C
# 102
0x 470
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00021fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00041fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000050000 0x00050000 0x00056fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00061fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000070000 0x00070000 0x00070fff Private Memory Readable, Writable True False False
private_0x0000000000080000 0x00080000 0x0017ffff Private Memory Readable, Writable True False False
locale.nls 0x00180000 0x001e6fff Memory Mapped File Readable False False False
private_0x00000000001f0000 0x001f0000 0x0022ffff Private Memory Readable, Writable True False False
private_0x0000000000230000 0x00230000 0x00230fff Private Memory Readable, Writable True False False
private_0x0000000000240000 0x00240000 0x0025ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000260000 0x00260000 0x00260fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000270000 0x00270000 0x00271fff Pagefile Backed Memory Readable True False False
private_0x0000000000280000 0x00280000 0x00280fff Private Memory Readable, Writable True False False
pagefile_0x0000000000290000 0x00290000 0x00291fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000002a0000 0x002a0000 0x002a0fff Pagefile Backed Memory Readable True False False
private_0x00000000002b0000 0x002b0000 0x002bffff Private Memory Readable, Writable True False False
pagefile_0x00000000002c0000 0x002c0000 0x00387fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000390000 0x00390000 0x00490fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000004a0000 0x004a0000 0x00892fff Pagefile Backed Memory Readable True False False
private_0x00000000008a0000 0x008a0000 0x0099ffff Private Memory Readable, Writable True False False
pagefile_0x00000000009a0000 0x009a0000 0x009a0fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000009b0000 0x009b0000 0x009b1fff Pagefile Backed Memory Readable True False False
private_0x00000000009c0000 0x009c0000 0x009fffff Private Memory Readable, Writable True False False
pagefile_0x0000000000a00000 0x00a00000 0x00adefff Pagefile Backed Memory Readable True False False
private_0x0000000000ae0000 0x00ae0000 0x00b0bfff Private Memory Readable, Writable True False False
private_0x0000000000b10000 0x00b10000 0x00b3ffff Private Memory Readable, Writable True False False
private_0x0000000000b40000 0x00b40000 0x00bbffff Private Memory Readable, Writable True False False
explorer.exe 0x00bc0000 0x00e40fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000e50000 0x00e50000 0x01a4ffff Pagefile Backed Memory Readable True False False
private_0x0000000001a50000 0x01a50000 0x01a8ffff Private Memory Readable, Writable True False False
SortDefault.nls 0x01a90000 0x01d5efff Memory Mapped File Readable False False False
pagefile_0x0000000001d60000 0x01d60000 0x01d61fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001d70000 0x01d70000 0x01d71fff Pagefile Backed Memory Readable True False False
private_0x0000000001d80000 0x01d80000 0x01d80fff Private Memory Readable, Writable True False False
comctl32.dll.mui 0x01d90000 0x01d92fff Memory Mapped File Readable, Writable False False False
private_0x0000000001da0000 0x01da0000 0x01da0fff Private Memory Readable, Writable True False False
private_0x0000000001db0000 0x01db0000 0x01deffff Private Memory Readable, Writable True False False
private_0x0000000001df0000 0x01df0000 0x01dfffff Private Memory Readable, Writable True False False
private_0x0000000001e00000 0x01e00000 0x01e08fff Private Memory Readable, Writable True False False
private_0x0000000001e10000 0x01e10000 0x01e4ffff Private Memory Readable, Writable True False False
pagefile_0x0000000001e10000 0x01e10000 0x01e11fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001e20000 0x01e20000 0x01e21fff Pagefile Backed Memory Readable True False False
ActionCenter.dll.mui 0x01e30000 0x01e34fff Memory Mapped File Readable, Writable False False False
private_0x0000000001e50000 0x01e50000 0x01e57fff Private Memory Readable, Writable True False False
private_0x0000000001e60000 0x01e60000 0x01f07fff Private Memory Readable, Writable True False False
private_0x0000000001f10000 0x01f10000 0x01fc3fff Private Memory Readable, Writable True False False
private_0x0000000001fd0000 0x01fd0000 0x01fd0fff Private Memory Readable, Writable True False False
private_0x0000000001fe0000 0x01fe0000 0x01fe0fff Private Memory Readable, Writable True False False
{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000000c.db 0x01ff0000 0x0200cfff Memory Mapped File Readable True False False
pagefile_0x0000000002010000 0x02010000 0x02010fff Pagefile Backed Memory Readable, Writable True False False
cversions.2.db 0x02020000 0x02023fff Memory Mapped File Readable True False False
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000007.db 0x02030000 0x0205ffff Memory Mapped File Readable True False False
cversions.2.db 0x02060000 0x02063fff Memory Mapped File Readable True False False
pagefile_0x0000000002070000 0x02070000 0x02071fff Pagefile Backed Memory Readable True False False
private_0x0000000002080000 0x02080000 0x020bffff Private Memory Readable, Writable True False False
private_0x0000000002080000 0x02080000 0x020affff Private Memory Readable, Writable True False False
pagefile_0x00000000020c0000 0x020c0000 0x020c1fff Pagefile Backed Memory Readable True False False
private_0x00000000020d0000 0x020d0000 0x020d3fff Private Memory Readable, Writable True False False
thumbcache_1024.db 0x020e0000 0x020e0fff Memory Mapped File Readable, Writable True False False
thumbcache_sr.db 0x020f0000 0x020f0fff Memory Mapped File Readable, Writable True False False
thumbcache_idx.db 0x02100000 0x02101fff Memory Mapped File Readable, Writable True False False
private_0x0000000002110000 0x02110000 0x0230ffff Private Memory Readable, Writable True False False
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db 0x02310000 0x02375fff Memory Mapped File Readable True False False
private_0x0000000002380000 0x02380000 0x02380fff Private Memory Readable, Writable True False False
private_0x0000000002390000 0x02390000 0x023cffff Private Memory Readable, Writable True False False
private_0x00000000023d0000 0x023d0000 0x023d3fff Private Memory Readable, Writable True False False
private_0x00000000023e0000 0x023e0000 0x023e3fff Private Memory Readable, Writable True False False
pagefile_0x00000000023f0000 0x023f0000 0x023f1fff Pagefile Backed Memory Readable True False False
private_0x0000000002400000 0x02400000 0x02400fff Private Memory Readable, Writable True False False
private_0x0000000002410000 0x02410000 0x02410fff Private Memory Readable, Writable True False False
private_0x0000000002420000 0x02420000 0x02420fff Private Memory Readable, Writable True False False
private_0x0000000002430000 0x02430000 0x0246ffff Private Memory Readable, Writable True False False
private_0x0000000002470000 0x02470000 0x02470fff Private Memory Readable, Writable True False False
thumbcache_1024.db 0x02480000 0x02480fff Memory Mapped File Readable, Writable True False False
thumbcache_sr.db 0x02490000 0x02490fff Memory Mapped File Readable, Writable True False False
thumbcache_idx.db 0x024a0000 0x024a1fff Memory Mapped File Readable, Writable True False False
pagefile_0x00000000024b0000 0x024b0000 0x024b0fff Pagefile Backed Memory Readable True False False
private_0x00000000024c0000 0x024c0000 0x024c0fff Private Memory Readable, Writable True False False
private_0x00000000024d0000 0x024d0000 0x0250ffff Private Memory Readable, Writable True False False
pagefile_0x0000000002510000 0x02510000 0x02510fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000002520000 0x02520000 0x02521fff Pagefile Backed Memory Readable True False False
cversions.2.db 0x02530000 0x02533fff Memory Mapped File Readable True False False
pagefile_0x0000000002540000 0x02540000 0x02541fff Pagefile Backed Memory Readable True False False
{7CD55808-3D38-4DD5-90C9-62F0E6EE60D4}.2.ver0x0000000000000001.db 0x02550000 0x02550fff Memory Mapped File Readable True False False
private_0x0000000002560000 0x02560000 0x02560fff Private Memory Readable, Writable True False False
private_0x0000000002570000 0x02570000 0x02570fff Private Memory Readable, Writable True False False
private_0x0000000002580000 0x02580000 0x02580fff Private Memory Readable, Writable True False False
private_0x0000000002590000 0x02590000 0x02590fff Private Memory Readable, Writable True False False
private_0x00000000025a0000 0x025a0000 0x025a0fff Private Memory Readable, Writable True False False
private_0x00000000025b0000 0x025b0000 0x025b0fff Private Memory Readable, Writable True False False
private_0x00000000025c0000 0x025c0000 0x025fffff Private Memory Readable, Writable True False False
StaticCache.dat 0x02600000 0x02f2ffff Memory Mapped File Readable False False False
private_0x0000000002f30000 0x02f30000 0x0302ffff Private Memory Readable, Writable True False False
private_0x0000000003030000 0x03030000 0x03030fff Private Memory Readable, Writable True False False
private_0x0000000003040000 0x03040000 0x03040fff Private Memory Readable, Writable True False False
private_0x0000000003050000 0x03050000 0x03050fff Private Memory Readable, Writable True False False
private_0x0000000003060000 0x03060000 0x03060fff Private Memory Readable, Writable True False False
private_0x0000000003070000 0x03070000 0x030affff Private Memory Readable, Writable True False False
wdmaud.drv.mui 0x030b0000 0x030b0fff Memory Mapped File Readable, Writable False False False
MMDevAPI.dll.mui 0x030c0000 0x030c0fff Memory Mapped File Readable, Writable False False False
private_0x00000000030d0000 0x030d0000 0x030d1fff Private Memory Readable, Writable True False False
thumbcache_1024.db 0x030e0000 0x030e0fff Memory Mapped File Readable, Writable True False False
private_0x00000000030f0000 0x030f0000 0x0312ffff Private Memory Readable, Writable True False False
private_0x0000000003130000 0x03130000 0x0316ffff Private Memory Readable, Writable True False False
private_0x0000000003130000 0x03130000 0x0316ffff Private Memory Readable, Writable True False False
thumbcache_sr.db 0x03170000 0x03170fff Memory Mapped File Readable, Writable True False False
thumbcache_idx.db 0x03180000 0x03181fff Memory Mapped File Readable, Writable True False False
pagefile_0x0000000003190000 0x03190000 0x03191fff Pagefile Backed Memory Readable True False False
private_0x00000000031a0000 0x031a0000 0x031dffff Private Memory Readable, Writable True False False
private_0x00000000031e0000 0x031e0000 0x0321ffff Private Memory Readable, Writable True False False
pagefile_0x0000000003220000 0x03220000 0x03221fff Pagefile Backed Memory Readable True False False
cversions.2.db 0x03230000 0x03233fff Memory Mapped File Readable True False False
private_0x0000000003240000 0x03240000 0x03240fff Private Memory Readable, Writable, Executable True False False
pagefile_0x0000000003250000 0x03250000 0x03250fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000003260000 0x03260000 0x03260fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000003270000 0x03270000 0x03270fff Private Memory Readable, Writable True False False
private_0x0000000003280000 0x03280000 0x03280fff Private Memory Readable, Writable True False False
private_0x0000000003290000 0x03290000 0x03292fff Private Memory Readable, Writable True False False
pagefile_0x00000000032a0000 0x032a0000 0x032a1fff Pagefile Backed Memory Readable True False False
private_0x00000000032b0000 0x032b0000 0x032f7fff Private Memory Readable, Writable True False False
private_0x0000000003300000 0x03300000 0x03332fff Private Memory Readable, Writable True False False
pagefile_0x0000000003340000 0x03340000 0x03341fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000003350000 0x03350000 0x03351fff Pagefile Backed Memory Readable True False False
thumbcache_1024.db 0x03360000 0x03360fff Memory Mapped File Readable, Writable True False False
thumbcache_sr.db 0x03370000 0x03370fff Memory Mapped File Readable, Writable True False False
thumbcache_idx.db 0x03380000 0x03381fff Memory Mapped File Readable, Writable True False False
pagefile_0x0000000003390000 0x03390000 0x03391fff Pagefile Backed Memory Readable True False False
private_0x00000000033a0000 0x033a0000 0x033dffff Private Memory Readable, Writable True False False
private_0x00000000033a0000 0x033a0000 0x033dffff Private Memory Readable, Writable True False False
private_0x00000000033e0000 0x033e0000 0x0341ffff Private Memory Readable, Writable True False False
private_0x00000000033f0000 0x033f0000 0x0342ffff Private Memory Readable, Writable True False False
thumbcache_32.db 0x03420000 0x0351ffff Memory Mapped File Readable, Writable True False False
private_0x0000000003520000 0x03520000 0x0356ffff Private Memory Readable, Writable True False False
oleaccrc.dll 0x03570000 0x03570fff Memory Mapped File Readable False False False
thumbcache_96.db 0x03580000 0x0367ffff Memory Mapped File Readable, Writable True False False
private_0x00000000035b0000 0x035b0000 0x035effff Private Memory Readable, Writable True False False
private_0x00000000035f0000 0x035f0000 0x0362ffff Private Memory Readable, Writable True False False
thumbcache_256.db 0x03680000 0x0377ffff Memory Mapped File Readable, Writable True False False
pagefile_0x0000000003780000 0x03780000 0x03781fff Pagefile Backed Memory Readable True False False
private_0x0000000003790000 0x03790000 0x037cffff Private Memory Readable, Writable True False False
bthprops.cpl.mui 0x037d0000 0x037d6fff Memory Mapped File Readable, Writable False False False
pagefile_0x00000000037e0000 0x037e0000 0x037e1fff Pagefile Backed Memory Readable True False False
private_0x00000000037f0000 0x037f0000 0x0382ffff Private Memory Readable, Writable True False False
imageres.dll 0x03830000 0x04b84fff Memory Mapped File Readable False False False
private_0x0000000004b90000 0x04b90000 0x04f91fff Private Memory Readable, Writable True False False
pagefile_0x0000000004fa0000 0x04fa0000 0x04fa1fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000004fb0000 0x04fb0000 0x04fb1fff Pagefile Backed Memory Readable True False False
prnfldr.dll.mui 0x04fc0000 0x04fc3fff Memory Mapped File Readable, Writable False False False
private_0x0000000004fd0000 0x04fd0000 0x04fd0fff Private Memory Readable, Writable True False False
private_0x0000000004fe0000 0x04fe0000 0x04fe0fff Private Memory Readable, Writable, Executable True False False
private_0x0000000004ff0000 0x04ff0000 0x04ffffff Private Memory Readable, Writable True False False
index.dat 0x05000000 0x05013fff Memory Mapped File Readable, Writable True True False
private_0x0000000005020000 0x05020000 0x0505ffff Private Memory Readable, Writable True False False
thumbcache_32.db 0x05060000 0x0515ffff Memory Mapped File Readable, Writable True False False
thumbcache_96.db 0x05160000 0x0525ffff Memory Mapped File Readable, Writable True False False
thumbcache_256.db 0x05260000 0x0535ffff Memory Mapped File Readable, Writable True False False
private_0x0000000005360000 0x05360000 0x0539ffff Private Memory Readable, Writable True False False
private_0x00000000053a0000 0x053a0000 0x053dffff Private Memory Readable, Writable True False False
index.dat 0x053e0000 0x053e7fff Memory Mapped File Readable, Writable True True False
index.dat 0x053f0000 0x053fbfff Memory Mapped File Readable, Writable True True False
private_0x0000000005410000 0x05410000 0x0544ffff Private Memory Readable, Writable True False False
private_0x0000000005450000 0x05450000 0x0564ffff Private Memory Readable, Writable True False False
private_0x0000000005650000 0x05650000 0x0568ffff Private Memory Readable, Writable True False False
private_0x0000000005690000 0x05690000 0x056cffff Private Memory Readable, Writable True False False
private_0x00000000056d0000 0x056d0000 0x0570ffff Private Memory Readable, Writable True False False
thumbcache_256.db 0x05710000 0x057bffff Memory Mapped File Readable, Writable True False False
thumbcache_32.db 0x057c0000 0x058bffff Memory Mapped File Readable, Writable True False False
thumbcache_96.db 0x058c0000 0x059bffff Memory Mapped File Readable, Writable True False False
thumbcache_256.db 0x059c0000 0x05abffff Memory Mapped File Readable, Writable True False False
thumbcache_256.db 0x05ac0000 0x05b6ffff Memory Mapped File Readable, Writable True False False
thumbcache_32.db 0x05b70000 0x05c6ffff Memory Mapped File Readable, Writable True False False
thumbcache_96.db 0x05c70000 0x05d6ffff Memory Mapped File Readable, Writable True False False
thumbcache_256.db 0x05d70000 0x05e6ffff Memory Mapped File Readable, Writable True False False
private_0x0000000005e70000 0x05e70000 0x05eaffff Private Memory Readable, Writable True False False
private_0x0000000005ed0000 0x05ed0000 0x05f0ffff Private Memory Readable, Writable True False False
private_0x0000000005f30000 0x05f30000 0x05f6ffff Private Memory Readable, Writable True False False
private_0x0000000005fb0000 0x05fb0000 0x05feffff Private Memory Readable, Writable True False False
private_0x0000000005ff0000 0x05ff0000 0x0602ffff Private Memory Readable, Writable True False False
private_0x00000000060a0000 0x060a0000 0x060dffff Private Memory Readable, Writable True False False
private_0x0000000006100000 0x06100000 0x0613ffff Private Memory Readable, Writable True False False
private_0x0000000006190000 0x06190000 0x061cffff Private Memory Readable, Writable True False False
private_0x00000000061f0000 0x061f0000 0x0622ffff Private Memory Readable, Writable True False False
private_0x00000000062a0000 0x062a0000 0x062affff Private Memory Readable, Writable True False False
KernelBase.dll.mui 0x062b0000 0x0636ffff Memory Mapped File Readable, Writable False False False
private_0x0000000006370000 0x06370000 0x063affff Private Memory Readable, Writable True False False
private_0x0000000006410000 0x06410000 0x0641ffff Private Memory Readable, Writable True False False
private_0x0000000006450000 0x06450000 0x0648ffff Private Memory Readable, Writable True False False
private_0x00000000064c0000 0x064c0000 0x064fffff Private Memory Readable, Writable True False False
private_0x0000000006550000 0x06550000 0x0658ffff Private Memory Readable, Writable True False False
private_0x00000000065b0000 0x065b0000 0x065bffff Private Memory Readable, Writable True False False
thumbcache_256.db 0x065c0000 0x0666ffff Memory Mapped File Readable, Writable True False False
N3Eg4.51N3E 0x06670000 0x066e4fff Memory Mapped File Readable, Writable, Executable True True False
private_0x0000000006730000 0x06730000 0x0676ffff Private Memory Readable, Writable True False False
private_0x0000000006770000 0x06770000 0x0686ffff Private Memory - True False False
private_0x00000000068c0000 0x068c0000 0x068fffff Private Memory Readable, Writable True False False
private_0x0000000006900000 0x06900000 0x06b92fff Private Memory Readable, Writable True False False
private_0x0000000006ba0000 0x06ba0000 0x06e3bfff Private Memory Readable, Writable True False False
private_0x0000000006e40000 0x06e40000 0x070dffff Private Memory - True False False
private_0x00000000070e0000 0x070e0000 0x0721ffff Private Memory Readable, Writable True False False
private_0x00000000072e0000 0x072e0000 0x0731ffff Private Memory Readable, Writable True False False
private_0x0000000007450000 0x07450000 0x0748ffff Private Memory Readable, Writable True False False
ieproxy.dll 0x6c3f0000 0x6c41afff Memory Mapped File Readable, Writable, Executable False False False
hcproviders.dll 0x6cea0000 0x6cea8fff Memory Mapped File Readable, Writable, Executable False False False
wercplsupport.dll 0x6ceb0000 0x6cec1fff Memory Mapped File Readable, Writable, Executable False False False
werconcpl.dll 0x6ced0000 0x6cfd5fff Memory Mapped File Readable, Writable, Executable False False False
wscui.cpl 0x6cfe0000 0x6d0f9fff Memory Mapped File Readable, Writable, Executable False False False
framedynos.dll 0x6d5e0000 0x6d614fff Memory Mapped File Readable, Writable, Executable False False False
wscinterop.dll 0x6d620000 0x6d639fff Memory Mapped File Readable, Writable, Executable False False False
wscapi.dll 0x6d930000 0x6d93efff Memory Mapped File Readable, Writable, Executable False False False
idndl.dll 0x6e0f0000 0x6e0fafff Memory Mapped File Readable, Writable, Executable False False False
olepro32.dll 0x6e100000 0x6e118fff Memory Mapped File Readable, Writable, Executable False False False
FXSRESM.dll 0x6e120000 0x6e202fff Memory Mapped File Readable, Writable, Executable False False False
FXSAPI.dll 0x6e210000 0x6e249fff Memory Mapped File Readable, Writable, Executable False False False
FXSST.dll 0x6e250000 0x6e321fff Memory Mapped File Readable, Writable, Executable False False False
provsvc.dll 0x6e330000 0x6e35afff Memory Mapped File Readable, Writable, Executable False False False
imapi2.dll 0x6e360000 0x6e3c3fff Memory Mapped File Readable, Writable, Executable False False False
ActionCenter.dll 0x6e3d0000 0x6e489fff Memory Mapped File Readable, Writable, Executable False False False
SyncCenter.dll 0x6e490000 0x6e69dfff Memory Mapped File Readable, Writable, Executable False False False
ieframe.dll 0x6e6a0000 0x6f11ffff Memory Mapped File Readable, Writable, Executable False False False
bthprops.cpl 0x6f120000 0x6f1cffff Memory Mapped File Readable, Writable, Executable False False False
srchadmin.dll 0x6f1f0000 0x6f23cfff Memory Mapped File Readable, Writable, Executable False False False
cscobj.dll 0x6f240000 0x6f264fff Memory Mapped File Readable, Writable, Executable False False False
QAGENT.DLL 0x6f290000 0x6f2bdfff Memory Mapped File Readable, Writable, Executable False False False
WWanAPI.dll 0x6f2c0000 0x6f307fff Memory Mapped File Readable, Writable, Executable False False False
wlanapi.dll 0x6f310000 0x6f325fff Memory Mapped File Readable, Writable, Executable False False False
wwapi.dll 0x6f330000 0x6f339fff Memory Mapped File Readable, Writable, Executable False False False
wlanutil.dll 0x6f340000 0x6f345fff Memory Mapped File Readable, Writable, Executable False False False
QUTIL.DLL 0x6f520000 0x6f536fff Memory Mapped File Readable, Writable, Executable False False False
pnidui.dll 0x6f540000 0x6f6edfff Memory Mapped File Readable, Writable, Executable False False False
PortableDeviceTypes.dll 0x6f6f0000 0x6f71afff Memory Mapped File Readable, Writable, Executable False False False
WPDShServiceObj.dll 0x6f720000 0x6f73cfff Memory Mapped File Readable, Writable, Executable False False False
netshell.dll 0x6f740000 0x6f9a4fff Memory Mapped File Readable, Writable, Executable False False False
security.dll 0x6f9b0000 0x6f9b2fff Memory Mapped File Readable, Writable, Executable False False False
ehSSO.dll 0x6f9c0000 0x6f9c7fff Memory Mapped File Readable, Writable, Executable False False False
AltTab.dll 0x6f9d0000 0x6f9ddfff Memory Mapped File Readable, Writable, Executable False False False
UIAnimation.dll 0x6f9e0000 0x6f9fafff Memory Mapped File Readable, Writable, Executable False False False
Syncreg.dll 0x6fa00000 0x6fa0ffff Memory Mapped File Readable, Writable, Executable False False False
DXP.dll 0x6fa10000 0x6fa73fff Memory Mapped File Readable, Writable, Executable False False False
PortableDeviceApi.dll 0x6fae0000 0x6fb68fff Memory Mapped File Readable, Writable, Executable False False False
winspool.drv 0x6fba0000 0x6fbf0fff Memory Mapped File Readable, Writable, Executable False False False
prnfldr.dll 0x6fc00000 0x6fc63fff Memory Mapped File Readable, Writable, Executable False False False
batmeter.dll 0x6fc70000 0x6fd26fff Memory Mapped File Readable, Writable, Executable False False False
stobject.dll 0x6fd30000 0x6fd69fff Memory Mapped File Readable, Writable, Executable False False False
msftedit.dll 0x6fe90000 0x6ff23fff Memory Mapped File Readable, Writable, Executable False False False
netprofm.dll 0x70690000 0x706e9fff Memory Mapped File Readable, Writable, Executable False False False
midimap.dll 0x70da0000 0x70da6fff Memory Mapped File Readable, Writable, Executable False False False
msacm32.dll 0x70db0000 0x70dc3fff Memory Mapped File Readable, Writable, Executable False False False
msacm32.drv 0x70dd0000 0x70dd7fff Memory Mapped File Readable, Writable, Executable False False False
AudioSes.dll 0x70e70000 0x70ea5fff Memory Mapped File Readable, Writable, Executable False False False
ksuser.dll 0x70eb0000 0x70eb3fff Memory Mapped File Readable, Writable, Executable False False False
wdmaud.drv 0x70ec0000 0x70eeffff Memory Mapped File Readable, Writable, Executable False False False
winmm.dll 0x70ef0000 0x70f21fff Memory Mapped File Readable, Writable, Executable False False False
networkexplorer.dll 0x70f30000 0x710c7fff Memory Mapped File Readable, Writable, Executable False False False
thumbcache.dll 0x710d0000 0x710e5fff Memory Mapped File Readable, Writable, Executable False False False
tiptsf.dll 0x71390000 0x713e7fff Memory Mapped File Readable, Writable, Executable False False False
msls31.dll 0x713f0000 0x71419fff Memory Mapped File Readable, Writable, Executable False False False
npmproxy.dll 0x714b0000 0x714b7fff Memory Mapped File Readable, Writable, Executable False False False
wer.dll 0x714c0000 0x71520fff Memory Mapped File Readable, Writable, Executable False False False
gameux.dll 0x71530000 0x717a7fff Memory Mapped File Readable, Writable, Executable False False False
linkinfo.dll 0x717b0000 0x717b8fff Memory Mapped File Readable, Writable, Executable False False False
shdocvw.dll 0x717c0000 0x717edfff Memory Mapped File Readable, Writable, Executable False False False
actxprxy.dll 0x717f0000 0x7183dfff Memory Mapped File Readable, Writable, Executable False False False
timedate.cpl 0x71840000 0x718b7fff Memory Mapped File Readable, Writable, Executable False False False
IconCodecService.dll 0x71950000 0x71955fff Memory Mapped File Readable, Writable, Executable False False False
ntshrui.dll 0x71960000 0x719cffff Memory Mapped File Readable, Writable, Executable False False False
cscapi.dll 0x71a20000 0x71a2afff Memory Mapped File Readable, Writable, Executable False False False
cscdll.dll 0x71a30000 0x71a38fff Memory Mapped File Readable, Writable, Executable False False False
cscui.dll 0x71a40000 0x71aa9fff Memory Mapped File Readable, Writable, Executable False False False
EhStorShell.dll 0x71ab0000 0x71ae0fff Memory Mapped File Readable, Writable, Executable False False False
apphelp.dll 0x71af0000 0x71b3bfff Memory Mapped File Readable, Writable, Executable False False False
ExplorerFrame.dll 0x71b40000 0x71caefff Memory Mapped File Readable, Writable, Executable False False False
dhcpcsvc.dll 0x72100000 0x72111fff Memory Mapped File Readable, Writable, Executable False False False
dhcpcsvc6.dll 0x72120000 0x7212cfff Memory Mapped File Readable, Writable, Executable False False False
hgcpl.dll 0x72140000 0x7218efff Memory Mapped File Readable, Writable, Executable False False False
oleacc.dll 0x72190000 0x721cbfff Memory Mapped File Readable, Writable, Executable False False False
FWPUCLNT.DLL 0x721e0000 0x72217fff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x72300000 0x72306fff Memory Mapped File Readable, Writable, Executable False False False
IPHLPAPI.DLL 0x72310000 0x7232bfff Memory Mapped File Readable, Writable, Executable False False False
rasadhlp.dll 0x72350000 0x72355fff Memory Mapped File Readable, Writable, Executable False False False
webio.dll 0x73530000 0x7357efff Memory Mapped File Readable, Writable, Executable False False False
winhttp.dll 0x73580000 0x735d7fff Memory Mapped File Readable, Writable, Executable False False False
es.dll 0x736c0000 0x73706fff Memory Mapped File Readable, Writable, Executable False False False
slc.dll 0x73710000 0x73719fff Memory Mapped File Readable, Writable, Executable False False False
taskschd.dll 0x73770000 0x737ecfff Memory Mapped File Readable, Writable, Executable False False False
atl.dll 0x73800000 0x73813fff Memory Mapped File Readable, Writable, Executable False False False
nlaapi.dll 0x73850000 0x7385ffff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x739c0000 0x739e0fff Memory Mapped File Readable, Writable, Executable False False False
samcli.dll 0x73b20000 0x73b2efff Memory Mapped File Readable, Writable, Executable False False False
wkscli.dll 0x73b30000 0x73b3efff Memory Mapped File Readable, Writable, Executable False False False
netutils.dll 0x73b40000 0x73b48fff Memory Mapped File Readable, Writable, Executable False False False
wtsapi32.dll 0x73c50000 0x73c5cfff Memory Mapped File Readable, Writable, Executable False False False
WindowsCodecs.dll 0x73c70000 0x73d6afff Memory Mapped File Readable, Writable, Executable False False False
xmllite.dll 0x73d70000 0x73d9efff Memory Mapped File Readable, Writable, Executable False False False
dwmapi.dll 0x73da0000 0x73db2fff Memory Mapped File Readable, Writable, Executable False False False
hid.dll 0x73dc0000 0x73dc8fff Memory Mapped File Readable, Writable, Executable False False False
SndVolSSO.dll 0x73dd0000 0x73e07fff Memory Mapped File Readable, Writable, Executable False False False
duser.dll 0x73e10000 0x73e3efff Memory Mapped File Readable, Writable, Executable False False False
dui70.dll 0x73e40000 0x73ef1fff Memory Mapped File Readable, Writable, Executable False False False
GdiPlus.dll 0x73f00000 0x7408ffff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x74090000 0x740cffff Memory Mapped File Readable, Writable, Executable False False False
samlib.dll 0x740d0000 0x740e1fff Memory Mapped File Readable, Writable, Executable False False False
shacct.dll 0x740f0000 0x7410dfff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x74110000 0x742adfff Memory Mapped File Readable, Writable, Executable False False False
cryptui.dll 0x742b0000 0x743a7fff Memory Mapped File Readable, Writable, Executable False False False
authui.dll 0x743b0000 0x74566fff Memory Mapped File Readable, Writable, Executable False False False
avrt.dll 0x74590000 0x74596fff Memory Mapped File Readable, Writable, Executable False False False
propsys.dll 0x745a0000 0x74694fff Memory Mapped File Readable, Writable, Executable False False False
MMDevAPI.dll 0x746a0000 0x746d8fff Memory Mapped File Readable, Writable, Executable False False False
powrprof.dll 0x746e0000 0x74704fff Memory Mapped File Readable, Writable, Executable False False False
version.dll 0x748a0000 0x748a8fff Memory Mapped File Readable, Writable, Executable False False False
WSHTCPIP.DLL 0x74930000 0x74934fff Memory Mapped File Readable, Writable, Executable False False False
userenv.dll 0x74a00000 0x74a16fff Memory Mapped File Readable, Writable, Executable False False False
credssp.dll 0x74af0000 0x74af7fff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x74bc0000 0x74bfafff Memory Mapped File Readable, Writable, Executable False False False
dnsapi.dll 0x74ca0000 0x74ce3fff Memory Mapped File Readable, Writable, Executable False False False
wship6.dll 0x74dd0000 0x74dd5fff Memory Mapped File Readable, Writable, Executable False False False
mswsock.dll 0x74de0000 0x74e1bfff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x74e20000 0x74e35fff Memory Mapped File Readable, Writable, Executable False False False
wevtapi.dll 0x74fe0000 0x75021fff Memory Mapped File Readable, Writable, Executable False False False
srvcli.dll 0x751f0000 0x75208fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x75260000 0x75267fff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75280000 0x7529afff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x752a0000 0x752abfff Memory Mapped File Readable, Writable, Executable False False False
sxs.dll 0x752b0000 0x7530efff Memory Mapped File Readable, Writable, Executable False False False
winsta.dll 0x75310000 0x75338fff Memory Mapped File Readable, Writable, Executable False False False
RpcRtRemote.dll 0x75340000 0x7534dfff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x75350000 0x7535afff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x753c0000 0x753cbfff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x753d0000 0x754ecfff Memory Mapped File Readable, Writable, Executable False False False
devobj.dll 0x754f0000 0x75501fff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
wintrust.dll 0x75560000 0x7558cfff Memory Mapped File Readable, Writable, Executable False False False
cfgmgr32.dll 0x75590000 0x755b6fff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75650000 0x75744fff Memory Mapped File Readable, Writable, Executable False False False
Wldap32.dll 0x757d0000 0x75814fff Memory Mapped File Readable, Writable, Executable False False False
normaliz.dll 0x75820000 0x75822fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x759e0000 0x76629fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
setupapi.dll 0x766f0000 0x7688cfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x76890000 0x76a8afff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x76a90000 0x76bebfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76d70000 0x76dc6fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x76e20000 0x76ea2fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x76ee0000 0x76f6efff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x770c0000 0x771f5fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x77340000 0x77345fff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x77360000 0x77364fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x773f0000 0x77424fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
private_0x000000007ff9a000 0x7ff9a000 0x7ff9afff Private Memory Readable, Writable True False False
private_0x000000007ff9b000 0x7ff9b000 0x7ff9bfff Private Memory Readable, Writable True False False
private_0x000000007ff9c000 0x7ff9c000 0x7ff9cfff Private Memory Readable, Writable True False False
private_0x000000007ff9d000 0x7ff9d000 0x7ff9dfff Private Memory Readable, Writable True False False
private_0x000000007ff9e000 0x7ff9e000 0x7ff9efff Private Memory Readable, Writable True False False
private_0x000000007ff9f000 0x7ff9f000 0x7ff9ffff Private Memory Readable, Writable True False False
private_0x000000007ffa0000 0x7ffa0000 0x7ffa0fff Private Memory Readable, Writable True False False
private_0x000000007ffa1000 0x7ffa1000 0x7ffa1fff Private Memory Readable, Writable True False False
private_0x000000007ffa2000 0x7ffa2000 0x7ffa2fff Private Memory Readable, Writable True False False
private_0x000000007ffa3000 0x7ffa3000 0x7ffa3fff Private Memory Readable, Writable True False False
private_0x000000007ffa4000 0x7ffa4000 0x7ffa4fff Private Memory Readable, Writable True False False
private_0x000000007ffa5000 0x7ffa5000 0x7ffa5fff Private Memory Readable, Writable True False False
private_0x000000007ffa6000 0x7ffa6000 0x7ffa6fff Private Memory Readable, Writable True False False
private_0x000000007ffa7000 0x7ffa7000 0x7ffa7fff Private Memory Readable, Writable True False False
private_0x000000007ffa8000 0x7ffa8000 0x7ffa8fff Private Memory Readable, Writable True False False
private_0x000000007ffa9000 0x7ffa9000 0x7ffa9fff Private Memory Readable, Writable True False False
private_0x000000007ffaa000 0x7ffaa000 0x7ffaafff Private Memory Readable, Writable True False False
private_0x000000007ffab000 0x7ffab000 0x7ffabfff Private Memory Readable, Writable True False False
private_0x000000007ffac000 0x7ffac000 0x7ffacfff Private Memory Readable, Writable True False False
private_0x000000007ffad000 0x7ffad000 0x7ffadfff Private Memory Readable, Writable True False False
private_0x000000007ffae000 0x7ffae000 0x7ffaefff Private Memory Readable, Writable True False False
private_0x000000007ffaf000 0x7ffaf000 0x7ffaffff Private Memory Readable, Writable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffd3000 0x7ffd3000 0x7ffd3fff Private Memory Readable, Writable True False False
private_0x000000007ffd4000 0x7ffd4000 0x7ffd4fff Private Memory Readable, Writable True False False
private_0x000000007ffd5000 0x7ffd5000 0x7ffd5fff Private Memory Readable, Writable True False False
private_0x000000007ffd5000 0x7ffd5000 0x7ffd5fff Private Memory Readable, Writable True False False
private_0x000000007ffd6000 0x7ffd6000 0x7ffd6fff Private Memory Readable, Writable True False False
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory Readable, Writable True False False
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory Readable, Writable True False False
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory Readable, Writable True False False
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory Readable, Writable True False False
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory Readable, Writable True False False
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory Readable, Writable True False False
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory Readable, Writable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Injection Information
+
Injection Type Source Process Source Os Thread ID Injection Info Success Count Logfile
Modify Memory c:\windows\system32\regsvr32.exe 0xbfc address = 0x4fd0000, size = 66 True 1
Fn
Data
Create Remote Thread c:\windows\system32\regsvr32.exe 0xbfc os_thread_id = 0xc00, address = 0x75953c01, flags = THREAD_RUNS_IMMEDIATELY True 1
Fn
Created Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\public\n3eg\wvs 0.00 KB (4 bytes) MD5: f4314bbaf858170dd3b5d1610b3370fa
SHA1: fb456dcb16fcac006136471acaf71089398f2063
SHA256: 45e26aeb4a0e45265193e9293e88a93d9b3c89af4e401cb1812161c4568d0b51
False
c:\users\public\n3eg\idx 0.01 KB (10 bytes) MD5: a26185275591cd0849899d86349265a0
SHA1: 209b5d24d976b7399dd37ee9669c312ddc3da214
SHA256: 7361213f5c9ebbdf90b6865202c7f02607e3d57ec9b070448dba250bef7061f4
False
c:\users\public\n3eg\n3e.vbs 4.10 KB (4199 bytes) MD5: 519b80fd9d6073f6034820a5c0f0241c
SHA1: 5d7d06d0b1100817dfccf7c87c824650da296fc1
SHA256: 7ac2bab32a34ef844ac2a63864db4d238011723b81f4072f22b148a4535a56d8
False
Modified Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\dssdpmx042\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat 80.00 KB (81920 bytes) MD5: 489a66c81bd1deebd347a3fce46c31d7
SHA1: fc27e597ef7a216a9c7eb63779d18ed1a1f8b5fc
SHA256: 177fb57447305271f05151adc9fabf9dd69d3e052c98f9fcaac79ced241bb5ad
False
c:\users\dssdpmx042\appdata\roaming\microsoft\windows\cookies\index.dat 32.00 KB (32768 bytes) MD5: 9da9b46d28aaa6d10d5ba425639fc03a
SHA1: 2602ba59732e5f2cca492e65771897d415805d78
SHA256: b0871c556380772c12490db86b7a1c20917ee3b4e6115e080eec8355d7b3d9f5
False
c:\users\dssdpmx042\appdata\local\microsoft\windows\history\history.ie5\index.dat 48.00 KB (49152 bytes) MD5: c4afe452c2cd7b22ab13582f920725c5
SHA1: adabacab480544deed5ca4966cbb1624ec5840d2
SHA256: 39ebb553a8f620ee98ad0560a6ee2cd5c01049d92d65c1f34947c531a9f54be6
False
Host Behavior
File (13)
+
Operation Filename Additional Information Success Count Logfile
CREATE c:\users\public\n3eg\n3eg1.51n3e desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\wvs desired_access = GENERIC_WRITE, GENERIC_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\idw desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\idx desired_access = GENERIC_WRITE, GENERIC_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\n3e.vbs desired_access = GENERIC_WRITE, GENERIC_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\id desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
READ c:\users\public\n3eg\n3eg1.51n3e size = 2689537 True 1
Fn
READ c:\users\public\n3eg\idw size = 2 True 1
Fn
Data
READ c:\users\public\n3eg\id size = 7 True 1
Fn
Data
WRITE c:\users\public\n3eg\wvs size = 4 True 1
Fn
Data
WRITE c:\users\public\n3eg\idx size = 10 True 1
Fn
Data
WRITE c:\users\public\n3eg\n3e.vbs size = 4199 True 1
Fn
Data
DELETE c:\users\public\n3eg\n3e.vbs False 1
Fn
Process (1)
+
Operation Process Name Additional Information Success Count Logfile
CREATE cmd /k "C:\Users\Public\N3Eg\N3E.vbs" show_window = SW_HIDE True 1
Fn
Module (779)
+
Operation Module Additional Information Success Count Logfile
LOAD C:\Users\Public\N3Eg\N3Eg4.ENU base_address = 0x0 False 1
Fn
LOAD C:\Users\Public\N3Eg\N3Eg4.EN base_address = 0x0 False 1
Fn
LOAD oleaut32.dll base_address = 0x76ee0000 True 3
Fn
LOAD advapi32.dll base_address = 0x76650000 True 2
Fn
LOAD user32.dll base_address = 0x76ca0000 True 4
Fn
LOAD kernel32.dll base_address = 0x75900000 True 8
Fn
LOAD gdi32.dll base_address = 0x76dd0000 True 1
Fn
LOAD version.dll base_address = 0x748a0000 True 1
Fn
LOAD ole32.dll base_address = 0x76a90000 True 1
Fn
LOAD comctl32.dll base_address = 0x74110000 True 1
Fn
LOAD msvcrt.dll base_address = 0x76f70000 True 1
Fn
LOAD shell32.dll base_address = 0x759e0000 True 1
Fn
LOAD wininet.dll base_address = 0x75650000 True 1
Fn
LOAD oleacc.dll base_address = 0x72190000 True 1
Fn
LOAD OLEACC.DLL base_address = 0x72190000 True 1
Fn
LOAD imm32.dll base_address = 0x76630000 True 2
Fn
LOAD olepro32.dll base_address = 0x6e100000 True 1
Fn
LOAD security.dll base_address = 0x6f9b0000 True 1
Fn
LOAD wtsapi32.dll base_address = 0x73c50000 True 1
Fn
LOAD uxtheme.dll base_address = 0x74090000 True 2
Fn
LOAD WS2_32.DLL base_address = 0x773f0000 True 1
Fn
LOAD Fwpuclnt.dll base_address = 0x721e0000 True 1
Fn
LOAD IdnDL.dll base_address = 0x6e0f0000 True 1
Fn
LOAD Normaliz.dll base_address = 0x75820000 True 1
Fn
GET_HANDLE c:\windows\system32\kernel32.dll base_address = 0x75900000 True 9
Fn
GET_HANDLE c:\windows\system32\oleaut32.dll base_address = 0x76ee0000 True 2
Fn
GET_HANDLE c:\windows\system32\ole32.dll base_address = 0x76a90000 True 1
Fn
GET_HANDLE c:\windows\system32\user32.dll base_address = 0x76ca0000 True 3
Fn
GET_HANDLE c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll base_address = 0x74110000 True 1
Fn
GET_FILENAME C:\Users\Public\N3Eg\N3Eg4.51N3E True 1
Fn
GET_FILENAME C:\Windows\Explorer.EXE True 3
Fn
GET_FILENAME False 1
Fn
GET_FILENAME C:\Windows\Explorer.EXE True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetDiskFreeSpaceExA, address = 0x7598f46f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VariantChangeTypeEx, address = 0x76ee4c28 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarNeg, address = 0x76f5c802 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarNot, address = 0x76f5ec66 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarAdd, address = 0x76f05934 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarSub, address = 0x76f5d332 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarMul, address = 0x76f5dbd4 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarDiv, address = 0x76f5e405 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarIdiv, address = 0x76f5f00a True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarMod, address = 0x76f5f15e True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarAnd, address = 0x76f05a98 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarOr, address = 0x76f5ecfa True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarXor, address = 0x76f5ee2e True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarCmp, address = 0x76efb0dc True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarI4FromStr, address = 0x76ef6fab True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarR4FromStr, address = 0x76f001a0 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarR8FromStr, address = 0x76ef699e True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarDateFromStr, address = 0x76f06ba7 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarCyFromStr, address = 0x76f26c12 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarBoolFromStr, address = 0x76efdbd1 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarBstrFromCy, address = 0x76f07fdc True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarBstrFromDate, address = 0x76ef7a2a True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarBstrFromBool, address = 0x76f00355 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = SysFreeString, address = 0x76ee3e59 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = SysReAllocStringLen, address = 0x76ee7810 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = SysAllocStringLen, address = 0x76ee45d2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = RegQueryValueExW, address = 0x766646ad True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = RegOpenKeyExW, address = 0x7666468d True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = RegCloseKey, address = 0x7666469d True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MessageBoxA, address = 0x76cfea11 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CharNextW, address = 0x76cb0be6 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = LoadStringW, address = 0x76cadfba True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Sleep, address = 0x7594ba46 True 3
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = VirtualFree, address = 0x75951da4 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = VirtualAlloc, address = 0x75952fb6 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = lstrlenW, address = 0x7594d9e8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = VirtualQuery, address = 0x759576d6 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = QueryPerformanceCounter, address = 0x7594bb9f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetTickCount, address = 0x7594ba60 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetSystemInfo, address = 0x75953728 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetVersion, address = 0x7594154e True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CompareStringW, address = 0x75949bee True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = IsValidLocale, address = 0x75943de4 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetThreadLocale, address = 0x759688e6 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetSystemDefaultUILanguage, address = 0x7593731d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetUserDefaultUILanguage, address = 0x759422ef True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetLocaleInfoW, address = 0x75956596 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WideCharToMultiByte, address = 0x7595450e True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = MultiByteToWideChar, address = 0x7595452b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetACP, address = 0x759539aa True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LoadLibraryExW, address = 0x75944775 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetStartupInfoW, address = 0x75953891 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetProcAddress, address = 0x759533d3 True 3
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetModuleHandleW, address = 0x7595374d True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetModuleFileNameW, address = 0x75953c26 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetCommandLineW, address = 0x7595679e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FreeLibrary, address = 0x7594d9d0 True 3
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetLastError, address = 0x7594bf00 True 3
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = UnhandledExceptionFilter, address = 0x7595ed38 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = RtlUnwind, address = 0x75937f70 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = RaiseException, address = 0x7593eb60 True 3
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = ExitProcess, address = 0x7595214f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = ExitThread, address = 0x7722f611 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SwitchToThread, address = 0x7593eb24 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetCurrentThreadId, address = 0x7594bb80 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CreateThread, address = 0x7595375d True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = DeleteCriticalSection, address = 0x77259ac5 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LeaveCriticalSection, address = 0x77247760 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = EnterCriticalSection, address = 0x772477a0 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = InitializeCriticalSection, address = 0x7725a149 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FindFirstFileW, address = 0x759553b2 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FindClose, address = 0x75950e62 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WriteFile, address = 0x75951400 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetStdHandle, address = 0x75951e46 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CloseHandle, address = 0x7594ca7c True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LoadLibraryA, address = 0x7595395c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = TlsSetValue, address = 0x7594da88 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = TlsGetValue, address = 0x7594da70 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = TlsFree, address = 0x759513b8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = TlsAlloc, address = 0x759535a1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LocalFree, address = 0x7594ca64 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LocalAlloc, address = 0x75953363 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetClassLongW, address = 0x76ca658b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetClassLongW, address = 0x76cb3860 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetWindowLongW, address = 0x76cb4449 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetWindowLongW, address = 0x76cb61b8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CreateWindowExW, address = 0x76caec7c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = keybd_event, address = 0x76cfec3b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = WindowFromPoint, address = 0x76cd6be9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = WaitMessage, address = 0x76cb66bd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = WaitForInputIdle, address = 0x76cd0397 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = UpdateWindow, address = 0x76caffa8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = UnregisterClassW, address = 0x76cab9ae True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = UnhookWindowsHookEx, address = 0x76caadf9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = TranslateMessage, address = 0x76cb64c7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = TranslateMDISysAccel, address = 0x76cd1a5a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = TrackPopupMenu, address = 0x76cc2228 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SystemParametersInfoW, address = 0x76cae09a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SwitchDesktop, address = 0x76ca476b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ShowWindow, address = 0x76caf2a9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ShowScrollBar, address = 0x76cd3c89 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ShowOwnedPopups, address = 0x76cd28ca True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ShowCaret, address = 0x76ca9334 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetWindowRgn, address = 0x76ca99ec True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetWindowsHookExW, address = 0x76cae30c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetWindowTextW, address = 0x76cb612b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetWindowPos, address = 0x76cb1bc4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetWindowPlacement, address = 0x76ca7f78 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetTimer, address = 0x76cb52ef True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetScrollRange, address = 0x76ca8ec5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetScrollPos, address = 0x76cd04be True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetScrollInfo, address = 0x76cb48da True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetRect, address = 0x76cb498b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetPropW, address = 0x76cb5dc5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetParent, address = 0x76ca8314 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetMenuItemInfoW, address = 0x76cb1799 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetMenu, address = 0x76cd6b0e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetKeyboardState, address = 0x76cd695a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetForegroundWindow, address = 0x76cab225 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetFocus, address = 0x76caabad True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetCursorPos, address = 0x76cec1b0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetCursor, address = 0x76cb3075 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetCapture, address = 0x76cd6932 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetActiveWindow, address = 0x76cb333a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SendMessageTimeoutW, address = 0x76cae459 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SendMessageA, address = 0x76caad60 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SendMessageW, address = 0x76cb5539 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ScrollWindow, address = 0x76ccfc1d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ScreenToClient, address = 0x76caa506 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = RemovePropW, address = 0x76cb5fe1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = RemoveMenu, address = 0x76ca86e8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ReleaseDC, address = 0x76cb5421 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ReleaseCapture, address = 0x76cd69f2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = RegisterWindowMessageW, address = 0x76cadf8d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = RegisterClipboardFormatW, address = 0x76cadf8d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = RegisterClassW, address = 0x76caed4a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = RedrawWindow, address = 0x76cb29bc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = PostQuitMessage, address = 0x76cab308 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = PostMessageW, address = 0x76cb447b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = PeekMessageA, address = 0x76cb19a5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = PeekMessageW, address = 0x76cb634a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = OpenDesktopW, address = 0x76cac669 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MsgWaitForMultipleObjectsEx, address = 0x76cae369 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MsgWaitForMultipleObjects, address = 0x76cb37d8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MoveWindow, address = 0x76ca8d29 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MessageBoxW, address = 0x76cfea5f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MessageBeep, address = 0x76cd2939 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MapWindowPoints, address = 0x76cb5caa True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MapVirtualKeyW, address = 0x76cd6a7c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = LoadKeyboardLayoutW, address = 0x76cec874 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = LoadIconW, address = 0x76caf142 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = LoadCursorW, address = 0x76caed90 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = LoadBitmapW, address = 0x76ca6460 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = KillTimer, address = 0x76cb64f7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsZoomed, address = 0x76cb4ce9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsWindowVisible, address = 0x76cb4d69 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsWindowUnicode, address = 0x76cb2f55 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsWindowEnabled, address = 0x76caa9b9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsWindow, address = 0x76cb53ba True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsIconic, address = 0x76cb4c8e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsDialogMessageA, address = 0x76cc2019 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsDialogMessageW, address = 0x76cb4104 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsChild, address = 0x76cb3a83 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = InvalidateRect, address = 0x76cb566d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = InsertMenuItemW, address = 0x76caaac5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = InsertMenuW, address = 0x76ca869a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = HideCaret, address = 0x76ca9348 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetWindowThreadProcessId, address = 0x76caee32 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetWindowTextW, address = 0x76cab8c5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetWindowRect, address = 0x76cb558c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetWindowPlacement, address = 0x76cd69de True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetWindowDC, address = 0x76cb4ab7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetTopWindow, address = 0x76cd24d9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetSystemMetrics, address = 0x76cb67cf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetSystemMenu, address = 0x76cafd8b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetSysColorBrush, address = 0x76caf1ed True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetSysColor, address = 0x76cbdb7a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetSubMenu, address = 0x76ca9c19 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetScrollRange, address = 0x76cd045a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetScrollPos, address = 0x76cd0e43 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetScrollInfo, address = 0x76cb2da3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetPropW, address = 0x76cb5bbe True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetParent, address = 0x76cb6029 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetWindow, address = 0x76cb2780 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMessageTime, address = 0x76cd4231 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMessagePos, address = 0x76cd6703 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMessageExtraInfo, address = 0x76cab705 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMenuStringW, address = 0x76cd6528 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMenuState, address = 0x76cd67d2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMenuItemInfoW, address = 0x76caaefa True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMenuItemID, address = 0x76ca9cd4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMenuItemCount, address = 0x76caae39 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMenu, address = 0x76cd6b68 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetLastActivePopup, address = 0x76cd6894 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetKeyboardState, address = 0x76cd6946 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetKeyboardLayoutNameW, address = 0x76cefa13 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetKeyboardLayoutList, address = 0x76ca935c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetKeyboardLayout, address = 0x76cb3800 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetKeyState, address = 0x76cb2b4d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetKeyNameTextW, address = 0x76cefa03 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetIconInfo, address = 0x76cb2989 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetGUIThreadInfo, address = 0x76cb237e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetForegroundWindow, address = 0x76cb335d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetFocus, address = 0x76cb3a34 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetDlgCtrlID, address = 0x76cab4e8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetDesktopWindow, address = 0x76cb01a9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetDCEx, address = 0x76cb2d57 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetDC, address = 0x76cb544c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetCursorPos, address = 0x76caa4b3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetCursor, address = 0x76cd6408 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetClipboardData, address = 0x76cc2ba7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetClientRect, address = 0x76cb54dd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetClassNameW, address = 0x76cb2a29 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetClassInfoExW, address = 0x76cb095e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetClassInfoW, address = 0x76cb0ac2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetCapture, address = 0x76ca9dc7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetActiveWindow, address = 0x76cd3b33 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = FrameRect, address = 0x76cd0eb0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = FindWindowExW, address = 0x76cd712b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = FindWindowW, address = 0x76caae0d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = FillRect, address = 0x76cb5d56 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EnumWindows, address = 0x76cb375b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EnumThreadWindows, address = 0x76cab712 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EnumChildWindows, address = 0x76cb2948 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EndPaint, address = 0x76cb5d42 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EndMenu, address = 0x76ca8302 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EnableWindow, address = 0x76ca8d02 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EnableScrollBar, address = 0x76cd19ce True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EnableMenuItem, address = 0x76cd43bc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DrawTextExW, address = 0x76cb5894 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DrawTextW, address = 0x76cb5b6a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DrawMenuBar, address = 0x76cd15ae True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DrawIconEx, address = 0x76cb2c32 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DrawIcon, address = 0x76ca6427 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DrawFrameControl, address = 0x76ccb4f9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DrawFocusRect, address = 0x76cd3091 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DrawEdge, address = 0x76cb311a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DispatchMessageA, address = 0x76cb2e32 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DispatchMessageW, address = 0x76cbcc61 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DestroyWindow, address = 0x76cab2f4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DestroyMenu, address = 0x76ca87f7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DestroyIcon, address = 0x76caa77f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DestroyCursor, address = 0x76caa77f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DeleteMenu, address = 0x76ca83c2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DefWindowProcW, address = 0x76cb507d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DefMDIChildProcW, address = 0x76cd150a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DefFrameProcW, address = 0x76cd152b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CreatePopupMenu, address = 0x76ca867c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CreateMenu, address = 0x76cd6aed True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CreateIcon, address = 0x76cc7510 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CreateDesktopW, address = 0x76ca40cf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CopyImage, address = 0x76ca87a6 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CloseDesktop, address = 0x76cac4ce True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ClientToScreen, address = 0x76cb1316 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CheckMenuItem, address = 0x76ccee7c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CharUpperBuffW, address = 0x76cbebd5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CharUpperW, address = 0x76cbe981 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CharLowerBuffW, address = 0x76cb3afe True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CharLowerW, address = 0x76caba8a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CallWindowProcW, address = 0x76cb1b3c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CallNextHookEx, address = 0x76caabe1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = BeginPaint, address = 0x76cb5d14 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = AdjustWindowRectEx, address = 0x76cb48ba True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ActivateKeyboardLayout, address = 0x76ca8203 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = UnrealizeObject, address = 0x76ddfb63 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = StretchBlt, address = 0x76ddf467 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetWindowOrgEx, address = 0x76dd8546 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetWinMetaFileBits, address = 0x76e0d957 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetViewportOrgEx, address = 0x76dd834f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetTextColor, address = 0x76dd6906 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetStretchBltMode, address = 0x76dd7705 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetROP2, address = 0x76ddf9e0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetPixel, address = 0x76df14f3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetMapMode, address = 0x76ddefbf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetEnhMetaFileBits, address = 0x76deb380 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetDIBits, address = 0x76dda995 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetDIBColorTable, address = 0x76df1492 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetBrushOrgEx, address = 0x76ddc4c5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetBkMode, address = 0x76dd69b1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetBkColor, address = 0x76dd6a3c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SelectPalette, address = 0x76dda1f6 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SelectObject, address = 0x76dd6640 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SaveDC, address = 0x76dda74b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = RoundRect, address = 0x76df016d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = RestoreDC, address = 0x76dda67b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = Rectangle, address = 0x76ddf1ff True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = RectVisible, address = 0x76dd8f13 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = RealizePalette, address = 0x76ddef91 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = Polyline, address = 0x76de05cf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = Polygon, address = 0x76ddfb87 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = PolyBezierTo, address = 0x76e06c25 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = PolyBezier, address = 0x76e06b03 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = PlayEnhMetaFile, address = 0x76de990d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = Pie, address = 0x76e0569f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = PatBlt, address = 0x76dd62af True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = MoveToEx, address = 0x76dd8c21 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = MaskBlt, address = 0x76ddc7ad True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = LineTo, address = 0x76ddf59b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = LPtoDP, address = 0x76dd8484 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = IntersectClipRect, address = 0x76dd7dfe True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetWindowOrgEx, address = 0x76ddd1bf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetWinMetaFileBits, address = 0x76e0d7cb True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetTextMetricsW, address = 0x76dd7b8f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetTextExtentPointW, address = 0x76ddb358 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetTextExtentPoint32W, address = 0x76ddb4b5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetSystemPaletteEntries, address = 0x76ddc2e1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetStockObject, address = 0x76dd5ddf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetRgnBox, address = 0x76dd621f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetPixel, address = 0x76ddc3d5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetPaletteEntries, address = 0x76ddc2aa True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetObjectW, address = 0x76dd7568 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetEnhMetaFilePaletteEntries, address = 0x76e0d1ac True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetEnhMetaFileHeader, address = 0x76decd3a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetEnhMetaFileDescriptionW, address = 0x76e0dc6b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetEnhMetaFileBits, address = 0x76decdc8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetDeviceCaps, address = 0x76dd6f7f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetDIBits, address = 0x76dda23b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetDIBColorTable, address = 0x76dda149 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetCurrentPositionEx, address = 0x76dd8d78 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetClipBox, address = 0x76dd8525 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetBrushOrgEx, address = 0x76ddc943 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetBitmapBits, address = 0x76ddc1ba True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GdiFlush, address = 0x76dd5fe4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = FrameRgn, address = 0x76e05ae2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = ExtTextOutW, address = 0x76dd8192 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = ExtFloodFill, address = 0x76defd94 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = ExcludeClipRect, address = 0x76dd9218 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = EnumFontFamiliesExW, address = 0x76ddce94 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = Ellipse, address = 0x76e055e3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = DeleteObject, address = 0x76dd5f14 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = DeleteEnhMetaFile, address = 0x76debda2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = DeleteDC, address = 0x76dd6eaa True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateSolidBrush, address = 0x76dd6b49 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateRectRgn, address = 0x76dd633b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreatePenIndirect, address = 0x76de744d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreatePalette, address = 0x76ddb1b0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateHalftonePalette, address = 0x76ddc2cd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateFontIndirectW, address = 0x76ddabfc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateEnhMetaFileW, address = 0x76decc1f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateDIBitmap, address = 0x76dda379 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateDIBSection, address = 0x76dd8850 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateCompatibleDC, address = 0x76dd6888 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateCompatibleBitmap, address = 0x76dd73ad True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateBrushIndirect, address = 0x76dd993c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateBitmap, address = 0x76dd6b79 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CopyEnhMetaFileW, address = 0x76e0d651 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CombineRgn, address = 0x76dd651e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CloseEnhMetaFile, address = 0x76dec3fe True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = Chord, address = 0x76e054fa True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = BitBlt, address = 0x76dd72c0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = ArcTo, address = 0x76e05436 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = Arc, address = 0x76e0534e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = AngleArc, address = 0x76e05299 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\version.dll function = VerQueryValueW, address = 0x748a1b51 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\version.dll function = GetFileVersionInfoSizeW, address = 0x748a19d9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\version.dll function = GetFileVersionInfoW, address = 0x748a19f4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WinExec, address = 0x7598e5fd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WaitForSingleObject, address = 0x7594ba90 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WaitForMultipleObjectsEx, address = 0x7594bc00 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = VirtualQueryEx, address = 0x75934e42 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = VirtualProtect, address = 0x75942341 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SuspendThread, address = 0x75960ca9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SizeofResource, address = 0x75943e7f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetThreadPriority, address = 0x75944815 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetLastError, address = 0x7594bb08 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetFilePointer, address = 0x7594db36 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetEvent, address = 0x7594bccc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetErrorMode, address = 0x75954a51 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetEndOfFile, address = 0x75942319 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = ResumeThread, address = 0x75940f1c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = ResetEvent, address = 0x7594bcb4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = RemoveDirectoryW, address = 0x7593586a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = ReadFile, address = 0x759496fb True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = IsDebuggerPresent, address = 0x75943ea8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = OpenProcess, address = 0x759459d7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = MulDiv, address = 0x7594b7a0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LockResource, address = 0x7593fd29 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LoadResource, address = 0x7594984d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LoadLibraryW, address = 0x75953c01 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = HeapFree, address = 0x7594bbd0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = HeapDestroy, address = 0x75942301 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = HeapCreate, address = 0x75953ea2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = HeapAlloc, address = 0x77252dd6 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GlobalUnlock, address = 0x75949d50 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GlobalSize, address = 0x7593eb78 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GlobalLock, address = 0x75949e05 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GlobalFree, address = 0x75949cf9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GlobalFindAtomW, address = 0x7594912d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GlobalDeleteAtom, address = 0x7593f16c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GlobalAlloc, address = 0x75949ce1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GlobalAddAtomW, address = 0x759470f9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetVolumeInformationW, address = 0x75957598 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetVersionExW, address = 0x75943b1a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetUserDefaultLCID, address = 0x75956584 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetTimeZoneInformation, address = 0x75938a3b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetThreadPriority, address = 0x75949147 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetThreadLocale, address = 0x7594153c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetTempPathW, address = 0x75938b33 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetLocalTime, address = 0x7594a90e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetFullPathNameW, address = 0x75954543 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetFileSize, address = 0x75940273 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetFileAttributesW, address = 0x759564ff True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetExitCodeThread, address = 0x75936ddd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetEnvironmentVariableW, address = 0x759565c4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetDiskFreeSpaceW, address = 0x75933530 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetDateFormatW, address = 0x7594afab True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetCurrentThread, address = 0x75953351 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetCurrentProcessId, address = 0x7594cac4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetCurrentProcess, address = 0x7594cdcf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetComputerNameW, address = 0x759403ff True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetCPInfoExW, address = 0x75938b1b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetCPInfo, address = 0x75951e2e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FreeResource, address = 0x7593f1bd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = InterlockedExchange, address = 0x7594bf0a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = InterlockedCompareExchange, address = 0x7594bb92 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FormatMessageW, address = 0x759454a3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FindResourceW, address = 0x75943e61 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FindNextFileW, address = 0x7594963a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FileTimeToLocalFileTime, address = 0x75952004 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FileTimeToDosDateTime, address = 0x75942ce1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = EnumSystemLocalesW, address = 0x7598f3df True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = EnumCalendarInfoW, address = 0x7598f38f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = DeleteFileW, address = 0x75940f62 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CreateProcessW, address = 0x7590204d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CreateFileW, address = 0x7594cc56 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CreateEventW, address = 0x75953386 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CreateDirectoryW, address = 0x75943925 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = RegSetValueExW, address = 0x766614d6 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = RegQueryInfoKeyW, address = 0x766646e7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = RegFlushKey, address = 0x7667773f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = RegEnumKeyExW, address = 0x766646c8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = RegCreateKeyExW, address = 0x766640fe True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = GetUserNameW, address = 0x7666157a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = SafeArrayPtrOfIndex, address = 0x76efe1ce True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = SafeArrayGetUBound, address = 0x76efe127 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = SafeArrayGetLBound, address = 0x76efe173 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = SafeArrayCreate, address = 0x76efe263 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VariantChangeType, address = 0x76ee5dee True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VariantCopyInd, address = 0x76efe86c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VariantCopy, address = 0x76ee48f1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VariantClear, address = 0x76ee3eae True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VariantInit, address = 0x76ee3ed5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = GetErrorInfo, address = 0x76ee3f21 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = GetActiveObject, address = 0x76f28f58 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CreateStreamOnHGlobal, address = 0x76ab363b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = IsAccelerator, address = 0x76b5043e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = OleDraw, address = 0x76b10286 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = OleSetMenuDescriptor, address = 0x76aedc53 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = OleUninitialize, address = 0x76aaeba1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = OleInitialize, address = 0x76aaefd7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoTaskMemFree, address = 0x76ae6f41 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoTaskMemAlloc, address = 0x76adea4c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = ProgIDFromCLSID, address = 0x76b1ef82 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = StringFromCLSID, address = 0x76aaeb17 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoCreateInstance, address = 0x76ad9d0b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoGetClassObject, address = 0x76ac54ad True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoUninitialize, address = 0x76ad86d3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoInitialize, address = 0x76aab636 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = IsEqualGUID, address = 0x76b5041c True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = InitializeFlatSB, address = 0x741ef803 True 2
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_SetScrollProp, address = 0x741907d0 True 2
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_SetScrollPos, address = 0x74190894 True 2
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_SetScrollInfo, address = 0x741908c7 True 2
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_GetScrollPos, address = 0x741ef80e True 2
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_GetScrollInfo, address = 0x741908b6 True 2
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = _TrackMouseEvent, address = 0x741922d1 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_SetIconSize, address = 0x741fb44e True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_GetIconSize, address = 0x741250df True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_Write, address = 0x74158b97 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_Read, address = 0x74113eae True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_GetDragImage, address = 0x741fafbb True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_DragShowNolock, address = 0x741fb161 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_DragMove, address = 0x741fb0f0 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_DragLeave, address = 0x741fb12a True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_DragEnter, address = 0x741fb0b3 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_EndDrag, address = 0x741fa177 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_BeginDrag, address = 0x741fb021 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_GetIcon, address = 0x7413af2e True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_Remove, address = 0x7413e333 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_DrawEx, address = 0x741210fd True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_Draw, address = 0x741ac687 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_GetBkColor, address = 0x7412e8d2 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_SetBkColor, address = 0x74190183 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_Add, address = 0x74168fa1 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_SetImageCount, address = 0x74165249 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_GetImageCount, address = 0x7411a8b9 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_Destroy, address = 0x74126471 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_Create, address = 0x74123c75 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EnumDisplayMonitors, address = 0x76cb34a3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMonitorInfoW, address = 0x76cb33e7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MonitorFromPoint, address = 0x76ca94c9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MonitorFromWindow, address = 0x76cb3622 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\msvcrt.dll function = memset, address = 0x76f79790 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\msvcrt.dll function = memcpy, address = 0x76f79910 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\shell32.dll function = ShellExecuteW, address = 0x759f3c71 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\shell32.dll function = Shell_NotifyIconW, address = 0x75a001c1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\wininet.dll function = FindNextUrlCacheEntryW, address = 0x7568989c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\wininet.dll function = FindFirstUrlCacheEntryW, address = 0x7568978a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\wininet.dll function = FindCloseUrlCache, address = 0x75698409 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\wininet.dll function = DeleteUrlCacheEntryW, address = 0x756a9573 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetRawInputData, address = 0x76d04c21 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = RegisterRawInputDevices, address = 0x76ca5b52 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleacc.dll function = AccessibleObjectFromWindow, address = 0x72192480 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleacc.dll function = AccessibleChildren, address = 0x72195d25 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetThreadPreferredUILanguages, address = 0x759422d7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetThreadPreferredUILanguages, address = 0x7593e627 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetThreadUILanguage, address = 0x7593ae42 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetNativeSystemInfo, address = 0x7593be77 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetDiskFreeSpaceExW, address = 0x7593de40 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = InitializeConditionVariable, address = 0x77259981 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WakeConditionVariable, address = 0x772a5a7b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WakeAllConditionVariable, address = 0x772245a5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SleepConditionVariableCS, address = 0x759318be True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetLogicalProcessorInformation, address = 0x75932004 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoCreateInstanceEx, address = 0x76ad9d4e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoInitializeEx, address = 0x76ad09ad True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoAddRefServerProcess, address = 0x76af3cf3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoReleaseServerProcess, address = 0x76af4314 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoResumeClassObjects, address = 0x76a9ea02 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoSuspendClassObjects, address = 0x76afbb02 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\imm32.dll function = ImmIsIME, address = 0x76632ceb True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = AnimateWindow, address = 0x76cd0620 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = UninitializeFlatSB, address = 0x7411d1ea True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_GetScrollProp, address = 0x741ef81f True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_EnableScrollBar, address = 0x741ef84b True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_ShowScrollBar, address = 0x741ef83a True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_GetScrollRange, address = 0x741ef829 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_SetScrollRange, address = 0x741908a5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetLayeredWindowAttributes, address = 0x76caa6dc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsHungAppWindow, address = 0x76cd7195 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = HungWindowFromGhostWindow, address = 0x76cc61f5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GhostWindowFromHungWindow, address = 0x76caa561 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\olepro32.dll function = OleCreatePropertyFrame, address = 0x6e1020ea True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\olepro32.dll function = OleCreateFontIndirect, address = 0x6e1020b7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\olepro32.dll function = OleCreatePictureIndirect, address = 0x6e1020c8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\olepro32.dll function = OleLoadPicture, address = 0x6e1020d9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetFileSizeEx, address = 0x759459ef True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\security.dll function = InitSecurityInterfaceW, address = 0x75285b53 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\wtsapi32.dll function = WTSRegisterSessionNotification, address = 0x73c51cbc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = BufferedPaintInit, address = 0x7409940e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = OpenThemeData, address = 0x740973d2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = CloseThemeData, address = 0x74096a18 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = DrawThemeBackground, address = 0x74093982 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = DrawThemeText, address = 0x74094ea1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeBackgroundContentRect, address = 0x7409cd2e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeBackgroundExtent, address = 0x7409f8bf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemePartSize, address = 0x7409cdb1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeTextExtent, address = 0x74092d57 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeTextMetrics, address = 0x7409f992 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeBackgroundRegion, address = 0x740a165d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = HitTestThemeBackground, address = 0x740a3ce3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = DrawThemeEdge, address = 0x740b3b52 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = DrawThemeIcon, address = 0x740c35e7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = IsThemePartDefined, address = 0x740985b4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = IsThemeBackgroundPartiallyTransparent, address = 0x740960ab True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeColor, address = 0x7409616c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeMetric, address = 0x740a06e2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeString, address = 0x740c22e4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeBool, address = 0x74097c1f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeInt, address = 0x7409616c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeEnumValue, address = 0x7409616c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemePosition, address = 0x740c2350 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeFont, address = 0x7409ff21 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeRect, address = 0x740a3611 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeMargins, address = 0x740986e9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeIntList, address = 0x740c23b1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemePropertyOrigin, address = 0x740b3fbb True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = SetWindowTheme, address = 0x740a0134 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeFilename, address = 0x740c2412 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeSysColor, address = 0x740b3274 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeSysColorBrush, address = 0x740c301e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeSysBool, address = 0x740c3172 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeSysSize, address = 0x740c320b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeSysFont, address = 0x740c29c4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeSysString, address = 0x740c2b3f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeSysInt, address = 0x740c2bd3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = IsThemeActive, address = 0x7409f785 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = IsAppThemed, address = 0x7409f869 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetWindowTheme, address = 0x7409df46 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = EnableThemeDialogTexture, address = 0x7409fcaf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = IsThemeDialogTextureEnabled, address = 0x740c312b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeAppProperties, address = 0x740a0fb1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = SetThemeAppProperties, address = 0x740c3296 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetCurrentThemeName, address = 0x740a05dd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeDocumentationProperty, address = 0x740c2932 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = DrawThemeParentBackground, address = 0x740953e5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = EnableTheming, address = 0x740c2feb True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = DrawThemeTextEx, address = 0x740963e6 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = WSAStartup, address = 0x773f3ab2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = GetAddrInfoW, address = 0x773f4889 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = GetNameInfoW, address = 0x773f66af True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = FreeAddrInfoW, address = 0x773f4b1b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = InetPtonW, address = 0x774039dc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = InetNtopW, address = 0x77403abf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = GetAddrInfoExW, address = 0x773fd1ea True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = SetAddrInfoExW, address = 0x773ff4f6 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = FreeAddrInfoExW, address = 0x773fe14d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\fwpuclnt.dll function = WSASetSocketPeerTargetName, address = 0x721fbb1e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\fwpuclnt.dll function = WSADeleteSocketPeerTargetName, address = 0x721fbb4e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\fwpuclnt.dll function = WSAImpersonateSocketPeer, address = 0x721fbb7e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\fwpuclnt.dll function = WSAQuerySocketSecurity, address = 0x721fbaed True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\fwpuclnt.dll function = WSARevertImpersonation, address = 0x721fbcfd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\idndl.dll function = DownlevelGetLocaleScripts, address = 0x6e0f2a5b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\idndl.dll function = DownlevelGetStringScripts, address = 0x6e0f2b2f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\idndl.dll function = DownlevelVerifyScripts, address = 0x6e0f2dad True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\normaliz.dll function = IdnToUnicode, address = 0x7599f707 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\normaliz.dll function = IdnToNameprepUnicode, address = 0x7599f6b4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\normaliz.dll function = IdnToAscii, address = 0x75938bb8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\normaliz.dll function = IsNormalizedString, address = 0x7599f662 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\normaliz.dll function = NormalizeString, address = 0x7599f5ea True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = socket, address = 0x773f3eb8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = getsockopt, address = 0x773f737d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = setsockopt, address = 0x773f41b6 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = htons, address = 0x773f2d8b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = bind, address = 0x773f4582 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = getsockname, address = 0x773f30af True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = ntohs, address = 0x773f2d8b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = connect, address = 0x773f6bdd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = WSAGetLastError, address = 0x773f37ad True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = shutdown, address = 0x773f449d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = closesocket, address = 0x773f3918 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CreateToolhelp32Snapshot, address = 0x7593f731 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Heap32ListFirst, address = 0x759902e7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Heap32ListNext, address = 0x75990391 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Heap32First, address = 0x75990429 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Heap32Next, address = 0x75990614 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Toolhelp32ReadProcessMemory, address = 0x75990819 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Process32First, address = 0x7596443d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Process32Next, address = 0x75964505 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Process32FirstW, address = 0x7593fa35 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Process32NextW, address = 0x7593faca True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Thread32First, address = 0x75967e4c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Thread32Next, address = 0x75967edc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Module32First, address = 0x75990859 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Module32Next, address = 0x75990942 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Module32FirstW, address = 0x7593c59e True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Module32NextW, address = 0x7593c11f True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = VerLanguageNameW, address = 0x75938ca1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetSystemDefaultLangID, address = 0x7593db6e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = getpeername, address = 0x773f7147 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = send, address = 0x773f6f01 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = select, address = 0x773f6989 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = recv, address = 0x773f6b0e True 1
Fn
Registry (16)
+
Operation Key Additional Information Success Count Logfile
OPEN_KEY HKEY_CURRENT_USER\Software\Borland\Locales False 2
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Borland\Locales False 1
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Borland\Delphi\Locales False 2
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Embarcadero\Locales False 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Embarcadero\Locales False 1
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\CodeGear\Locales False 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\CodeGear\Locales False 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes True 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04090409 False 1
Fn
OPEN_KEY HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run True 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes value_name = MS Shell Dlg 2, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes value_name = MS Shell Dlg 2, data_ident_out = Tahoma True 1
Fn
WRITE_VALUE HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run value_name = xacwe, data = regsvr32.exe /s "C:\Users\Public\N3Eg\N3Eg2.51N3E" #96 True 1
Fn
User (2)
+
Operation User/Group/Server Additional Information Success Count Logfile
GET_CURRENT DSsDPMx042 True 2
Fn
Window (44)
+
Operation Window Name Additional Information Success Count Logfile
CREATE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 18
Fn
CREATE Explorer class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0, window_parameter = 0 True 1
Fn
CREATE Explorer window_name = FrmMwM41n, class_name = TFrmMwM41n, x_coordinate = 18446744073709551164, y_coordinate = 18446744073709551164, width = 320, height = 240, class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0, window_parameter = 0 True 1
Fn
FIND k8w0 False 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE Explorer class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE Explorer class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE FrmMwM41n class_name = TFrmMwM41n, x_coordinate = 18446744073709551164, y_coordinate = 18446744073709551164, width = 320, height = 240 True 1
Fn
SET_ATTRIBUTE FrmMwM41n class_name = TFrmMwM41n, x_coordinate = 18446744073709551164, y_coordinate = 18446744073709551164, width = 320, height = 240 True 1
Fn
SET_ATTRIBUTE Explorer class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0 True 1
Fn
Keyboard (3)
+
Operation Virtual Key Code Additional Information Success Count Logfile
GET_INFO 0 result_out = 4 True 1
Fn
GET_INFO KB_LOCALE_ID os_tid = 0, result_out = 67699721 True 1
Fn
GET_INFO KB_LOCALE_ID True 1
Fn
System (32)
+
Operation Information Success Count Logfile
GET_CURSOR x_out = 991, y_out = 872 True 12
Fn
GET_CURSOR x_out = 1126, y_out = 518 True 10
Fn
SLEEP duration = 1500 milliseconds (1.500 seconds) True 1
Fn
SLEEP duration = 1000 milliseconds (1.000 seconds) True 2
Fn
SLEEP duration = 60000 milliseconds (60.000 seconds) True 2
Fn
SLEEP duration = 600000 milliseconds (600.000 seconds) True 2
Fn
SLEEP duration = 20000 milliseconds (20.000 seconds) True 1
Fn
SLEEP duration = 70000 milliseconds (70.000 seconds) True 1
Fn
GET_INFO type = Hardware Information True 1
Fn
Network Behavior
HTTP Session (1)
+
Remote Address Remote Port Username Password Success Count
127.0.0.1 80 True 1
HTTP Request (1)
+
Method URL Success Count
GET http://127.0.0.1/nosoanfhtympkl50tre/infx/s1/conta.php?chave=s3n4&url=N3EERVTWSM%20*%20%2032%20bits%20*%202626.5%20kb%20*%20%20*%20English%20(United%20States) True 1
DNS (10)
+
Operation Host Additional Information Success Count Logfile
RESOLVE_NAME carvas32ltda.com True 3
Fn
RESOLVE_NAME carva32ssa.com True 2
Fn
RESOLVE_NAME bandeivacomercial.com True 2
Fn
RESOLVE_NAME bandeivacomercio.com True 2
Fn
RESOLVE_NAME adom2.com.br True 1
Fn
TCP Outgoing Connection (10)
+
Remote Address Remote Port L7Protocol Success Count
187.191.100.112 80 False 10
Process #5: cmd.exe
(Host: 39, Network: 0)
+
Information Value
ID / OS PID #5 / 0xef8
OS Parent PID 0x4f0 (c:\windows\explorer.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\cmd.exe
Command Line cmd /k "C:\Users\Public\N3Eg\N3E.vbs"
Monitor Start Time: 00:03:41, Reason: Child Process
Unmonitor End Time: 00:03:50, Reason: Terminated
Monitor Duration 00:00:09
OS Thread IDs
# 80
0x EFC
# 82
0x F18
# 83
0x F1C
# 84
0x F20
# 85
0x F24
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
private_0x00000000000c0000 0x000c0000 0x001bffff Private Memory Readable, Writable True False False
pagefile_0x00000000001c0000 0x001c0000 0x001c6fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000001d0000 0x001d0000 0x001d1fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000001e0000 0x001e0000 0x001e0fff Private Memory Readable, Writable True False False
private_0x00000000001f0000 0x001f0000 0x001f0fff Private Memory Readable, Writable True False False
pagefile_0x0000000000200000 0x00200000 0x00201fff Pagefile Backed Memory Readable True False False
private_0x0000000000210000 0x00210000 0x0021ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000220000 0x00220000 0x002e7fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000002f0000 0x002f0000 0x002f0fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000300000 0x00300000 0x00301fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000310000 0x00310000 0x00310fff Pagefile Backed Memory Readable True False False
private_0x0000000000320000 0x00320000 0x0041ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000420000 0x00420000 0x00520fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000530000 0x00530000 0x0112ffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001130000 0x01130000 0x013bafff Pagefile Backed Memory Readable True False False
SortDefault.nls 0x013c0000 0x0168efff Memory Mapped File Readable False False False
pagefile_0x0000000001690000 0x01690000 0x01690fff Pagefile Backed Memory Readable True False False
cversions.2.db 0x016a0000 0x016a3fff Memory Mapped File Readable True False False
{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000000c.db 0x016b0000 0x016ccfff Memory Mapped File Readable True False False
pagefile_0x00000000016d0000 0x016d0000 0x016d0fff Pagefile Backed Memory Readable, Writable True False False
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000007.db 0x016e0000 0x0170ffff Memory Mapped File Readable True False False
cversions.2.db 0x01710000 0x01713fff Memory Mapped File Readable True False False
pagefile_0x0000000001720000 0x01720000 0x01720fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000001740000 0x01740000 0x0183ffff Private Memory Readable, Writable True False False
pagefile_0x0000000001840000 0x01840000 0x0191efff Pagefile Backed Memory Readable True False False
private_0x0000000001950000 0x01950000 0x0198ffff Private Memory Readable, Writable True False False
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db 0x01990000 0x019f5fff Memory Mapped File Readable True False False
pagefile_0x0000000001a00000 0x01a00000 0x01df2fff Pagefile Backed Memory Readable True False False
private_0x0000000001e00000 0x01e00000 0x01efffff Private Memory Readable, Writable True False False
private_0x0000000001f90000 0x01f90000 0x0208ffff Private Memory Readable, Writable True False False
private_0x0000000002160000 0x02160000 0x0225ffff Private Memory Readable, Writable True False False
cmd.exe 0x4a810000 0x4a85bfff Memory Mapped File Readable, Writable, Executable True False False
winbrand.dll 0x6dd80000 0x6dd86fff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x739c0000 0x739e0fff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x74090000 0x740cffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x74110000 0x742adfff Memory Mapped File Readable, Writable, Executable False False False
propsys.dll 0x745a0000 0x74694fff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75280000 0x7529afff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x752a0000 0x752abfff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x75350000 0x7535afff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x753c0000 0x753cbfff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x753d0000 0x754ecfff Memory Mapped File Readable, Writable, Executable False False False
devobj.dll 0x754f0000 0x75501fff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
cfgmgr32.dll 0x75590000 0x755b6fff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75650000 0x75744fff Memory Mapped File Readable, Writable, Executable False False False
Wldap32.dll 0x757d0000 0x75814fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x759e0000 0x76629fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
setupapi.dll 0x766f0000 0x7688cfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x76890000 0x76a8afff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x76a90000 0x76bebfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76d70000 0x76dc6fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x76e20000 0x76ea2fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x76ee0000 0x76f6efff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x770c0000 0x771f5fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffd3000 0x7ffd3000 0x7ffd3fff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory Readable, Writable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Host Behavior
File (9)
+
Operation Filename Additional Information Success Count Logfile
OPEN STD_OUTPUT_HANDLE True 7
Fn
OPEN STD_INPUT_HANDLE True 2
Fn
Process (3)
+
Operation Process Name Additional Information Success Count Logfile
CREATE C:\Users\Public\N3Eg\N3E.vbs os_tid = 0x0, os_pid = 0x0, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, current_directory = C:\Windows\system32, show_window = SW_SHOWNORMAL False 1
Fn
CREATE C:\Users\Public\N3Eg\N3E.vbs current_directory = C:\Windows\system32, show_window = SW_SHOWNORMAL True 1
Fn
SET_CURDIR c:\windows\system32\cmd.exe os_pid = 0xef8, new_path_name = c:\windows\system32 True 1
Fn
Module (10)
+
Operation Module Additional Information Success Count Logfile
LOAD SHELL32.dll base_address = 0x759e0000 True 1
Fn
GET_HANDLE c:\windows\system32\cmd.exe base_address = 0x4a810000 True 1
Fn
GET_HANDLE c:\windows\system32\kernel32.dll base_address = 0x75900000 True 2
Fn
GET_FILENAME C:\Windows\system32\cmd.exe True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetThreadUILanguage, address = 0x759524c2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CopyFileExW, address = 0x7593ac6c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = IsDebuggerPresent, address = 0x75943ea8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetConsoleInputExeNameW, address = 0x75952732 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\shell32.dll function = ShellExecuteExW, address = 0x75a01e46 True 1
Fn
Registry (17)
+
Operation Key Additional Information Success Count Logfile
OPEN_KEY HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 0 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 9 False 1
Fn
Process #6: wscript.exe
(Host: 92, Network: 0)
+
Information Value
ID / OS PID #6 / 0xf28
OS Parent PID 0xef8 (c:\windows\system32\cmd.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\wscript.exe
Command Line "C:\Windows\System32\WScript.exe" "C:\Users\Public\N3Eg\N3E.vbs"
Monitor Start Time: 00:03:42, Reason: Child Process
Unmonitor End Time: 00:03:50, Reason: Terminated
Monitor Duration 00:00:08
OS Thread IDs
# 86
0x F2C
# 87
0x F30
# 88
0x F34
# 89
0x F38
# 90
0x F3C
# 91
0x F40
# 92
0x F44
# 93
0x F48
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00041fff Pagefile Backed Memory Readable, Writable True False False
wscript.exe.mui 0x00050000 0x00052fff Memory Mapped File Readable, Writable False False False
private_0x0000000000060000 0x00060000 0x00060fff Private Memory Readable, Writable True False False
private_0x0000000000070000 0x00070000 0x00070fff Private Memory Readable, Writable True False False
wscript.exe 0x00080000 0x000a5fff Memory Mapped File Readable, Writable, Executable True False False
private_0x00000000000b0000 0x000b0000 0x001affff Private Memory Readable, Writable True False False
private_0x00000000001b0000 0x001b0000 0x002affff Private Memory Readable, Writable True False False
locale.nls 0x002b0000 0x00316fff Memory Mapped File Readable False False False
wscript.exe 0x00320000 0x0032efff Memory Mapped File Readable True False False
pagefile_0x0000000000330000 0x00330000 0x00330fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000340000 0x00340000 0x00340fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000350000 0x00350000 0x00351fff Pagefile Backed Memory Readable True False False
private_0x0000000000350000 0x00350000 0x0035ffff Private Memory Readable, Writable True False False
private_0x0000000000360000 0x00360000 0x0036ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000370000 0x00370000 0x00437fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000440000 0x00440000 0x00540fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000550000 0x00550000 0x0114ffff Pagefile Backed Memory Readable True False False
scrrun.dll 0x01150000 0x01164fff Memory Mapped File Readable True False False
shell32.dll 0x01170000 0x01182fff Memory Mapped File Readable False False False
pagefile_0x0000000001190000 0x01190000 0x01190fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x00000000011a0000 0x011a0000 0x011a1fff Pagefile Backed Memory Readable True False False
oleaccrc.dll 0x011b0000 0x011b0fff Memory Mapped File Readable False False False
pagefile_0x00000000011c0000 0x011c0000 0x011c1fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000011d0000 0x011d0000 0x011d1fff Pagefile Backed Memory Readable True False False
cversions.2.db 0x011e0000 0x011e3fff Memory Mapped File Readable True False False
pagefile_0x00000000011f0000 0x011f0000 0x011f0fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000001200000 0x01200000 0x0123ffff Private Memory Readable, Writable True False False
pagefile_0x0000000001240000 0x01240000 0x0131efff Pagefile Backed Memory Readable True False False
{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000000c.db 0x01320000 0x0133cfff Memory Mapped File Readable True False False
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000007.db 0x01340000 0x0136ffff Memory Mapped File Readable True False False
cversions.2.db 0x01370000 0x01373fff Memory Mapped File Readable True False False
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db 0x01380000 0x013e5fff Memory Mapped File Readable True False False
pagefile_0x00000000013f0000 0x013f0000 0x013f0fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000001400000 0x01400000 0x014fffff Private Memory Readable, Writable True False False
private_0x0000000001500000 0x01500000 0x015fffff Private Memory Readable, Writable True False False
SortDefault.nls 0x01600000 0x018cefff Memory Mapped File Readable False False False
private_0x0000000001920000 0x01920000 0x01a1ffff Private Memory Readable, Writable True False False
private_0x0000000001a60000 0x01a60000 0x01b5ffff Private Memory Readable, Writable True False False
pagefile_0x0000000001b60000 0x01b60000 0x01f5ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000002050000 0x02050000 0x0205ffff Private Memory Readable, Writable True False False
private_0x0000000002060000 0x02060000 0x0215ffff Private Memory Readable, Writable True False False
private_0x0000000002200000 0x02200000 0x022fffff Private Memory Readable, Writable True False False
private_0x00000000023b0000 0x023b0000 0x024affff Private Memory Readable, Writable True False False
pagefile_0x00000000024b0000 0x024b0000 0x028a2fff Pagefile Backed Memory Readable True False False
private_0x00000000028b0000 0x028b0000 0x029affff Private Memory Readable, Writable True False False
comctl32.dll 0x6c1c0000 0x6c243fff Memory Mapped File Readable, Writable, Executable False False False
vbscript.dll 0x6c4c0000 0x6c52afff Memory Mapped File Readable, Writable, Executable True False False
scrrun.dll 0x6dab0000 0x6dad9fff Memory Mapped File Readable, Writable, Executable True False False
scrobj.dll 0x6dae0000 0x6db0cfff Memory Mapped File Readable, Writable, Executable True False False
wshext.dll 0x6db10000 0x6db25fff Memory Mapped File Readable, Writable, Executable True False False
msisip.dll 0x6dd30000 0x6dd37fff Memory Mapped File Readable, Writable, Executable False False False
ieframe.dll 0x6e6a0000 0x6f11ffff Memory Mapped File Readable, Writable, Executable False False False
apphelp.dll 0x71af0000 0x71b3bfff Memory Mapped File Readable, Writable, Executable False False False
mpr.dll 0x72080000 0x72091fff Memory Mapped File Readable, Writable, Executable False False False
oleacc.dll 0x72190000 0x721cbfff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x739c0000 0x739e0fff Memory Mapped File Readable, Writable, Executable False False False
dwmapi.dll 0x73da0000 0x73db2fff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x74090000 0x740cffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x74110000 0x742adfff Memory Mapped File Readable, Writable, Executable False False False
propsys.dll 0x745a0000 0x74694fff Memory Mapped File Readable, Writable, Executable False False False
version.dll 0x748a0000 0x748a8fff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x74bc0000 0x74bfafff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x74e20000 0x74e35fff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75280000 0x7529afff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x752a0000 0x752abfff Memory Mapped File Readable, Writable, Executable False False False
sxs.dll 0x752b0000 0x7530efff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x75350000 0x7535afff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x753c0000 0x753cbfff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x753d0000 0x754ecfff Memory Mapped File Readable, Writable, Executable False False False
devobj.dll 0x754f0000 0x75501fff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
wintrust.dll 0x75560000 0x7558cfff Memory Mapped File Readable, Writable, Executable False False False
cfgmgr32.dll 0x75590000 0x755b6fff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75650000 0x75744fff Memory Mapped File Readable, Writable, Executable False False False
Wldap32.dll 0x757d0000 0x75814fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x759e0000 0x76629fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
setupapi.dll 0x766f0000 0x7688cfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x76890000 0x76a8afff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x76a90000 0x76bebfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76d70000 0x76dc6fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x76e20000 0x76ea2fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x76ee0000 0x76f6efff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x770c0000 0x771f5fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x77360000 0x77364fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory Readable, Writable True False False
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory Readable, Writable True False False
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory Readable, Writable True False False
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory Readable, Writable True False False
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory Readable, Writable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Host Behavior
File (2)
+
Operation Filename Additional Information Success Count Logfile
CREATE c:\users\public\n3eg\n3e.vbs desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTING, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN True 1
Fn
READ c:\users\public\n3eg\n3e.vbs module_name = Nameless FileMapping, size = 4199 True 1
Fn
Data
Module (17)
+
Operation Module Additional Information Success Count Logfile
LOAD kernel32.dll base_address = 0x75900000 True 1
Fn
LOAD ole32.dll base_address = 0x76a90000 True 1
Fn
LOAD C:\Windows\system32\advapi32.dll base_address = 0x76650000 True 1
Fn
GET_HANDLE c:\windows\system32\wscript.exe base_address = 0x80000 True 2
Fn
GET_HANDLE c:\windows\system32\ole32.dll base_address = 0x76a90000 True 1
Fn
CREATE_MAPPING c:\users\public\n3eg\n3e.vbs module_name = Nameless FileMapping, maximum_size = 4199, protection = PAGE_READONLY True 1
Fn
MAP c:\users\public\n3eg\n3e.vbs process_name = c:\windows\system32\wscript.exe, os_pid = 0xf28, module_name = Nameless FileMapping, desired_access = FILE_MAP_READ, file_offset = 0, address = 0x350000 True 1
Fn
UNMAP c:\windows\system32\wscript.exe os_pid = 0xf28, base_address = 0x350000 True 1
Fn
GET_FILENAME c:\windows\system32\wscript.exe file_name = C:\Windows\System32\WScript.exe True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = HeapSetInformation, address = 0x75954157 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoCreateInstance, address = 0x76ad9d0b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = SaferIdentifyLevel, address = 0x76672102 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = SaferComputeTokenFromLevel, address = 0x76673352 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = SaferCloseLevel, address = 0x76673825 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CLSIDFromProgIDEx, address = 0x76aa0782 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoGetClassObject, address = 0x76ac54ad True 1
Fn
Com (38)
+
Operation Class Interface Additional Information Success Count Logfile
CREATE VBScriptEngine5 IUnknown cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
CREATE VBScriptEngine5 IClassFactory True 1
Fn
CREATE {6C736DB1-BD94-11D0-8A23-00AA00B58E10} ISystemDebugEventFire cls_context = CLSCTX_INPROC_SERVER True 1
Fn
CREATE {06290BD1-48AA-11D2-8432-006008C3FBFC} {E4D1C9B0-46E8-11D4-A2A6-00104BD35090} cls_context = CLSCTX_INPROC_SERVER True 1
Fn
CREATE {06290BD1-48AA-11D2-8432-006008C3FBFC} IClassFactory True 1
Fn
CREATE FileSystemObject IClassFactory cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
CREATE Shell IClassFactory cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
QUERY VBScriptEngine5 IClassFactory new_interface = IUnknown, True 1
Fn
QUERY VBScriptEngine5 IUnknown new_interface = IUnknown True 1
Fn
QUERY IClassFactory new_interface = {E4D1C9B0-46E8-11D4-A2A6-00104BD35090}, True 1
Fn
QUERY new_interface = {E4D1C9B0-46E8-11D4-A2A6-00104BD35090} True 1
Fn
QUERY Shell IClassFactory new_interface = {342D1EA0-AE25-11D1-89C5-006008C3FBFC}, False 1
Fn
QUERY Shell IClassFactory new_interface = IUnknown, True 1
Fn
QUERY Shell IUnknown new_interface = IObjectWithSite True 1
Fn
QUERY Shell IUnknown new_interface = IDispatch True 1
Fn
QUERY Shell IUnknown new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 2
Fn
METHOD IMessageFilter method = AddRef False 2
Fn
METHOD ITypeLib method = GetTypeInfoType True 5
Fn
METHOD VBScriptEngine5 IClassFactory new_interface = IUnknown, method = CreateInstance True 1
Fn
METHOD VBScriptEngine5 IUnknown method = AddRef False 1
Fn
METHOD ISystemDebugEventFire method = BeginSession True 1
Fn
METHOD IClassFactory method = CreateInstance True 1
Fn
METHOD method = AddRef False 1
Fn
METHOD ISystemDebugEventFire method = IsActive False 1
Fn
METHOD Shell IClassFactory new_interface = IUnknown, method = CreateInstance True 1
Fn
METHOD Shell IObjectWithSite method = SetSite True 1
Fn
METHOD FileSystemObject IClassFactory method = AddRef False 1
Fn
METHOD Shell IUnknown method = AddRef False 3
Fn
METHOD Shell IUnknown method = GetIDsOfNames True 1
Fn
METHOD Shell IUnknown method = Invoke True 1
Fn
Registry (27)
+
Operation Key Additional Information Success Count Logfile
CREATE_KEY HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
CREATE_KEY HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 3
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 3
Fn
OPEN_KEY HKEY_CLASSES_ROOT\.vbs True 1
Fn
OPEN_KEY HKEY_CLASSES_ROOT\VBSFile\ScriptEngine True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = IgnoreUserSettings, data_ident_out = 0 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = Enabled, data_ident_out = 0 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = Enabled, data_ident_out = 0 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = IgnoreUserSettings, data_ident_out = 255 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = LogSecuritySuccesses, data_ident_out = 255 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = LogSecuritySuccesses, data_ident_out = 255 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = IgnoreUserSettings, data_ident_out = 18 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = TrustPolicy, data_ident_out = 171 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = UseWINSAFER, data_ident_out = 18 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = TrustPolicy, data_ident_out = 171 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = UseWINSAFER, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = Timeout, data_ident_out = 20 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = DisplayLogo, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = Timeout, data_ident_out = 20 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = DisplayLogo, data_ident_out = 49 False 1
Fn
READ_VALUE HKEY_CLASSES_ROOT\.vbs data_ident_out = VBSFile True 1
Fn
READ_VALUE HKEY_CLASSES_ROOT\VBSFile\ScriptEngine data_ident_out = VBScript True 1
Fn
Window (2)
+
Operation Window Name Additional Information Success Count Logfile
CREATE class_name = WSH-Timer, x_coordinate = 0, y_coordinate = 0, width = 1, height = 1, window_parameter = 3548128 True 1
Fn
SET_ATTRIBUTE class_name = WSH-Timer, x_coordinate = 0, y_coordinate = 0, width = 1, height = 1 False 1
Fn
System (6)
+
Operation Information Success Count Logfile
SLEEP duration = -1 (infinite) True 1
Fn
SLEEP duration = 1000 milliseconds (1.000 seconds) True 3
Fn
SLEEP duration = 1000 milliseconds (1.000 seconds) False 1
Fn
GET_INFO type = Hardware Information True 1
Fn
Process #7: wscript.exe
(Host: 804, Network: 0)
+
Information Value
ID / OS PID #7 / 0x494
OS Parent PID 0xf28 (c:\windows\system32\wscript.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\wscript.exe
Command Line "C:\Windows\System32\wscript.exe" "C:\Users\Public\N3Eg\N3E.vbs" uac
Monitor Start Time: 00:03:46, Reason: Child Process
Unmonitor End Time: 00:03:49, Reason: Terminated
Monitor Duration 00:00:03
OS Thread IDs
# 96
0x 8C0
# 97
0x 8C4
# 98
0x 490
# 99
0x 478
# 100
0x 488
# 103
0x 268
# 104
0x 948
# 105
0x 968
# 107
0x 990
# 113
0x 9C8
# 115
0x 690
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00041fff Pagefile Backed Memory Readable, Writable True False False
wscript.exe.mui 0x00050000 0x00052fff Memory Mapped File Readable, Writable False False False
private_0x0000000000060000 0x00060000 0x00060fff Private Memory Readable, Writable True False False
private_0x0000000000070000 0x00070000 0x00070fff Private Memory Readable, Writable True False False
wscript.exe 0x00080000 0x000a5fff Memory Mapped File Readable, Writable, Executable True False False
locale.nls 0x000b0000 0x00116fff Memory Mapped File Readable False False False
wscript.exe 0x00120000 0x0012efff Memory Mapped File Readable True False False
pagefile_0x0000000000130000 0x00130000 0x00130fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000140000 0x00140000 0x00140fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000150000 0x00150000 0x00151fff Pagefile Backed Memory Readable True False False
private_0x0000000000150000 0x00150000 0x0015ffff Private Memory Readable, Writable True False False
private_0x0000000000160000 0x00160000 0x0025ffff Private Memory Readable, Writable True False False
scrrun.dll 0x00260000 0x00274fff Memory Mapped File Readable True False False
wshom.ocx 0x00280000 0x0028bfff Memory Mapped File Readable True False False
private_0x0000000000290000 0x00290000 0x0029ffff Private Memory Readable, Writable True False False
private_0x00000000002a0000 0x002a0000 0x002affff Private Memory Readable, Writable True False False
pagefile_0x00000000002b0000 0x002b0000 0x00377fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000380000 0x00380000 0x00380fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000390000 0x00390000 0x0048ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000490000 0x00490000 0x00590fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000005a0000 0x005a0000 0x0119ffff Pagefile Backed Memory Readable True False False
pagefile_0x00000000011a0000 0x011a0000 0x011a1fff Pagefile Backed Memory Readable True False False
oleaccrc.dll 0x011b0000 0x011b0fff Memory Mapped File Readable False False False
private_0x00000000011c0000 0x011c0000 0x011fffff Private Memory Readable, Writable True False False
pagefile_0x0000000001200000 0x01200000 0x012defff Pagefile Backed Memory Readable True False False
pagefile_0x00000000012e0000 0x012e0000 0x012e1fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000012f0000 0x012f0000 0x012f1fff Pagefile Backed Memory Readable True False False
cversions.2.db 0x01300000 0x01303fff Memory Mapped File Readable True False False
private_0x0000000001310000 0x01310000 0x0140ffff Private Memory Readable, Writable True False False
SortDefault.nls 0x01410000 0x016defff Memory Mapped File Readable False False False
{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000000c.db 0x016e0000 0x016fcfff Memory Mapped File Readable True False False
pagefile_0x0000000001700000 0x01700000 0x01700fff Pagefile Backed Memory Readable, Writable True False False
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000007.db 0x01710000 0x0173ffff Memory Mapped File Readable True False False
cversions.2.db 0x01740000 0x01743fff Memory Mapped File Readable True False False
pagefile_0x0000000001750000 0x01750000 0x01750fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000001760000 0x01760000 0x01760fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000001770000 0x01770000 0x0186ffff Private Memory Readable, Writable True False False
private_0x0000000001870000 0x01870000 0x0196ffff Private Memory Readable, Writable True False False
FirewallAPI.dll 0x01970000 0x0197afff Memory Mapped File Readable False False False
stdole2.tlb 0x01980000 0x01983fff Memory Mapped File Readable False False False
private_0x0000000001990000 0x01990000 0x01a8ffff Private Memory Readable, Writable True False False
pagefile_0x0000000001a90000 0x01a90000 0x01e8ffff Pagefile Backed Memory Readable, Writable True False False
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db 0x01e90000 0x01ef5fff Memory Mapped File Readable True False False
private_0x0000000001f80000 0x01f80000 0x0207ffff Private Memory Readable, Writable True False False
private_0x0000000002080000 0x02080000 0x0217ffff Private Memory Readable, Writable True False False
private_0x0000000002160000 0x02160000 0x0225ffff Private Memory Readable, Writable True False False
private_0x0000000002280000 0x02280000 0x0237ffff Private Memory Readable, Writable True False False
private_0x00000000023f0000 0x023f0000 0x024effff Private Memory Readable, Writable True False False
pagefile_0x00000000024f0000 0x024f0000 0x028e2fff Pagefile Backed Memory Readable True False False
comctl32.dll 0x6c1c0000 0x6c243fff Memory Mapped File Readable, Writable, Executable False False False
wshom.ocx 0x6c420000 0x6c440fff Memory Mapped File Readable, Writable, Executable True False False
vbscript.dll 0x6c4c0000 0x6c52afff Memory Mapped File Readable, Writable, Executable True False False
scrrun.dll 0x6dab0000 0x6dad9fff Memory Mapped File Readable, Writable, Executable True False False
scrobj.dll 0x6dae0000 0x6db0cfff Memory Mapped File Readable, Writable, Executable True False False
wshext.dll 0x6db10000 0x6db25fff Memory Mapped File Readable, Writable, Executable True False False
msisip.dll 0x6dd30000 0x6dd37fff Memory Mapped File Readable, Writable, Executable False False False
ieframe.dll 0x6e6a0000 0x6f11ffff Memory Mapped File Readable, Writable, Executable False False False
apphelp.dll 0x71af0000 0x71b3bfff Memory Mapped File Readable, Writable, Executable False False False
mpr.dll 0x72080000 0x72091fff Memory Mapped File Readable, Writable, Executable False False False
oleacc.dll 0x72190000 0x721cbfff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x739c0000 0x739e0fff Memory Mapped File Readable, Writable, Executable False False False
dwmapi.dll 0x73da0000 0x73db2fff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x74090000 0x740cffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x74110000 0x742adfff Memory Mapped File Readable, Writable, Executable False False False
propsys.dll 0x745a0000 0x74694fff Memory Mapped File Readable, Writable, Executable False False False
version.dll 0x748a0000 0x748a8fff Memory Mapped File Readable, Writable, Executable False False False
FirewallAPI.dll 0x748b0000 0x74925fff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x74bc0000 0x74bfafff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x74e20000 0x74e35fff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75280000 0x7529afff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x752a0000 0x752abfff Memory Mapped File Readable, Writable, Executable False False False
sxs.dll 0x752b0000 0x7530efff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x75350000 0x7535afff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x753c0000 0x753cbfff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x753d0000 0x754ecfff Memory Mapped File Readable, Writable, Executable False False False
devobj.dll 0x754f0000 0x75501fff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
wintrust.dll 0x75560000 0x7558cfff Memory Mapped File Readable, Writable, Executable False False False
cfgmgr32.dll 0x75590000 0x755b6fff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75650000 0x75744fff Memory Mapped File Readable, Writable, Executable False False False
Wldap32.dll 0x757d0000 0x75814fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x759e0000 0x76629fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
setupapi.dll 0x766f0000 0x7688cfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x76890000 0x76a8afff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x76a90000 0x76bebfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76d70000 0x76dc6fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x76e20000 0x76ea2fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x76ee0000 0x76f6efff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x770c0000 0x771f5fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x77360000 0x77364fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory Readable, Writable True False False
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory Readable, Writable True False False
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory Readable, Writable True False False
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory Readable, Writable True False False
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory Readable, Writable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Host Behavior
File (2)
+
Operation Filename Additional Information Success Count Logfile
CREATE c:\users\public\n3eg\n3e.vbs desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTING, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN True 1
Fn
READ c:\users\public\n3eg\n3e.vbs module_name = Nameless FileMapping, size = 4199 True 1
Fn
Data
Process (4)
+
Operation Process Name Additional Information Success Count Logfile
CREATE sc operation = Open, show_window = SW_HIDE True 1
Fn
CREATE net operation = Open, show_window = SW_HIDE True 1
Fn
CREATE cmd operation = Open, show_window = SW_HIDE True 2
Fn
Module (22)
+
Operation Module Additional Information Success Count Logfile
LOAD kernel32.dll base_address = 0x75900000 True 1
Fn
LOAD ole32.dll base_address = 0x76a90000 True 1
Fn
LOAD C:\Windows\system32\advapi32.dll base_address = 0x76650000 True 1
Fn
LOAD shell32.dll base_address = 0x759e0000 True 1
Fn
GET_HANDLE c:\windows\system32\wscript.exe base_address = 0x80000 True 3
Fn
GET_HANDLE c:\windows\system32\ole32.dll base_address = 0x76a90000 True 1
Fn
CREATE_MAPPING c:\users\public\n3eg\n3e.vbs module_name = Nameless FileMapping, maximum_size = 4199, protection = PAGE_READONLY True 1
Fn
MAP c:\users\public\n3eg\n3e.vbs process_name = c:\windows\system32\wscript.exe, os_pid = 0x494, module_name = Nameless FileMapping, desired_access = FILE_MAP_READ, file_offset = 0, address = 0x150000 True 1
Fn
UNMAP c:\windows\system32\wscript.exe os_pid = 0x494, base_address = 0x150000 True 1
Fn
GET_FILENAME c:\windows\system32\wscript.exe file_name = C:\Windows\System32\wscript.exe True 1
Fn
GET_FILENAME C:\Windows\System32\wscript.exe True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = HeapSetInformation, address = 0x75954157 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoCreateInstance, address = 0x76ad9d0b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = SaferIdentifyLevel, address = 0x76672102 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = SaferComputeTokenFromLevel, address = 0x76673352 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = SaferCloseLevel, address = 0x76673825 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CLSIDFromProgIDEx, address = 0x76aa0782 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoGetClassObject, address = 0x76ac54ad True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\wscript.exe function = 1, address = 0x82bb9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\shell32.dll function = ShellExecuteExW, address = 0x75a01e46 True 1
Fn
Com (730)
+
Operation Class Interface Additional Information Success Count Logfile
CREATE VBScriptEngine5 IUnknown cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
CREATE VBScriptEngine5 IClassFactory True 1
Fn
CREATE {6C736DB1-BD94-11D0-8A23-00AA00B58E10} ISystemDebugEventFire cls_context = CLSCTX_INPROC_SERVER True 1
Fn
CREATE {06290BD1-48AA-11D2-8432-006008C3FBFC} {E4D1C9B0-46E8-11D4-A2A6-00104BD35090} cls_context = CLSCTX_INPROC_SERVER True 1
Fn
CREATE {06290BD1-48AA-11D2-8432-006008C3FBFC} IClassFactory True 1
Fn
CREATE FileSystemObject IClassFactory cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
CREATE WshShell IUnknown cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
CREATE WshShell IClassFactory True 1
Fn
CREATE NetFwPolicy2 IClassFactory cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
CREATE NetFwRule IClassFactory cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
QUERY VBScriptEngine5 IClassFactory new_interface = IUnknown, True 1
Fn
QUERY VBScriptEngine5 IUnknown new_interface = IUnknown True 1
Fn
QUERY IClassFactory new_interface = {E4D1C9B0-46E8-11D4-A2A6-00104BD35090}, True 1
Fn
QUERY new_interface = {E4D1C9B0-46E8-11D4-A2A6-00104BD35090} True 1
Fn
QUERY FileSystemObject IClassFactory new_interface = IUnknown, True 1
Fn
QUERY FileSystemObject IUnknown new_interface = IUnknown True 1
Fn
QUERY NetFwPolicy2 IClassFactory new_interface = {342D1EA0-AE25-11D1-89C5-006008C3FBFC}, False 1
Fn
QUERY NetFwPolicy2 IClassFactory new_interface = IUnknown, True 1
Fn
QUERY NetFwPolicy2 IUnknown new_interface = {FC4801A3-2BA9-11CF-A229-00AA003D7352} False 1
Fn
QUERY NetFwPolicy2 IUnknown new_interface = IDispatch True 1
Fn
QUERY NetFwPolicy2 IUnknown new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 2
Fn
QUERY NetFwPolicy2 IDispatch new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 4
Fn
QUERY NetFwPolicy2 IUnknown new_interface = {00020400-0000-0000-C000-000000000046} False 1
Fn
QUERY NetFwPolicy2 IUnknown new_interface = IEnumVARIANT True 1
Fn
QUERY NetFwPolicy2 IUnknown new_interface = {342D1EA0-AE25-11D1-89C5-006008C3FBFC}, False 1
Fn
QUERY NetFwPolicy2 IUnknown new_interface = IUnknown, True 1
Fn
QUERY NetFwPolicy2 IUnknown new_interface = {FC4801A3-2BA9-11CF-A229-00AA003D7352} False 1
Fn
QUERY NetFwPolicy2 IUnknown new_interface = IDispatch True 1
Fn
QUERY NetFwPolicy2 IUnknown new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 22
Fn
METHOD IMessageFilter method = AddRef False 306
Fn
METHOD ITypeLib method = GetTypeInfoType True 6
Fn
METHOD VBScriptEngine5 IClassFactory new_interface = IUnknown, method = CreateInstance True 1
Fn
METHOD VBScriptEngine5 IUnknown method = AddRef False 1
Fn
METHOD ISystemDebugEventFire method = BeginSession True 1
Fn
METHOD IClassFactory method = CreateInstance True 1
Fn
METHOD method = AddRef False 1
Fn
METHOD ISystemDebugEventFire method = IsActive False 2
Fn
METHOD FileSystemObject IClassFactory new_interface = IUnknown, method = CreateInstance True 1
Fn
METHOD FileSystemObject IUnknown method = AddRef False 1
Fn
METHOD NetFwPolicy2 IClassFactory new_interface = IUnknown, method = CreateInstance True 1
Fn
METHOD NetFwPolicy2 IUnknown method = AddRef False 3
Fn
METHOD NetFwPolicy2 IUnknown method = GetIDsOfNames True 1
Fn
METHOD NetFwPolicy2 IUnknown new_interface = IDispatch, method = Invoke True 1
Fn
METHOD NetFwPolicy2 IDispatch method = AddRef False 4
Fn
METHOD NetFwPolicy2 IDispatch new_interface = IUnknown, method = Invoke True 1
Fn
METHOD NetFwPolicy2 IUnknown method = Next True 304
Fn
METHOD NetFwPolicy2 IUnknown method = Next False 1
Fn
METHOD NetFwPolicy2 IUnknown new_interface = IUnknown, method = CreateInstance True 1
Fn
METHOD NetFwPolicy2 IUnknown method = AddRef False 13
Fn
METHOD NetFwPolicy2 IUnknown method = GetIDsOfNames True 11
Fn
METHOD NetFwPolicy2 IUnknown method = Invoke True 11
Fn
METHOD NetFwPolicy2 IDispatch method = GetIDsOfNames True 1
Fn
METHOD NetFwPolicy2 IDispatch new_interface = IDispatch, method = Invoke True 1
Fn
METHOD ISystemDebugEventFire method = EndSession True 1
Fn
Registry (41)
+
Operation Key Additional Information Success Count Logfile
CREATE_KEY HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
CREATE_KEY HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
CREATE_KEY HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System True 3
Fn
CREATE_KEY HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download True 2
Fn
CREATE_KEY HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center True 2
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 3
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 3
Fn
OPEN_KEY HKEY_CLASSES_ROOT\.vbs True 1
Fn
OPEN_KEY HKEY_CLASSES_ROOT\VBSFile\ScriptEngine True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = IgnoreUserSettings, data_ident_out = 0 False 2
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = Enabled, data_ident_out = 0 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = Enabled, data_ident_out = 0 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = LogSecuritySuccesses, data_ident_out = 0 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = LogSecuritySuccesses, data_ident_out = 0 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = IgnoreUserSettings, data_ident_out = 237 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = TrustPolicy, data_ident_out = 143 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = UseWINSAFER, data_ident_out = 237 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = TrustPolicy, data_ident_out = 143 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = UseWINSAFER, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = Timeout, data_ident_out = 176 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings value_name = DisplayLogo, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = Timeout, data_ident_out = 176 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings value_name = DisplayLogo, data_ident_out = 49 False 1
Fn
READ_VALUE HKEY_CLASSES_ROOT\.vbs data_ident_out = VBSFile True 1
Fn
READ_VALUE HKEY_CLASSES_ROOT\VBSFile\ScriptEngine data_ident_out = VBScript True 1
Fn
WRITE_VALUE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System value_name = EnableLUA, data = 0 True 1
Fn
WRITE_VALUE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System value_name = ConsentPromptBehaviorAdmin, data = 0 True 1
Fn
WRITE_VALUE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System value_name = PromptOnSecureDesktop, data = 0 True 1
Fn
WRITE_VALUE HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download value_name = CheckExeSignatures, data = no True 1
Fn
WRITE_VALUE HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download value_name = RunInvalidSignatures, data = 00000001 True 1
Fn
WRITE_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center value_name = AntiVirusDisableNotify, data = 1 True 1
Fn
WRITE_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center value_name = UpdatesDisableNotify, data = 1 True 1
Fn
Window (2)
+
Operation Window Name Additional Information Success Count Logfile
CREATE class_name = WSH-Timer, x_coordinate = 0, y_coordinate = 0, width = 1, height = 1, window_parameter = 2761696 True 1
Fn
SET_ATTRIBUTE class_name = WSH-Timer, x_coordinate = 0, y_coordinate = 0, width = 1, height = 1 False 1
Fn
System (3)
+
Operation Information Success Count Logfile
SLEEP duration = -1 (infinite) True 2
Fn
GET_INFO type = Hardware Information True 1
Fn
Process #8: sc.exe
(Host: 8, Network: 0)
+
Information Value
ID / OS PID #8 / 0x960
OS Parent PID 0x494 (c:\windows\system32\wscript.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\sc.exe
Command Line "C:\Windows\System32\sc.exe" config WinDefend start= disabled
Monitor Start Time: 00:03:47, Reason: Child Process
Unmonitor End Time: 00:03:48, Reason: Terminated
Monitor Duration 00:00:01
OS Thread IDs
# 106
0x 994
# 109
0x 6AC
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory Readable True False False
private_0x0000000000080000 0x00080000 0x000bffff Private Memory Readable, Writable True False False
locale.nls 0x000c0000 0x00126fff Memory Mapped File Readable False False False
private_0x00000000001f0000 0x001f0000 0x001fffff Private Memory Readable, Writable True False False
private_0x0000000000220000 0x00220000 0x0031ffff Private Memory Readable, Writable True False False
sc.exe 0x00ec0000 0x00ecbfff Memory Mapped File Readable, Writable, Executable True False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Host Behavior
File (2)
+
Operation Filename Additional Information Success Count Logfile
OPEN STD_OUTPUT_HANDLE True 1
Fn
WRITE STD_OUTPUT_HANDLE size = 34 True 1
Fn
Data
Module (1)
+
Operation Module Additional Information Success Count Logfile
GET_HANDLE c:\windows\system32\sc.exe base_address = 0xec0000 True 1
Fn
Service (5)
+
Operation Service Additional Information Success Count Logfile
OPEN_MGR SERVICES_ACTIVE_DATABASE host = Localhost, desired_access = SC_MANAGER_CONNECT True 1
Fn
OPEN WinDefend database_name = SERVICES_ACTIVE_DATABASE, desired_access = SERVICE_QUERY_CONFIG, SERVICE_CHANGE_CONFIG True 1
Fn
GET_INFO WinDefend type = SERVICE_CONFIG_DELAYED_AUTO_START_INFO True 1
Fn
SET_CONFIG WinDefend True 1
Fn
SET_CONFIG WinDefend new_service_type = SERVICE_NO_CHANGE, new_start_type = SERVICE_DISABLED True 1
Fn
Process #9: net.exe
+
Information Value
ID / OS PID #9 / 0x6b0
OS Parent PID 0x494 (c:\windows\system32\wscript.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\net.exe
Command Line "C:\Windows\System32\net.exe" localgroup HomeUsers /delete DSsDPMx042
Monitor Start Time: 00:03:47, Reason: Child Process
Unmonitor End Time: 00:03:48, Reason: Terminated
Monitor Duration 00:00:01
OS Thread IDs
# 108
0x 954
Remarks No high level activity detected in monitored regions
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
net.exe 0x00130000 0x00147fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000270000 0x00270000 0x002effff Private Memory Readable, Writable True False False
private_0x0000000000430000 0x00430000 0x0043ffff Private Memory Readable, Writable True False False
private_0x0000000000490000 0x00490000 0x0058ffff Private Memory Readable, Writable True False False
browcli.dll 0x6dca0000 0x6dcacfff Memory Mapped File Readable, Writable, Executable False False False
mpr.dll 0x72080000 0x72091fff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x72300000 0x72306fff Memory Mapped File Readable, Writable, Executable False False False
IPHLPAPI.DLL 0x72310000 0x7232bfff Memory Mapped File Readable, Writable, Executable False False False
samcli.dll 0x73b20000 0x73b2efff Memory Mapped File Readable, Writable, Executable False False False
wkscli.dll 0x73b30000 0x73b3efff Memory Mapped File Readable, Writable, Executable False False False
netutils.dll 0x73b40000 0x73b48fff Memory Mapped File Readable, Writable, Executable False False False
srvcli.dll 0x751f0000 0x75208fff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x77340000 0x77345fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Process #10: net1.exe
(Host: 9, Network: 0)
+
Information Value
ID / OS PID #10 / 0x9bc
OS Parent PID 0x6b0 (c:\windows\system32\net.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\net1.exe
Command Line C:\Windows\system32\net1 localgroup HomeUsers /delete DSsDPMx042
Monitor Start Time: 00:03:48, Reason: Child Process
Unmonitor End Time: 00:03:48, Reason: Terminated
Monitor Duration 00:00:00
OS Thread IDs
# 110
0x 66C
# 111
0x 668
# 112
0x 664
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory Readable True False False
private_0x0000000000050000 0x00050000 0x000cffff Private Memory Readable, Writable True False False
locale.nls 0x000d0000 0x00136fff Memory Mapped File Readable False False False
private_0x00000000002b0000 0x002b0000 0x003affff Private Memory Readable, Writable True False False
private_0x00000000003d0000 0x003d0000 0x0044ffff Private Memory Readable, Writable True False False
private_0x00000000004d0000 0x004d0000 0x0054ffff Private Memory Readable, Writable True False False
private_0x0000000000550000 0x00550000 0x0055ffff Private Memory Readable, Writable True False False
net1.exe 0x00a70000 0x00a99fff Memory Mapped File Readable, Writable, Executable True False False
netmsg.dll 0x6c3c0000 0x6c3c1fff Memory Mapped File Readable, Writable, Executable False False False
browcli.dll 0x6dca0000 0x6dcacfff Memory Mapped File Readable, Writable, Executable False False False
ntdsapi.dll 0x72e10000 0x72e27fff Memory Mapped File Readable, Writable, Executable False False False
dsrole.dll 0x73720000 0x73728fff Memory Mapped File Readable, Writable, Executable False False False
samcli.dll 0x73b20000 0x73b2efff Memory Mapped File Readable, Writable, Executable False False False
wkscli.dll 0x73b30000 0x73b3efff Memory Mapped File Readable, Writable, Executable False False False
netutils.dll 0x73b40000 0x73b48fff Memory Mapped File Readable, Writable, Executable False False False
netapi32.dll 0x73b50000 0x73b60fff Memory Mapped File Readable, Writable, Executable False False False
samlib.dll 0x740d0000 0x740e1fff Memory Mapped File Readable, Writable, Executable False False False
logoncli.dll 0x74c70000 0x74c91fff Memory Mapped File Readable, Writable, Executable False False False
srvcli.dll 0x751f0000 0x75208fff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x77340000 0x77345fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x773f0000 0x77424fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory Readable, Writable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Host Behavior
File (6)
+
Operation Filename Additional Information Success Count Logfile
OPEN STD_OUTPUT_HANDLE True 1
Fn
OPEN STD_ERROR_HANDLE True 1
Fn
WRITE STD_ERROR_HANDLE size = 33 True 1
Fn
Data
WRITE STD_ERROR_HANDLE size = 2 True 2
Fn
Data
WRITE STD_ERROR_HANDLE size = 43 True 1
Fn
Data
Module (3)
+
Operation Module Additional Information Success Count Logfile
LOAD NETMSG base_address = 0x6c3c0000 True 1
Fn
GET_HANDLE c:\windows\system32\net1.exe base_address = 0xa70000 True 1
Fn
GET_FILENAME C:\Windows\system32\net1.exe True 1
Fn
Process #11: cmd.exe
(Host: 65, Network: 0)
+
Information Value
ID / OS PID #11 / 0x69c
OS Parent PID 0x494 (c:\windows\system32\wscript.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\cmd.exe
Command Line "C:\Windows\System32\cmd.exe" /k echo a > "C:\Users\Public\N3Eg\uc"
Monitor Start Time: 00:03:48, Reason: Child Process
Unmonitor End Time: 00:03:50, Reason: Terminated
Monitor Duration 00:00:02
OS Thread IDs
# 114
0x 9CC
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x0012ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000130000 0x00130000 0x00133fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000140000 0x00140000 0x00140fff Pagefile Backed Memory Readable True False False
locale.nls 0x00150000 0x001b6fff Memory Mapped File Readable False False False
pagefile_0x00000000001c0000 0x001c0000 0x00287fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000290000 0x00290000 0x00296fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000002a0000 0x002a0000 0x002a1fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000002b0000 0x002b0000 0x002b0fff Private Memory Readable, Writable True False False
private_0x00000000002c0000 0x002c0000 0x003bffff Private Memory Readable, Writable True False False
pagefile_0x00000000003c0000 0x003c0000 0x004c0fff Pagefile Backed Memory Readable True False False
private_0x00000000004d0000 0x004d0000 0x004d0fff Private Memory Readable, Writable True False False
private_0x0000000000500000 0x00500000 0x0050ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000510000 0x00510000 0x0110ffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001110000 0x01110000 0x0139afff Pagefile Backed Memory Readable True False False
cmd.exe 0x4a810000 0x4a85bfff Memory Mapped File Readable, Writable, Executable True False False
winbrand.dll 0x6dd80000 0x6dd86fff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Created Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\public\n3eg\uc 0.00 KB (4 bytes) MD5: 27ff7ea9ce50076cfc8e794d64957f7c
SHA1: d765803318ad03df1a1fbdc66fd542945dd81a84
SHA256: 885fa5c5cb5f80fdb414f1b3e0b94c4b1366db1ce83e82358c4cb67da2ab73e4
False
Host Behavior
File (39)
+
Operation Filename Additional Information Success Count Logfile
CREATE c:\users\public\n3eg\uc desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
OPEN STD_OUTPUT_HANDLE True 14
Fn
OPEN STD_INPUT_HANDLE True 11
Fn
OPEN c:\users\public\n3eg\uc True 9
Fn
READ STD_INPUT_HANDLE size = 8192 False 1
Fn
WRITE c:\users\public\n3eg\uc size = 4 True 1
Fn
Data
WRITE STD_OUTPUT_HANDLE size = 2 True 1
Fn
Data
WRITE STD_OUTPUT_HANDLE size = 20 True 1
Fn
Data
Process (1)
+
Operation Process Name Additional Information Success Count Logfile
SET_CURDIR c:\windows\system32\cmd.exe os_pid = 0x69c, new_path_name = c:\windows\system32 True 1
Fn
Module (8)
+
Operation Module Additional Information Success Count Logfile
GET_HANDLE c:\windows\system32\cmd.exe base_address = 0x4a810000 True 1
Fn
GET_HANDLE c:\windows\system32\kernel32.dll base_address = 0x75900000 True 2
Fn
GET_FILENAME C:\Windows\System32\cmd.exe True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetThreadUILanguage, address = 0x759524c2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CopyFileExW, address = 0x7593ac6c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = IsDebuggerPresent, address = 0x75943ea8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetConsoleInputExeNameW, address = 0x75952732 True 1
Fn
Registry (17)
+
Operation Key Additional Information Success Count Logfile
OPEN_KEY HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 88 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 9 False 1
Fn
Process #12: cmd.exe
(Host: 57, Network: 0)
+
Information Value
ID / OS PID #12 / 0x660
OS Parent PID 0x494 (c:\windows\system32\wscript.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\cmd.exe
Command Line "C:\Windows\System32\cmd.exe" /k shutdown -r -t 0 -f
Monitor Start Time: 00:03:49, Reason: Child Process
Unmonitor End Time: 00:03:50, Reason: Terminated
Monitor Duration 00:00:01
OS Thread IDs
# 116
0x 65C
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
pagefile_0x00000000000c0000 0x000c0000 0x000c6fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000000d0000 0x000d0000 0x000d1fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000000e0000 0x000e0000 0x000e0fff Private Memory Readable, Writable True False False
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory Readable, Writable True False False
private_0x0000000000170000 0x00170000 0x0026ffff Private Memory Readable, Writable True False False
private_0x00000000002e0000 0x002e0000 0x003dffff Private Memory Readable, Writable True False False
pagefile_0x00000000003e0000 0x003e0000 0x004a7fff Pagefile Backed Memory Readable True False False
private_0x0000000000580000 0x00580000 0x0058ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000590000 0x00590000 0x00690fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000006a0000 0x006a0000 0x0129ffff Pagefile Backed Memory Readable True False False
pagefile_0x00000000012a0000 0x012a0000 0x0152afff Pagefile Backed Memory Readable True False False
cmd.exe 0x4a810000 0x4a85bfff Memory Mapped File Readable, Writable, Executable True False False
winbrand.dll 0x6dd80000 0x6dd86fff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Host Behavior
File (30)
+
Operation Filename Additional Information Success Count Logfile
OPEN c:\users\public\n3eg\uc True 10
Fn
OPEN STD_INPUT_HANDLE True 11
Fn
OPEN STD_OUTPUT_HANDLE True 6
Fn
READ STD_INPUT_HANDLE size = 8192 False 1
Fn
WRITE STD_OUTPUT_HANDLE size = 2 True 1
Fn
Data
WRITE STD_OUTPUT_HANDLE size = 20 True 1
Fn
Data
Process (2)
+
Operation Process Name Additional Information Success Count Logfile
CREATE C:\Windows\system32\shutdown.exe os_tid = 0x9f0, os_pid = 0x9ec, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, current_directory = C:\Windows\system32, show_window = SW_SHOWNORMAL True 1
Fn
SET_CURDIR c:\windows\system32\cmd.exe os_pid = 0x660, new_path_name = c:\windows\system32 True 1
Fn
Module (8)
+
Operation Module Additional Information Success Count Logfile
GET_HANDLE c:\windows\system32\cmd.exe base_address = 0x4a810000 True 1
Fn
GET_HANDLE c:\windows\system32\kernel32.dll base_address = 0x75900000 True 2
Fn
GET_FILENAME C:\Windows\System32\cmd.exe True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetThreadUILanguage, address = 0x759524c2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CopyFileExW, address = 0x7593ac6c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = IsDebuggerPresent, address = 0x75943ea8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetConsoleInputExeNameW, address = 0x75952732 True 1
Fn
Registry (17)
+
Operation Key Additional Information Success Count Logfile
OPEN_KEY HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 0 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 9 False 1
Fn
Process #13: shutdown.exe
+
Information Value
ID / OS PID #13 / 0x9ec
OS Parent PID 0x660 (c:\windows\system32\cmd.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\shutdown.exe
Command Line shutdown -r -t 0 -f
Monitor Start Time: 00:03:49, Reason: Child Process
Unmonitor End Time: 00:03:49, Reason: Terminated
Monitor Duration 00:00:00
OS Thread IDs
# 117
0x 9F0
# 118
0x A1C
Remarks No high level activity detected in monitored regions
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
private_0x0000000000140000 0x00140000 0x0017ffff Private Memory Readable, Writable True False False
private_0x00000000001d0000 0x001d0000 0x002cffff Private Memory Readable, Writable True False False
pagefile_0x00000000002d0000 0x002d0000 0x00397fff Pagefile Backed Memory Readable True False False
shutdown.exe 0x00410000 0x00419fff Memory Mapped File Readable, Writable, Executable False False False
private_0x00000000005b0000 0x005b0000 0x005bffff Private Memory Readable, Writable True False False
secur32.dll 0x75260000 0x75267fff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75280000 0x7529afff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x76a90000 0x76bebfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Process #14: regsvr32.exe
(Host: 90, Network: 0)
+
Information Value
ID / OS PID #14 / 0x574
OS Parent PID 0x470 (c:\windows\explorer.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\regsvr32.exe
Command Line "C:\Windows\System32\regsvr32.exe" /s "C:\Users\Public\N3Eg\N3Eg2.51N3E" #96
Monitor Start Time: 00:04:12, Reason: Analysis Target
Unmonitor End Time: 00:04:23, Reason: Terminated
Monitor Duration 00:00:11
OS Thread IDs
# 120
0x 578
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00041fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
pagefile_0x00000000000c0000 0x000c0000 0x000c1fff Pagefile Backed Memory Readable, Writable True False False
regsvr32.exe.mui 0x000d0000 0x000d1fff Memory Mapped File Readable, Writable False False False
private_0x00000000000e0000 0x000e0000 0x000e0fff Private Memory Readable, Writable True False False
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory Readable, Writable True False False
pagefile_0x0000000000110000 0x00110000 0x00111fff Pagefile Backed Memory Readable True False False
private_0x0000000000130000 0x00130000 0x0013ffff Private Memory Readable, Writable True False False
private_0x0000000000140000 0x00140000 0x0017ffff Private Memory Readable, Writable True False False
private_0x00000000001b0000 0x001b0000 0x002affff Private Memory Readable, Writable True False False
pagefile_0x00000000002b0000 0x002b0000 0x00377fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000380000 0x00380000 0x00480fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000490000 0x00490000 0x0056efff Pagefile Backed Memory Readable True False False
private_0x00000000005d0000 0x005d0000 0x0060ffff Private Memory Readable, Writable True False False
N3Eg2.51N3E 0x00610000 0x00764fff Memory Mapped File Readable, Writable, Executable True True False
private_0x0000000000770000 0x00770000 0x008affff Private Memory Readable, Writable True False False
SortDefault.nls 0x008b0000 0x00b7efff Memory Mapped File Readable False False False
regsvr32.exe 0x00f30000 0x00f36fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000f40000 0x00f40000 0x01b3ffff Pagefile Backed Memory Readable True False False
uxtheme.dll 0x74b10000 0x74b4ffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x74c90000 0x74e2dfff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x75c00000 0x75c0bfff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75f30000 0x75f79fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x75fb0000 0x75fcefff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76010000 0x7605dfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76110000 0x761b0fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x761c0000 0x7626bfff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76270000 0x76338fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x77130000 0x771cffff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77580000 0x7761cfff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x77620000 0x7777bfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x77780000 0x77853fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x77860000 0x778b6fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x77a00000 0x77a8efff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x77a90000 0x77b5bfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b60000 0x77c9bfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77cc0000 0x77cc9fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77ce0000 0x77cf8fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77da0000 0x77da0fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Host Behavior
Process (1)
+
Operation Process Name Additional Information Success Count Logfile
OPEN c:\windows\explorer.exe os_pid = 0x470, desired_access = PROCESS_ALL_ACCESS True 1
Fn
Memory (2)
+
Operation Address Additional Information Success Count Logfile
ALLOC 0x3140000 process_name = c:\windows\explorer.exe, os_pid = 0x470, size = 66, allocation_type = MEM_COMMIT, protection = PAGE_READWRITE True 1
Fn
WRITE 0x3140000 process_name = c:\windows\explorer.exe, os_pid = 0x470, size = 66 True 1
Fn
Data
Thread (1)
+
Operation Process Name Additional Information Success Count Logfile
CREATE c:\windows\explorer.exe os_tid = 0x628, os_pid = 0x470, proc_address = 0x777d3c01, flags = THREAD_RUNS_IMMEDIATELY True 1
Fn
Module (73)
+
Operation Module Additional Information Success Count Logfile
LOAD kernel32.dll base_address = 0x77780000 True 3
Fn
GET_HANDLE c:\windows\system32\kernel32.dll base_address = 0x77780000 True 7
Fn
GET_HANDLE c:\windows\system32\oleaut32.dll base_address = 0x77a00000 True 1
Fn
GET_FILENAME C:\Users\Public\N3Eg\N3Eg2.51N3E True 1
Fn
GET_FILENAME C:\Windows\System32\regsvr32.exe True 3
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetThreadPreferredUILanguages, address = 0x777c22d7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetThreadPreferredUILanguages, address = 0x777be627 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetThreadUILanguage, address = 0x777bae42 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetNativeSystemInfo, address = 0x777bbe77 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetDiskFreeSpaceExW, address = 0x777bde40 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VariantChangeTypeEx, address = 0x77a04c28 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarNeg, address = 0x77a7c802 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarNot, address = 0x77a7ec66 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarAdd, address = 0x77a25934 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarSub, address = 0x77a7d332 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarMul, address = 0x77a7dbd4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarDiv, address = 0x77a7e405 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarIdiv, address = 0x77a7f00a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarMod, address = 0x77a7f15e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarAnd, address = 0x77a25a98 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarOr, address = 0x77a7ecfa True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarXor, address = 0x77a7ee2e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarCmp, address = 0x77a1b0dc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarI4FromStr, address = 0x77a16fab True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarR4FromStr, address = 0x77a201a0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarR8FromStr, address = 0x77a1699e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarDateFromStr, address = 0x77a26ba7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarCyFromStr, address = 0x77a46c12 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarBoolFromStr, address = 0x77a1dbd1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarBstrFromCy, address = 0x77a27fdc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarBstrFromDate, address = 0x77a17a2a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarBstrFromBool, address = 0x77a20355 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = InitializeConditionVariable, address = 0x77bb9981 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WakeConditionVariable, address = 0x77c05a7b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WakeAllConditionVariable, address = 0x77b845a5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SleepConditionVariableCS, address = 0x777b18be True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CreateToolhelp32Snapshot, address = 0x777bf731 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Heap32ListFirst, address = 0x778102e7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Heap32ListNext, address = 0x77810391 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Heap32First, address = 0x77810429 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Heap32Next, address = 0x77810614 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Toolhelp32ReadProcessMemory, address = 0x77810819 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Process32First, address = 0x777e443d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Process32Next, address = 0x777e4505 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Process32FirstW, address = 0x777bfa35 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Process32NextW, address = 0x777bfaca True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Thread32First, address = 0x777e7e4c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Thread32Next, address = 0x777e7edc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Module32First, address = 0x77810859 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Module32Next, address = 0x77810942 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Module32FirstW, address = 0x777bc59e True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Module32NextW, address = 0x777bc11f True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = VirtualAllocEx, address = 0x777bc1b6 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WriteProcessMemory, address = 0x777bc1de True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CreateRemoteThread, address = 0x7780f33b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = OpenProcess, address = 0x777c59d7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LoadLibraryW, address = 0x777d3c01 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetLogicalProcessorInformation, address = 0x777b2004 True 2
Fn
Registry (12)
+
Operation Key Additional Information Success Count Logfile
OPEN_KEY HKEY_CURRENT_USER\Software\Embarcadero\Locales False 2
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Embarcadero\Locales False 2
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\CodeGear\Locales False 2
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\CodeGear\Locales False 2
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Borland\Locales False 2
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Borland\Delphi\Locales False 2
Fn
System (1)
+
Operation Information Success Count Logfile
GET_INFO type = Hardware Information True 1
Fn
Process #15: explorer.exe
(Host: 844, Network: 12)
+
Information Value
ID / OS PID #15 / 0x470
OS Parent PID 0x468 (c:\windows\system32\userinit.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\explorer.exe
Command Line C:\Windows\Explorer.EXE
Monitor Start Time: 00:04:22, Reason: Injection
Unmonitor End Time: 00:06:46, Reason: Terminated
Monitor Duration 00:02:24
OS Thread IDs
# 121
0x 5E8
# 122
0x 5C4
# 123
0x 5B4
# 124
0x 59C
# 125
0x 594
# 126
0x 568
# 127
0x 564
# 128
0x 560
# 129
0x 55C
# 130
0x 558
# 131
0x 52C
# 132
0x 528
# 133
0x 524
# 134
0x 494
# 135
0x 490
# 136
0x 48C
# 137
0x 488
# 138
0x 484
# 139
0x 480
# 140
0x 47C
# 141
0x 478
# 142
0x 474
# 143
0x 628
# 144
0x 62C
# 145
0x 66C
# 146
0x 670
# 155
0x 6A0
# 156
0x 6A8
# 157
0x 6B4
# 158
0x 6C4
# 159
0x 6C8
# 160
0x 6D0
# 161
0x 6D4
# 182
0x 7C4
# 183
0x 7C8
# 184
0x 7DC
# 185
0x 7E4
# 205
0x 918
# 210
0x 954
# 242
0x A1C
# 244
0x ACC
# 246
0x B00
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00021fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00041fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000050000 0x00050000 0x00056fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00061fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000070000 0x00070000 0x00070fff Private Memory Readable, Writable True False False
private_0x0000000000080000 0x00080000 0x000bffff Private Memory Readable, Writable True False False
locale.nls 0x000c0000 0x00126fff Memory Mapped File Readable False False False
pagefile_0x0000000000130000 0x00130000 0x001f7fff Pagefile Backed Memory Readable True False False
private_0x0000000000200000 0x00200000 0x00200fff Private Memory Readable, Writable True False False
private_0x0000000000210000 0x00210000 0x0022ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000230000 0x00230000 0x00230fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000240000 0x00240000 0x00241fff Pagefile Backed Memory Readable True False False
private_0x0000000000250000 0x00250000 0x00250fff Private Memory Readable, Writable True False False
private_0x0000000000260000 0x00260000 0x0026ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000270000 0x00270000 0x00271fff Pagefile Backed Memory Readable True False False
private_0x0000000000280000 0x00280000 0x0037ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000380000 0x00380000 0x00480fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000490000 0x00490000 0x00882fff Pagefile Backed Memory Readable True False False
private_0x0000000000890000 0x00890000 0x008cffff Private Memory Readable, Writable True False False
private_0x00000000008d0000 0x008d0000 0x009cffff Private Memory Readable, Writable True False False
private_0x00000000009d0000 0x009d0000 0x009fbfff Private Memory Readable, Writable True False False
private_0x0000000000a00000 0x00a00000 0x00a2ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000a30000 0x00a30000 0x00a30fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000a40000 0x00a40000 0x00a40fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000a50000 0x00a50000 0x00a51fff Pagefile Backed Memory Readable True False False
private_0x0000000000a60000 0x00a60000 0x00a60fff Private Memory Readable, Writable True False False
private_0x0000000000a70000 0x00a70000 0x00a70fff Private Memory Readable, Writable True False False
pagefile_0x0000000000a80000 0x00a80000 0x00a81fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000a90000 0x00a90000 0x00a91fff Pagefile Backed Memory Readable True False False
private_0x0000000000aa0000 0x00aa0000 0x00adffff Private Memory Readable, Writable True False False
pagefile_0x0000000000ae0000 0x00ae0000 0x00bbefff Pagefile Backed Memory Readable True False False
private_0x0000000000bc0000 0x00bc0000 0x00bc0fff Private Memory Readable, Writable True False False
comctl32.dll.mui 0x00bd0000 0x00bd2fff Memory Mapped File Readable, Writable False False False
private_0x0000000000be0000 0x00be0000 0x00be0fff Private Memory Readable, Writable True False False
private_0x0000000000bf0000 0x00bf0000 0x00bfffff Private Memory Readable, Writable True False False
private_0x0000000000c00000 0x00c00000 0x00c08fff Private Memory Readable, Writable True False False
private_0x0000000000c10000 0x00c10000 0x00c17fff Private Memory Readable, Writable True False False
{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000000c.db 0x00c20000 0x00c3cfff Memory Mapped File Readable True False False
pagefile_0x0000000000c40000 0x00c40000 0x00c40fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000c50000 0x00c50000 0x00c8ffff Private Memory Readable, Writable True False False
cversions.2.db 0x00c90000 0x00c93fff Memory Mapped File Readable True False False
cversions.2.db 0x00ca0000 0x00ca3fff Memory Mapped File Readable True False False
pagefile_0x0000000000cb0000 0x00cb0000 0x00cb1fff Pagefile Backed Memory Readable True False False
private_0x0000000000cc0000 0x00cc0000 0x00d3ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000d40000 0x00d40000 0x00d41fff Pagefile Backed Memory Readable True False False
private_0x0000000000d50000 0x00d50000 0x00d50fff Private Memory Readable, Writable True False False
explorer.exe 0x00d60000 0x00fe0fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000ff0000 0x00ff0000 0x01beffff Pagefile Backed Memory Readable True False False
SortDefault.nls 0x01bf0000 0x01ebefff Memory Mapped File Readable False False False
private_0x0000000001ec0000 0x01ec0000 0x01f67fff Private Memory Readable, Writable True False False
private_0x0000000001f70000 0x01f70000 0x02023fff Private Memory Readable, Writable True False False
private_0x0000000002030000 0x02030000 0x02033fff Private Memory Readable, Writable True False False
private_0x0000000002040000 0x02040000 0x0207ffff Private Memory Readable, Writable True False False
private_0x0000000002040000 0x02040000 0x02043fff Private Memory Readable, Writable True False False
thumbcache_1024.db 0x02050000 0x02050fff Memory Mapped File Readable, Writable True False False
pagefile_0x0000000002050000 0x02050000 0x02051fff Pagefile Backed Memory Readable, Writable True False False
thumbcache_sr.db 0x02060000 0x02060fff Memory Mapped File Readable, Writable True False False
pagefile_0x0000000002060000 0x02060000 0x02061fff Pagefile Backed Memory Readable True False False
thumbcache_idx.db 0x02070000 0x02071fff Memory Mapped File Readable, Writable True False False
pagefile_0x0000000002070000 0x02070000 0x02071fff Pagefile Backed Memory Readable True False False
private_0x0000000002080000 0x02080000 0x0227ffff Private Memory Readable, Writable True False False
private_0x0000000002280000 0x02280000 0x022bffff Private Memory Readable, Writable True False False
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000007.db 0x022c0000 0x022effff Memory Mapped File Readable True False False
private_0x00000000022f0000 0x022f0000 0x022f3fff Private Memory Readable, Writable True False False
private_0x0000000002300000 0x02300000 0x02300fff Private Memory Readable, Writable True False False
private_0x0000000002300000 0x02300000 0x02300fff Private Memory Readable, Writable True False False
private_0x0000000002310000 0x02310000 0x0234ffff Private Memory Readable, Writable True False False
ActionCenter.dll.mui 0x02310000 0x02314fff Memory Mapped File Readable, Writable False False False
private_0x0000000002350000 0x02350000 0x02350fff Private Memory Readable, Writable True False False
private_0x0000000002360000 0x02360000 0x0239ffff Private Memory Readable, Writable True False False
private_0x00000000023a0000 0x023a0000 0x023a0fff Private Memory Readable, Writable True False False
private_0x00000000023b0000 0x023b0000 0x023effff Private Memory Readable, Writable True False False
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db 0x023f0000 0x02455fff Memory Mapped File Readable True False False
private_0x0000000002460000 0x02460000 0x02460fff Private Memory Readable, Writable True False False
private_0x0000000002470000 0x02470000 0x02470fff Private Memory Readable, Writable True False False
private_0x0000000002480000 0x02480000 0x02480fff Private Memory Readable, Writable True False False
private_0x0000000002490000 0x02490000 0x02490fff Private Memory Readable, Writable True False False
private_0x00000000024a0000 0x024a0000 0x024a0fff Private Memory Readable, Writable True False False
private_0x00000000024b0000 0x024b0000 0x024effff Private Memory Readable, Writable True False False
StaticCache.dat 0x024f0000 0x02e1ffff Memory Mapped File Readable False False False
pagefile_0x0000000002e20000 0x02e20000 0x02e20fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000002e30000 0x02e30000 0x02e31fff Pagefile Backed Memory Readable True False False
cversions.2.db 0x02e40000 0x02e43fff Memory Mapped File Readable True False False
pagefile_0x0000000002e50000 0x02e50000 0x02e51fff Pagefile Backed Memory Readable True False False
{7CD55808-3D38-4DD5-90C9-62F0E6EE60D4}.2.ver0x0000000000000001.db 0x02e60000 0x02e60fff Memory Mapped File Readable True False False
private_0x0000000002e70000 0x02e70000 0x02e73fff Private Memory Readable, Writable True False False
private_0x0000000002e70000 0x02e70000 0x02e70fff Private Memory Readable, Writable True False False
private_0x0000000002e80000 0x02e80000 0x02e80fff Private Memory Readable, Writable True False False
private_0x0000000002e90000 0x02e90000 0x02e90fff Private Memory Readable, Writable True False False
private_0x0000000002ea0000 0x02ea0000 0x02ea0fff Private Memory Readable, Writable True False False
private_0x0000000002eb0000 0x02eb0000 0x02eeffff Private Memory Readable, Writable True False False
private_0x0000000002ef0000 0x02ef0000 0x02feffff Private Memory Readable, Writable True False False
private_0x0000000002ff0000 0x02ff0000 0x02ff0fff Private Memory Readable, Writable True False False
private_0x0000000002ff0000 0x02ff0000 0x0302ffff Private Memory Readable, Writable True False False
private_0x0000000003000000 0x03000000 0x03000fff Private Memory Readable, Writable True False False
private_0x0000000003010000 0x03010000 0x03010fff Private Memory Readable, Writable True False False
private_0x0000000003020000 0x03020000 0x03020fff Private Memory Readable, Writable True False False
private_0x0000000003020000 0x03020000 0x0305ffff Private Memory Readable, Writable True False False
thumbcache_1024.db 0x03030000 0x03030fff Memory Mapped File Readable, Writable True False False
thumbcache_sr.db 0x03040000 0x03040fff Memory Mapped File Readable, Writable True False False
thumbcache_idx.db 0x03050000 0x03051fff Memory Mapped File Readable, Writable True False False
private_0x0000000003060000 0x03060000 0x0309ffff Private Memory Readable, Writable True False False
pagefile_0x00000000030a0000 0x030a0000 0x030a0fff Pagefile Backed Memory Readable True False False
wdmaud.drv.mui 0x030b0000 0x030b0fff Memory Mapped File Readable, Writable False False False
pagefile_0x00000000030c0000 0x030c0000 0x030c1fff Pagefile Backed Memory Readable True False False
MMDevAPI.dll.mui 0x030d0000 0x030d0fff Memory Mapped File Readable, Writable False False False
private_0x00000000030e0000 0x030e0000 0x0311ffff Private Memory Readable, Writable True False False
private_0x0000000003120000 0x03120000 0x03120fff Private Memory Readable, Writable True False False
private_0x0000000003130000 0x03130000 0x03131fff Private Memory Readable, Writable True False False
private_0x0000000003140000 0x03140000 0x03140fff Private Memory Readable, Writable True False False
private_0x0000000003150000 0x03150000 0x0318ffff Private Memory Readable, Writable True False False
private_0x0000000003190000 0x03190000 0x031dffff Private Memory Readable, Writable True False False
private_0x0000000003190000 0x03190000 0x03190fff Private Memory Readable, Writable True False False
private_0x00000000031a0000 0x031a0000 0x031a0fff Private Memory Readable, Writable True False False
private_0x00000000031b0000 0x031b0000 0x031b0fff Private Memory Readable, Writable True False False
private_0x00000000031c0000 0x031c0000 0x031c0fff Private Memory Readable, Writable True False False
private_0x00000000031e0000 0x031e0000 0x03227fff Private Memory Readable, Writable True False False
pagefile_0x0000000003230000 0x03230000 0x03231fff Pagefile Backed Memory Readable, Writable True False False
oleaccrc.dll 0x03230000 0x03230fff Memory Mapped File Readable False False False
private_0x0000000003240000 0x03240000 0x03241fff Private Memory Readable, Writable True False False
private_0x0000000003250000 0x03250000 0x0328ffff Private Memory Readable, Writable True False False
pagefile_0x0000000003290000 0x03290000 0x03291fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000032a0000 0x032a0000 0x032a1fff Pagefile Backed Memory Readable True False False
cversions.2.db 0x032b0000 0x032b3fff Memory Mapped File Readable True False False
private_0x00000000032c0000 0x032c0000 0x032fffff Private Memory Readable, Writable True False False
private_0x00000000032c0000 0x032c0000 0x032fffff Private Memory Readable, Writable True False False
private_0x0000000003300000 0x03300000 0x03300fff Private Memory Readable, Writable, Executable True False False
pagefile_0x0000000003310000 0x03310000 0x03311fff Pagefile Backed Memory Readable True False False
private_0x0000000003320000 0x03320000 0x0335ffff Private Memory Readable, Writable True False False
pagefile_0x0000000003360000 0x03360000 0x03361fff Pagefile Backed Memory Readable True False False
private_0x0000000003370000 0x03370000 0x0337ffff Private Memory Readable, Writable True False False
bthprops.cpl.mui 0x03380000 0x03386fff Memory Mapped File Readable, Writable False False False
private_0x0000000003390000 0x03390000 0x033cffff Private Memory Readable, Writable True False False
private_0x00000000033d0000 0x033d0000 0x03402fff Private Memory Readable, Writable True False False
pagefile_0x0000000003410000 0x03410000 0x03411fff Pagefile Backed Memory Readable True False False
private_0x0000000003420000 0x03420000 0x0345ffff Private Memory Readable, Writable True False False
private_0x0000000003420000 0x03420000 0x03420fff Private Memory Readable, Writable, Executable True False False
private_0x0000000003430000 0x03430000 0x0343ffff Private Memory Readable, Writable True False False
index.dat 0x03440000 0x03453fff Memory Mapped File Readable, Writable True True False
private_0x0000000003460000 0x03460000 0x0349ffff Private Memory Readable, Writable True False False
thumbcache_32.db 0x034a0000 0x0359ffff Memory Mapped File Readable, Writable True False False
index.dat 0x035a0000 0x035a7fff Memory Mapped File Readable, Writable True True False
index.dat 0x035b0000 0x035bbfff Memory Mapped File Readable, Writable True True False
pagefile_0x00000000035c0000 0x035c0000 0x035c0fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x00000000035d0000 0x035d0000 0x035d0fff Pagefile Backed Memory Readable, Writable True False False
thumbcache_96.db 0x035e0000 0x036dffff Memory Mapped File Readable, Writable True False False
thumbcache_256.db 0x036e0000 0x037dffff Memory Mapped File Readable, Writable True False False
private_0x00000000037e0000 0x037e0000 0x037e2fff Private Memory Readable, Writable True False False
private_0x00000000037f0000 0x037f0000 0x0382ffff Private Memory Readable, Writable True False False
pagefile_0x0000000003830000 0x03830000 0x03831fff Pagefile Backed Memory Readable True False False
private_0x0000000003840000 0x03840000 0x0387ffff Private Memory Readable, Writable True False False
imageres.dll 0x03880000 0x04bd4fff Memory Mapped File Readable False False False
N3Eg4.51N3E 0x04be0000 0x04c54fff Memory Mapped File Readable, Writable, Executable True True False
pagefile_0x0000000004c60000 0x04c60000 0x04c61fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000004c70000 0x04c70000 0x04c71fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000004c80000 0x04c80000 0x04c81fff Pagefile Backed Memory Readable True False False
private_0x0000000004cb0000 0x04cb0000 0x04ceffff Private Memory Readable, Writable True False False
private_0x0000000004d00000 0x04d00000 0x04d3ffff Private Memory Readable, Writable True False False
private_0x0000000004d40000 0x04d40000 0x05141fff Private Memory Readable, Writable True False False
private_0x0000000005160000 0x05160000 0x0519ffff Private Memory Readable, Writable True False False
private_0x00000000051c0000 0x051c0000 0x051fffff Private Memory Readable, Writable True False False
private_0x00000000051d0000 0x051d0000 0x0520ffff Private Memory Readable, Writable True False False
private_0x0000000005210000 0x05210000 0x0530ffff Private Memory - True False False
private_0x0000000005310000 0x05310000 0x0534ffff Private Memory Readable, Writable True False False
private_0x0000000005350000 0x05350000 0x055e2fff Private Memory Readable, Writable True False False
private_0x00000000055f0000 0x055f0000 0x057effff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059aefff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059b2fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059b6fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059bafff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059befff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059c2fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059c6fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059cafff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059cefff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059d2fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059d6fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059dafff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059defff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059e2fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059e6fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059eafff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059eefff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059f2fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059f6fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059fafff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059fefff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a02fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a06fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a0afff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a0efff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a12fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a16fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a1afff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a1efff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a22fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a26fff Private Memory Readable, Writable True False False
KernelBase.dll.mui 0x057f0000 0x058affff Memory Mapped File Readable, Writable False False False
thumbcache_32.db 0x058b0000 0x059affff Memory Mapped File Readable, Writable True False False
private_0x00000000058c0000 0x058c0000 0x058fffff Private Memory Readable, Writable True False False
private_0x00000000059b0000 0x059b0000 0x05b6cfff Private Memory Readable, Writable True False False
private_0x00000000059d0000 0x059d0000 0x05a0ffff Private Memory Readable, Writable True False False
private_0x0000000005a40000 0x05a40000 0x05a7ffff Private Memory Readable, Writable True False False
private_0x0000000005a90000 0x05a90000 0x05acffff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05c90fff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05c94fff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05c98fff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05c9cfff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05ca0fff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05ca4fff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05ca8fff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05cacfff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05cb0fff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05cb4fff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05cb8fff Private Memory Readable, Writable True False False
private_0x0000000005ae0000 0x05ae0000 0x05b1ffff Private Memory Readable, Writable True False False
private_0x0000000005b20000 0x05b20000 0x05b5ffff Private Memory Readable, Writable True False False
private_0x0000000005b90000 0x05b90000 0x05bcffff Private Memory Readable, Writable True False False
private_0x0000000005c10000 0x05c10000 0x05c1ffff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e0cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e10fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e14fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e18fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e1cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e20fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e24fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e28fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e2cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e30fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e34fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e38fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e40fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e44fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e48fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e4cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e50fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e54fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e58fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e5cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e60fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e64fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e68fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e6cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e70fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e74fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e78fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e7cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e80fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e84fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e88fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e8cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e90fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e94fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e98fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e9cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05ea0fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05ea4fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05ea8fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05eacfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05eb0fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05ebffff Private Memory - True False False
private_0x0000000005c60000 0x05c60000 0x05c9ffff Private Memory Readable, Writable True False False
private_0x0000000005ca0000 0x05ca0000 0x05ebcfff Private Memory Readable, Writable True False False
private_0x0000000005ec0000 0x05ec0000 0x05efffff Private Memory Readable, Writable True False False
private_0x0000000005f30000 0x05f30000 0x05f6ffff Private Memory Readable, Writable True False False
private_0x0000000005fb0000 0x05fb0000 0x05fbffff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x061fafff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x061fefff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06202fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06206fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0620afff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0620efff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06212fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06216fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0621afff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0621efff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06222fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06226fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0622afff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0622efff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06232fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06236fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0623afff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0623efff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06242fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06246fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0624afff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0624efff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06252fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0625bfff Private Memory Readable, Writable True False False
private_0x0000000006260000 0x06260000 0x0639ffff Private Memory Readable, Writable True False False
thumbcache_96.db 0x063a0000 0x0649ffff Memory Mapped File Readable, Writable True False False
thumbcache_256.db 0x064a0000 0x0659ffff Memory Mapped File Readable, Writable True False False
private_0x00000000065a0000 0x065a0000 0x065effff Private Memory Readable, Writable True False False
thumbcache_256.db 0x065f0000 0x0669ffff Memory Mapped File Readable, Writable True False False
private_0x0000000006720000 0x06720000 0x0675ffff Private Memory Readable, Writable True False False
private_0x00000000067f0000 0x067f0000 0x0682ffff Private Memory Readable, Writable True False False
private_0x00000000068b0000 0x068b0000 0x068effff Private Memory Readable, Writable True False False
private_0x0000000006950000 0x06950000 0x0698ffff Private Memory Readable, Writable True False False
private_0x00000000069d0000 0x069d0000 0x06a0ffff Private Memory Readable, Writable True False False
private_0x0000000006a80000 0x06a80000 0x06abffff Private Memory Readable, Writable True False False
ieproxy.dll 0x6dec0000 0x6deeafff Memory Mapped File Readable, Writable, Executable False False False
hcproviders.dll 0x6def0000 0x6def8fff Memory Mapped File Readable, Writable, Executable False False False
wercplsupport.dll 0x6df00000 0x6df11fff Memory Mapped File Readable, Writable, Executable False False False
framedynos.dll 0x6df20000 0x6df54fff Memory Mapped File Readable, Writable, Executable False False False
werconcpl.dll 0x6df60000 0x6e065fff Memory Mapped File Readable, Writable, Executable False False False
wscui.cpl 0x6e070000 0x6e189fff Memory Mapped File Readable, Writable, Executable False False False
wscapi.dll 0x6e190000 0x6e19efff Memory Mapped File Readable, Writable, Executable False False False
wscinterop.dll 0x6e1c0000 0x6e1d9fff Memory Mapped File Readable, Writable, Executable False False False
QAGENT.DLL 0x6ea40000 0x6ea6dfff Memory Mapped File Readable, Writable, Executable False False False
npmproxy.dll 0x6ed50000 0x6ed57fff Memory Mapped File Readable, Writable, Executable False False False
idndl.dll 0x6ee90000 0x6ee9afff Memory Mapped File Readable, Writable, Executable False False False
msftedit.dll 0x6f5c0000 0x6f653fff Memory Mapped File Readable, Writable, Executable False False False
netprofm.dll 0x6f6b0000 0x6f709fff Memory Mapped File Readable, Writable, Executable False False False
rasadhlp.dll 0x6f710000 0x6f715fff Memory Mapped File Readable, Writable, Executable False False False
provsvc.dll 0x6fb60000 0x6fb8afff Memory Mapped File Readable, Writable, Executable False False False
hgcpl.dll 0x6fb90000 0x6fbdefff Memory Mapped File Readable, Writable, Executable False False False
SyncCenter.dll 0x6fd30000 0x6ff3dfff Memory Mapped File Readable, Writable, Executable False False False
mlang.dll 0x6ffd0000 0x6fffdfff Memory Mapped File Readable, Writable, Executable False False False
imapi2.dll 0x6ffd0000 0x70033fff Memory Mapped File Readable, Writable, Executable False False False
webcheck.dll 0x70000000 0x70039fff Memory Mapped File Readable, Writable, Executable False False False
srchadmin.dll 0x701c0000 0x7020cfff Memory Mapped File Readable, Writable, Executable False False False
ieframe.dll 0x70d80000 0x717fffff Memory Mapped File Readable, Writable, Executable False False False
midimap.dll 0x71880000 0x71886fff Memory Mapped File Readable, Writable, Executable False False False
msacm32.dll 0x71890000 0x718a3fff Memory Mapped File Readable, Writable, Executable False False False
msacm32.drv 0x718b0000 0x718b7fff Memory Mapped File Readable, Writable, Executable False False False
AudioSes.dll 0x718c0000 0x718f5fff Memory Mapped File Readable, Writable, Executable False False False
ksuser.dll 0x71900000 0x71903fff Memory Mapped File Readable, Writable, Executable False False False
wdmaud.drv 0x71910000 0x7193ffff Memory Mapped File Readable, Writable, Executable False False False
winmm.dll 0x71940000 0x71971fff Memory Mapped File Readable, Writable, Executable False False False
networkexplorer.dll 0x71980000 0x71b17fff Memory Mapped File Readable, Writable, Executable False False False
thumbcache.dll 0x71b20000 0x71b35fff Memory Mapped File Readable, Writable, Executable False False False
tiptsf.dll 0x71d80000 0x71dd7fff Memory Mapped File Readable, Writable, Executable False False False
msls31.dll 0x71de0000 0x71e09fff Memory Mapped File Readable, Writable, Executable False False False
msftedit.dll 0x71e10000 0x71ea3fff Memory Mapped File Readable, Writable, Executable False False False
wwapi.dll 0x71e20000 0x71e29fff Memory Mapped File Readable, Writable, Executable False False False
WWanAPI.dll 0x71e30000 0x71e77fff Memory Mapped File Readable, Writable, Executable False False False
wlanutil.dll 0x71e80000 0x71e85fff Memory Mapped File Readable, Writable, Executable False False False
wlanapi.dll 0x71e90000 0x71ea5fff Memory Mapped File Readable, Writable, Executable False False False
wer.dll 0x71eb0000 0x71f10fff Memory Mapped File Readable, Writable, Executable False False False
gameux.dll 0x71f20000 0x72197fff Memory Mapped File Readable, Writable, Executable False False False
linkinfo.dll 0x721f0000 0x721f8fff Memory Mapped File Readable, Writable, Executable False False False
shdocvw.dll 0x72200000 0x7222dfff Memory Mapped File Readable, Writable, Executable False False False
actxprxy.dll 0x72310000 0x7235dfff Memory Mapped File Readable, Writable, Executable False False False
dhcpcsvc.dll 0x72430000 0x72441fff Memory Mapped File Readable, Writable, Executable False False False
dhcpcsvc6.dll 0x72450000 0x7245cfff Memory Mapped File Readable, Writable, Executable False False False
FWPUCLNT.DLL 0x72470000 0x724a7fff Memory Mapped File Readable, Writable, Executable False False False
FWPUCLNT.DLL 0x72470000 0x724a7fff Memory Mapped File Readable, Writable, Executable False False False
timedate.cpl 0x72820000 0x72897fff Memory Mapped File Readable, Writable, Executable False False False
IconCodecService.dll 0x728a0000 0x728a5fff Memory Mapped File Readable, Writable, Executable False False False
ntshrui.dll 0x728b0000 0x7291ffff Memory Mapped File Readable, Writable, Executable False False False
cscapi.dll 0x72920000 0x7292afff Memory Mapped File Readable, Writable, Executable False False False
cscdll.dll 0x72930000 0x72938fff Memory Mapped File Readable, Writable, Executable False False False
cscui.dll 0x72940000 0x729a9fff Memory Mapped File Readable, Writable, Executable False False False
EhStorShell.dll 0x729b0000 0x729e0fff Memory Mapped File Readable, Writable, Executable False False False
apphelp.dll 0x729f0000 0x72a3bfff Memory Mapped File Readable, Writable, Executable False False False
ExplorerFrame.dll 0x72a40000 0x72baefff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x72c80000 0x72c86fff Memory Mapped File Readable, Writable, Executable False False False
IPHLPAPI.DLL 0x72c90000 0x72cabfff Memory Mapped File Readable, Writable, Executable False False False
UIAnimation.dll 0x72f90000 0x72faafff Memory Mapped File Readable, Writable, Executable False False False
FXSRESM.dll 0x72fb0000 0x73092fff Memory Mapped File Readable, Writable, Executable False False False
FXSAPI.dll 0x730a0000 0x730d9fff Memory Mapped File Readable, Writable, Executable False False False
FXSST.dll 0x730e0000 0x731b1fff Memory Mapped File Readable, Writable, Executable False False False
webio.dll 0x731c0000 0x7320efff Memory Mapped File Readable, Writable, Executable False False False
winhttp.dll 0x73210000 0x73267fff Memory Mapped File Readable, Writable, Executable False False False
ncsi.dll 0x73270000 0x73297fff Memory Mapped File Readable, Writable, Executable False False False
security.dll 0x73270000 0x73272fff Memory Mapped File Readable, Writable, Executable False False False
olepro32.dll 0x73280000 0x73298fff Memory Mapped File Readable, Writable, Executable False False False
oleacc.dll 0x732a0000 0x732dbfff Memory Mapped File Readable, Writable, Executable False False False
bthprops.cpl 0x73320000 0x733cffff Memory Mapped File Readable, Writable, Executable False False False
ActionCenter.dll 0x733d0000 0x73489fff Memory Mapped File Readable, Writable, Executable False False False
cscobj.dll 0x73490000 0x734b4fff Memory Mapped File Readable, Writable, Executable False False False
QUTIL.DLL 0x73500000 0x73516fff Memory Mapped File Readable, Writable, Executable False False False
pnidui.dll 0x73520000 0x736cdfff Memory Mapped File Readable, Writable, Executable False False False
AltTab.dll 0x736d0000 0x736ddfff Memory Mapped File Readable, Writable, Executable False False False
PortableDeviceApi.dll 0x736e0000 0x73768fff Memory Mapped File Readable, Writable, Executable False False False
PortableDeviceTypes.dll 0x73770000 0x7379afff Memory Mapped File Readable, Writable, Executable False False False
WPDShServiceObj.dll 0x737a0000 0x737bcfff Memory Mapped File Readable, Writable, Executable False False False
netshell.dll 0x737d0000 0x73a34fff Memory Mapped File Readable, Writable, Executable False False False
ehSSO.dll 0x73a40000 0x73a47fff Memory Mapped File Readable, Writable, Executable False False False
DXP.dll 0x73a50000 0x73ab3fff Memory Mapped File Readable, Writable, Executable False False False
winspool.drv 0x73c90000 0x73ce0fff Memory Mapped File Readable, Writable, Executable False False False
prnfldr.dll 0x73cf0000 0x73d53fff Memory Mapped File Readable, Writable, Executable False False False
batmeter.dll 0x73d60000 0x73e16fff Memory Mapped File Readable, Writable, Executable False False False
es.dll 0x74010000 0x74056fff Memory Mapped File Readable, Writable, Executable False False False
slc.dll 0x74070000 0x74079fff Memory Mapped File Readable, Writable, Executable False False False
atl.dll 0x740a0000 0x740b3fff Memory Mapped File Readable, Writable, Executable False False False
nlaapi.dll 0x74130000 0x7413ffff Memory Mapped File Readable, Writable, Executable False False False
taskschd.dll 0x741e0000 0x7425cfff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x74320000 0x74340fff Memory Mapped File Readable, Writable, Executable False False False
avrt.dll 0x74370000 0x74376fff Memory Mapped File Readable, Writable, Executable False False False
powrprof.dll 0x74380000 0x743a4fff Memory Mapped File Readable, Writable, Executable False False False
Syncreg.dll 0x74430000 0x7443ffff Memory Mapped File Readable, Writable, Executable False False False
stobject.dll 0x74440000 0x74479fff Memory Mapped File Readable, Writable, Executable False False False
samcli.dll 0x74560000 0x7456efff Memory Mapped File Readable, Writable, Executable False False False
wkscli.dll 0x74570000 0x7457efff Memory Mapped File Readable, Writable, Executable False False False
netutils.dll 0x74580000 0x74588fff Memory Mapped File Readable, Writable, Executable False False False
wtsapi32.dll 0x74690000 0x7469cfff Memory Mapped File Readable, Writable, Executable False False False
WindowsCodecs.dll 0x746b0000 0x747aafff Memory Mapped File Readable, Writable, Executable False False False
xmllite.dll 0x747b0000 0x747defff Memory Mapped File Readable, Writable, Executable False False False
dwmapi.dll 0x747e0000 0x747f2fff Memory Mapped File Readable, Writable, Executable False False False
MMDevAPI.dll 0x74800000 0x74838fff Memory Mapped File Readable, Writable, Executable False False False
hid.dll 0x74840000 0x74848fff Memory Mapped File Readable, Writable, Executable False False False
SndVolSSO.dll 0x74850000 0x74887fff Memory Mapped File Readable, Writable, Executable False False False
duser.dll 0x74890000 0x748befff Memory Mapped File Readable, Writable, Executable False False False
dui70.dll 0x748c0000 0x74971fff Memory Mapped File Readable, Writable, Executable False False False
GdiPlus.dll 0x74980000 0x74b0ffff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x74b10000 0x74b4ffff Memory Mapped File Readable, Writable, Executable False False False
propsys.dll 0x74b50000 0x74c44fff Memory Mapped File Readable, Writable, Executable False False False
samlib.dll 0x74c50000 0x74c61fff Memory Mapped File Readable, Writable, Executable False False False
shacct.dll 0x74c70000 0x74c8dfff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x74c90000 0x74e2dfff Memory Mapped File Readable, Writable, Executable False False False
cryptui.dll 0x74e30000 0x74f27fff Memory Mapped File Readable, Writable, Executable False False False
authui.dll 0x74f30000 0x750e6fff Memory Mapped File Readable, Writable, Executable False False False
version.dll 0x75200000 0x75208fff Memory Mapped File Readable, Writable, Executable False False False
WSHTCPIP.DLL 0x75290000 0x75294fff Memory Mapped File Readable, Writable, Executable False False False
userenv.dll 0x75360000 0x75376fff Memory Mapped File Readable, Writable, Executable False False False
credssp.dll 0x75450000 0x75457fff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x75520000 0x7555afff Memory Mapped File Readable, Writable, Executable False False False
dnsapi.dll 0x75600000 0x75643fff Memory Mapped File Readable, Writable, Executable False False False
wship6.dll 0x75730000 0x75735fff Memory Mapped File Readable, Writable, Executable False False False
mswsock.dll 0x75740000 0x7577bfff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x75780000 0x75795fff Memory Mapped File Readable, Writable, Executable False False False
wevtapi.dll 0x75940000 0x75981fff Memory Mapped File Readable, Writable, Executable False False False
srvcli.dll 0x75b50000 0x75b68fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x75bc0000 0x75bc7fff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75be0000 0x75bfafff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x75c00000 0x75c0bfff Memory Mapped File Readable, Writable, Executable False False False
sxs.dll 0x75c10000 0x75c6efff Memory Mapped File Readable, Writable, Executable False False False
winsta.dll 0x75c70000 0x75c98fff Memory Mapped File Readable, Writable, Executable False False False
RpcRtRemote.dll 0x75ca0000 0x75cadfff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x75cb0000 0x75cbafff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x75d20000 0x75d2bfff Memory Mapped File Readable, Writable, Executable False False False
devobj.dll 0x75d30000 0x75d41fff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x75d50000 0x75e6cfff Memory Mapped File Readable, Writable, Executable False False False
wintrust.dll 0x75e70000 0x75e9cfff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75f30000 0x75f79fff Memory Mapped File Readable, Writable, Executable False False False
cfgmgr32.dll 0x75f80000 0x75fa6fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x75fb0000 0x75fcefff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x75fd0000 0x76004fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76010000 0x7605dfff Memory Mapped File Readable, Writable, Executable False False False
Wldap32.dll 0x76060000 0x760a4fff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76110000 0x761b0fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x761c0000 0x7626bfff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76270000 0x76338fff Memory Mapped File Readable, Writable, Executable False False False
setupapi.dll 0x76340000 0x764dcfff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x764e0000 0x77129fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x77130000 0x771cffff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x771d0000 0x772c4fff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x77380000 0x7757afff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77580000 0x7761cfff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x77620000 0x7777bfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x77780000 0x77853fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x77860000 0x778b6fff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x778c0000 0x779f5fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x77a00000 0x77a8efff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x77a90000 0x77b5bfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b60000 0x77c9bfff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x77ca0000 0x77ca5fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x77cb0000 0x77cb4fff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77cc0000 0x77cc9fff Memory Mapped File Readable, Writable, Executable False False False
normaliz.dll 0x77cd0000 0x77cd2fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77ce0000 0x77cf8fff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x77d00000 0x77d82fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77da0000 0x77da0fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
private_0x000000007ff9d000 0x7ff9d000 0x7ff9dfff Private Memory Readable, Writable True False False
private_0x000000007ff9e000 0x7ff9e000 0x7ff9efff Private Memory Readable, Writable True False False
private_0x000000007ff9f000 0x7ff9f000 0x7ff9ffff Private Memory Readable, Writable True False False
private_0x000000007ffa0000 0x7ffa0000 0x7ffa0fff Private Memory Readable, Writable True False False
private_0x000000007ffa1000 0x7ffa1000 0x7ffa1fff Private Memory Readable, Writable True False False
private_0x000000007ffa2000 0x7ffa2000 0x7ffa2fff Private Memory Readable, Writable True False False
private_0x000000007ffa3000 0x7ffa3000 0x7ffa3fff Private Memory Readable, Writable True False False
private_0x000000007ffa3000 0x7ffa3000 0x7ffa3fff Private Memory Readable, Writable True False False
private_0x000000007ffa4000 0x7ffa4000 0x7ffa4fff Private Memory Readable, Writable True False False
private_0x000000007ffa5000 0x7ffa5000 0x7ffa5fff Private Memory Readable, Writable True False False
private_0x000000007ffa6000 0x7ffa6000 0x7ffa6fff Private Memory Readable, Writable True False False
private_0x000000007ffa7000 0x7ffa7000 0x7ffa7fff Private Memory Readable, Writable True False False
private_0x000000007ffa8000 0x7ffa8000 0x7ffa8fff Private Memory Readable, Writable True False False
private_0x000000007ffa8000 0x7ffa8000 0x7ffa8fff Private Memory Readable, Writable True False False
private_0x000000007ffa9000 0x7ffa9000 0x7ffa9fff Private Memory Readable, Writable True False False
private_0x000000007ffa9000 0x7ffa9000 0x7ffa9fff Private Memory Readable, Writable True False False
private_0x000000007ffaa000 0x7ffaa000 0x7ffaafff Private Memory Readable, Writable True False False
private_0x000000007ffab000 0x7ffab000 0x7ffabfff Private Memory Readable, Writable True False False
private_0x000000007ffac000 0x7ffac000 0x7ffacfff Private Memory Readable, Writable True False False
private_0x000000007ffad000 0x7ffad000 0x7ffadfff Private Memory Readable, Writable True False False
private_0x000000007ffae000 0x7ffae000 0x7ffaefff Private Memory Readable, Writable True False False
private_0x000000007ffaf000 0x7ffaf000 0x7ffaffff Private Memory Readable, Writable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffd3000 0x7ffd3000 0x7ffd3fff Private Memory Readable, Writable True False False
private_0x000000007ffd4000 0x7ffd4000 0x7ffd4fff Private Memory Readable, Writable True False False
private_0x000000007ffd5000 0x7ffd5000 0x7ffd5fff Private Memory Readable, Writable True False False
private_0x000000007ffd6000 0x7ffd6000 0x7ffd6fff Private Memory Readable, Writable True False False
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory Readable, Writable True False False
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory Readable, Writable True False False
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory Readable, Writable True False False
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory Readable, Writable True False False
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory Readable, Writable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Injection Information
+
Injection Type Source Process Source Os Thread ID Injection Info Success Count Logfile
Modify Memory c:\windows\system32\regsvr32.exe 0x578 address = 0x3140000, size = 66 True 1
Fn
Data
Create Remote Thread c:\windows\system32\regsvr32.exe 0x578 os_thread_id = 0x628, address = 0x777d3c01, flags = THREAD_RUNS_IMMEDIATELY True 1
Fn
Host Behavior
File (6)
+
Operation Filename Additional Information Success Count Logfile
CREATE c:\users\public\n3eg\n3eg1.51n3e desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
CREATE c:\users\public\n3eg\wvs desired_access = GENERIC_WRITE, GENERIC_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
READ c:\users\public\n3eg\n3eg1.51n3e size = 2689537 True 1
Fn
WRITE c:\users\public\n3eg\wvs size = 4 True 1
Fn
Data
DELETE c:\users\public\n3eg\n3e.vbs True 1
Fn
DELETE c:\users\public\n3eg\n3e.vbs False 1
Fn
Module (750)
+
Operation Module Additional Information Success Count Logfile
LOAD C:\Users\Public\N3Eg\N3Eg4.ENU base_address = 0x0 False 1
Fn
LOAD C:\Users\Public\N3Eg\N3Eg4.EN base_address = 0x0 False 1
Fn
LOAD oleaut32.dll base_address = 0x77a00000 True 3
Fn
LOAD advapi32.dll base_address = 0x77130000 True 2
Fn
LOAD user32.dll base_address = 0x76270000 True 4
Fn
LOAD kernel32.dll base_address = 0x77780000 True 6
Fn
LOAD gdi32.dll base_address = 0x76010000 True 1
Fn
LOAD version.dll base_address = 0x75200000 True 1
Fn
LOAD ole32.dll base_address = 0x77620000 True 1
Fn
LOAD comctl32.dll base_address = 0x74c90000 True 1
Fn
LOAD msvcrt.dll base_address = 0x761c0000 True 1
Fn
LOAD shell32.dll base_address = 0x764e0000 True 1
Fn
LOAD wininet.dll base_address = 0x771d0000 True 1
Fn
LOAD oleacc.dll base_address = 0x732a0000 True 1
Fn
LOAD OLEACC.DLL base_address = 0x732a0000 True 1
Fn
LOAD imm32.dll base_address = 0x75fb0000 True 2
Fn
LOAD olepro32.dll base_address = 0x73280000 True 1
Fn
LOAD security.dll base_address = 0x73270000 True 1
Fn
LOAD wtsapi32.dll base_address = 0x74690000 True 1
Fn
LOAD uxtheme.dll base_address = 0x74b10000 True 2
Fn
LOAD WS2_32.DLL base_address = 0x75fd0000 True 1
Fn
LOAD Fwpuclnt.dll base_address = 0x72470000 True 1
Fn
LOAD IdnDL.dll base_address = 0x6ee90000 True 1
Fn
LOAD Normaliz.dll base_address = 0x77cd0000 True 1
Fn
GET_HANDLE c:\windows\system32\kernel32.dll base_address = 0x77780000 True 8
Fn
GET_HANDLE c:\windows\system32\oleaut32.dll base_address = 0x77a00000 True 2
Fn
GET_HANDLE c:\windows\system32\ole32.dll base_address = 0x77620000 True 1
Fn
GET_HANDLE c:\windows\system32\user32.dll base_address = 0x76270000 True 3
Fn
GET_HANDLE c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll base_address = 0x74c90000 True 1
Fn
GET_FILENAME C:\Users\Public\N3Eg\N3Eg4.51N3E True 1
Fn
GET_FILENAME C:\Windows\Explorer.EXE True 3
Fn
GET_FILENAME False 1
Fn
GET_FILENAME C:\Windows\Explorer.EXE True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetDiskFreeSpaceExA, address = 0x7780f46f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VariantChangeTypeEx, address = 0x77a04c28 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarNeg, address = 0x77a7c802 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarNot, address = 0x77a7ec66 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarAdd, address = 0x77a25934 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarSub, address = 0x77a7d332 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarMul, address = 0x77a7dbd4 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarDiv, address = 0x77a7e405 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarIdiv, address = 0x77a7f00a True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarMod, address = 0x77a7f15e True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarAnd, address = 0x77a25a98 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarOr, address = 0x77a7ecfa True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarXor, address = 0x77a7ee2e True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarCmp, address = 0x77a1b0dc True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarI4FromStr, address = 0x77a16fab True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarR4FromStr, address = 0x77a201a0 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarR8FromStr, address = 0x77a1699e True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarDateFromStr, address = 0x77a26ba7 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarCyFromStr, address = 0x77a46c12 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarBoolFromStr, address = 0x77a1dbd1 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarBstrFromCy, address = 0x77a27fdc True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarBstrFromDate, address = 0x77a17a2a True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VarBstrFromBool, address = 0x77a20355 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = SysFreeString, address = 0x77a03e59 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = SysReAllocStringLen, address = 0x77a07810 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = SysAllocStringLen, address = 0x77a045d2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = RegQueryValueExW, address = 0x771446ad True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = RegOpenKeyExW, address = 0x7714468d True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = RegCloseKey, address = 0x7714469d True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MessageBoxA, address = 0x762cea11 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CharNextW, address = 0x76280be6 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = LoadStringW, address = 0x7627dfba True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = Sleep, address = 0x777cba46 True 3
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = VirtualFree, address = 0x777d1da4 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = VirtualAlloc, address = 0x777d2fb6 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = lstrlenW, address = 0x777cd9e8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = VirtualQuery, address = 0x777d76d6 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = QueryPerformanceCounter, address = 0x777cbb9f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetTickCount, address = 0x777cba60 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetSystemInfo, address = 0x777d3728 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetVersion, address = 0x777c154e True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CompareStringW, address = 0x777c9bee True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = IsValidLocale, address = 0x777c3de4 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetThreadLocale, address = 0x777e88e6 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetSystemDefaultUILanguage, address = 0x777b731d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetUserDefaultUILanguage, address = 0x777c22ef True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetLocaleInfoW, address = 0x777d6596 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WideCharToMultiByte, address = 0x777d450e True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = MultiByteToWideChar, address = 0x777d452b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetACP, address = 0x777d39aa True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LoadLibraryExW, address = 0x777c4775 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetStartupInfoW, address = 0x777d3891 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetProcAddress, address = 0x777d33d3 True 3
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetModuleHandleW, address = 0x777d374d True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetModuleFileNameW, address = 0x777d3c26 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetCommandLineW, address = 0x777d679e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FreeLibrary, address = 0x777cd9d0 True 3
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetLastError, address = 0x777cbf00 True 3
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = UnhandledExceptionFilter, address = 0x777ded38 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = RtlUnwind, address = 0x777b7f70 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = RaiseException, address = 0x777beb60 True 3
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = ExitProcess, address = 0x777d214f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = ExitThread, address = 0x77b8f611 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SwitchToThread, address = 0x777beb24 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetCurrentThreadId, address = 0x777cbb80 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CreateThread, address = 0x777d375d True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = DeleteCriticalSection, address = 0x77bb9ac5 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LeaveCriticalSection, address = 0x77ba7760 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = EnterCriticalSection, address = 0x77ba77a0 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = InitializeCriticalSection, address = 0x77bba149 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FindFirstFileW, address = 0x777d53b2 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FindClose, address = 0x777d0e62 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WriteFile, address = 0x777d1400 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetStdHandle, address = 0x777d1e46 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CloseHandle, address = 0x777cca7c True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LoadLibraryA, address = 0x777d395c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = TlsSetValue, address = 0x777cda88 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = TlsGetValue, address = 0x777cda70 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = TlsFree, address = 0x777d13b8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = TlsAlloc, address = 0x777d35a1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LocalFree, address = 0x777cca64 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LocalAlloc, address = 0x777d3363 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetClassLongW, address = 0x7627658b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetClassLongW, address = 0x76283860 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetWindowLongW, address = 0x76284449 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetWindowLongW, address = 0x762861b8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CreateWindowExW, address = 0x7627ec7c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = keybd_event, address = 0x762cec3b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = WindowFromPoint, address = 0x762a6be9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = WaitMessage, address = 0x762866bd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = WaitForInputIdle, address = 0x762a0397 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = UpdateWindow, address = 0x7627ffa8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = UnregisterClassW, address = 0x7627b9ae True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = UnhookWindowsHookEx, address = 0x7627adf9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = TranslateMessage, address = 0x762864c7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = TranslateMDISysAccel, address = 0x762a1a5a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = TrackPopupMenu, address = 0x76292228 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SystemParametersInfoW, address = 0x7627e09a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SwitchDesktop, address = 0x7627476b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ShowWindow, address = 0x7627f2a9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ShowScrollBar, address = 0x762a3c89 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ShowOwnedPopups, address = 0x762a28ca True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ShowCaret, address = 0x76279334 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetWindowRgn, address = 0x762799ec True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetWindowsHookExW, address = 0x7627e30c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetWindowTextW, address = 0x7628612b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetWindowPos, address = 0x76281bc4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetWindowPlacement, address = 0x76277f78 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetTimer, address = 0x762852ef True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetScrollRange, address = 0x76278ec5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetScrollPos, address = 0x762a04be True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetScrollInfo, address = 0x762848da True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetRect, address = 0x7628498b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetPropW, address = 0x76285dc5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetParent, address = 0x76278314 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetMenuItemInfoW, address = 0x76281799 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetMenu, address = 0x762a6b0e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetKeyboardState, address = 0x762a695a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetForegroundWindow, address = 0x7627b225 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetFocus, address = 0x7627abad True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetCursorPos, address = 0x762bc1b0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetCursor, address = 0x76283075 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetCapture, address = 0x762a6932 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetActiveWindow, address = 0x7628333a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SendMessageTimeoutW, address = 0x7627e459 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SendMessageA, address = 0x7627ad60 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SendMessageW, address = 0x76285539 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ScrollWindow, address = 0x7629fc1d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ScreenToClient, address = 0x7627a506 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = RemovePropW, address = 0x76285fe1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = RemoveMenu, address = 0x762786e8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ReleaseDC, address = 0x76285421 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ReleaseCapture, address = 0x762a69f2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = RegisterWindowMessageW, address = 0x7627df8d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = RegisterClipboardFormatW, address = 0x7627df8d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = RegisterClassW, address = 0x7627ed4a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = RedrawWindow, address = 0x762829bc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = PostQuitMessage, address = 0x7627b308 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = PostMessageW, address = 0x7628447b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = PeekMessageA, address = 0x762819a5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = PeekMessageW, address = 0x7628634a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = OpenDesktopW, address = 0x7627c669 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MsgWaitForMultipleObjectsEx, address = 0x7627e369 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MsgWaitForMultipleObjects, address = 0x762837d8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MoveWindow, address = 0x76278d29 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MessageBoxW, address = 0x762cea5f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MessageBeep, address = 0x762a2939 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MapWindowPoints, address = 0x76285caa True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MapVirtualKeyW, address = 0x762a6a7c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = LoadKeyboardLayoutW, address = 0x762bc874 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = LoadIconW, address = 0x7627f142 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = LoadCursorW, address = 0x7627ed90 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = LoadBitmapW, address = 0x76276460 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = KillTimer, address = 0x762864f7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsZoomed, address = 0x76284ce9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsWindowVisible, address = 0x76284d69 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsWindowUnicode, address = 0x76282f55 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsWindowEnabled, address = 0x7627a9b9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsWindow, address = 0x762853ba True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsIconic, address = 0x76284c8e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsDialogMessageA, address = 0x76292019 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsDialogMessageW, address = 0x76284104 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsChild, address = 0x76283a83 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = InvalidateRect, address = 0x7628566d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = InsertMenuItemW, address = 0x7627aac5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = InsertMenuW, address = 0x7627869a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = HideCaret, address = 0x76279348 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetWindowThreadProcessId, address = 0x7627ee32 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetWindowTextW, address = 0x7627b8c5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetWindowRect, address = 0x7628558c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetWindowPlacement, address = 0x762a69de True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetWindowDC, address = 0x76284ab7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetTopWindow, address = 0x762a24d9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetSystemMetrics, address = 0x762867cf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetSystemMenu, address = 0x7627fd8b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetSysColorBrush, address = 0x7627f1ed True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetSysColor, address = 0x7628db7a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetSubMenu, address = 0x76279c19 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetScrollRange, address = 0x762a045a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetScrollPos, address = 0x762a0e43 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetScrollInfo, address = 0x76282da3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetPropW, address = 0x76285bbe True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetParent, address = 0x76286029 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetWindow, address = 0x76282780 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMessageTime, address = 0x762a4231 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMessagePos, address = 0x762a6703 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMessageExtraInfo, address = 0x7627b705 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMenuStringW, address = 0x762a6528 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMenuState, address = 0x762a67d2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMenuItemInfoW, address = 0x7627aefa True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMenuItemID, address = 0x76279cd4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMenuItemCount, address = 0x7627ae39 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMenu, address = 0x762a6b68 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetLastActivePopup, address = 0x762a6894 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetKeyboardState, address = 0x762a6946 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetKeyboardLayoutNameW, address = 0x762bfa13 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetKeyboardLayoutList, address = 0x7627935c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetKeyboardLayout, address = 0x76283800 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetKeyState, address = 0x76282b4d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetKeyNameTextW, address = 0x762bfa03 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetIconInfo, address = 0x76282989 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetGUIThreadInfo, address = 0x7628237e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetForegroundWindow, address = 0x7628335d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetFocus, address = 0x76283a34 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetDlgCtrlID, address = 0x7627b4e8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetDesktopWindow, address = 0x762801a9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetDCEx, address = 0x76282d57 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetDC, address = 0x7628544c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetCursorPos, address = 0x7627a4b3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetCursor, address = 0x762a6408 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetClipboardData, address = 0x76292ba7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetClientRect, address = 0x762854dd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetClassNameW, address = 0x76282a29 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetClassInfoExW, address = 0x7628095e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetClassInfoW, address = 0x76280ac2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetCapture, address = 0x76279dc7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetActiveWindow, address = 0x762a3b33 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = FrameRect, address = 0x762a0eb0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = FindWindowExW, address = 0x762a712b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = FindWindowW, address = 0x7627ae0d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = FillRect, address = 0x76285d56 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EnumWindows, address = 0x7628375b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EnumThreadWindows, address = 0x7627b712 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EnumChildWindows, address = 0x76282948 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EndPaint, address = 0x76285d42 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EndMenu, address = 0x76278302 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EnableWindow, address = 0x76278d02 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EnableScrollBar, address = 0x762a19ce True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EnableMenuItem, address = 0x762a43bc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DrawTextExW, address = 0x76285894 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DrawTextW, address = 0x76285b6a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DrawMenuBar, address = 0x762a15ae True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DrawIconEx, address = 0x76282c32 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DrawIcon, address = 0x76276427 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DrawFrameControl, address = 0x7629b4f9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DrawFocusRect, address = 0x762a3091 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DrawEdge, address = 0x7628311a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DispatchMessageA, address = 0x76282e32 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DispatchMessageW, address = 0x7628cc61 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DestroyWindow, address = 0x7627b2f4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DestroyMenu, address = 0x762787f7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DestroyIcon, address = 0x7627a77f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DestroyCursor, address = 0x7627a77f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DeleteMenu, address = 0x762783c2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DefWindowProcW, address = 0x7628507d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DefMDIChildProcW, address = 0x762a150a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = DefFrameProcW, address = 0x762a152b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CreatePopupMenu, address = 0x7627867c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CreateMenu, address = 0x762a6aed True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CreateIcon, address = 0x76297510 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CreateDesktopW, address = 0x762740cf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CopyImage, address = 0x762787a6 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CloseDesktop, address = 0x7627c4ce True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ClientToScreen, address = 0x76281316 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CheckMenuItem, address = 0x7629ee7c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CharUpperBuffW, address = 0x7628ebd5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CharUpperW, address = 0x7628e981 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CharLowerBuffW, address = 0x76283afe True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CharLowerW, address = 0x7627ba8a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CallWindowProcW, address = 0x76281b3c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = CallNextHookEx, address = 0x7627abe1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = BeginPaint, address = 0x76285d14 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = AdjustWindowRectEx, address = 0x762848ba True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = ActivateKeyboardLayout, address = 0x76278203 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = UnrealizeObject, address = 0x7601fb63 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = StretchBlt, address = 0x7601f467 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetWindowOrgEx, address = 0x76018546 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetWinMetaFileBits, address = 0x7604d957 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetViewportOrgEx, address = 0x7601834f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetTextColor, address = 0x76016906 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetStretchBltMode, address = 0x76017705 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetROP2, address = 0x7601f9e0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetPixel, address = 0x760314f3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetMapMode, address = 0x7601efbf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetEnhMetaFileBits, address = 0x7602b380 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetDIBits, address = 0x7601a995 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetDIBColorTable, address = 0x76031492 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetBrushOrgEx, address = 0x7601c4c5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetBkMode, address = 0x760169b1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SetBkColor, address = 0x76016a3c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SelectPalette, address = 0x7601a1f6 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SelectObject, address = 0x76016640 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = SaveDC, address = 0x7601a74b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = RoundRect, address = 0x7603016d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = RestoreDC, address = 0x7601a67b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = Rectangle, address = 0x7601f1ff True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = RectVisible, address = 0x76018f13 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = RealizePalette, address = 0x7601ef91 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = Polyline, address = 0x760205cf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = Polygon, address = 0x7601fb87 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = PolyBezierTo, address = 0x76046c25 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = PolyBezier, address = 0x76046b03 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = PlayEnhMetaFile, address = 0x7602990d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = Pie, address = 0x7604569f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = PatBlt, address = 0x760162af True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = MoveToEx, address = 0x76018c21 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = MaskBlt, address = 0x7601c7ad True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = LineTo, address = 0x7601f59b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = LPtoDP, address = 0x76018484 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = IntersectClipRect, address = 0x76017dfe True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetWindowOrgEx, address = 0x7601d1bf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetWinMetaFileBits, address = 0x7604d7cb True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetTextMetricsW, address = 0x76017b8f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetTextExtentPointW, address = 0x7601b358 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetTextExtentPoint32W, address = 0x7601b4b5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetSystemPaletteEntries, address = 0x7601c2e1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetStockObject, address = 0x76015ddf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetRgnBox, address = 0x7601621f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetPixel, address = 0x7601c3d5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetPaletteEntries, address = 0x7601c2aa True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetObjectW, address = 0x76017568 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetEnhMetaFilePaletteEntries, address = 0x7604d1ac True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetEnhMetaFileHeader, address = 0x7602cd3a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetEnhMetaFileDescriptionW, address = 0x7604dc6b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetEnhMetaFileBits, address = 0x7602cdc8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetDeviceCaps, address = 0x76016f7f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetDIBits, address = 0x7601a23b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetDIBColorTable, address = 0x7601a149 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetCurrentPositionEx, address = 0x76018d78 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetClipBox, address = 0x76018525 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetBrushOrgEx, address = 0x7601c943 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GetBitmapBits, address = 0x7601c1ba True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = GdiFlush, address = 0x76015fe4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = FrameRgn, address = 0x76045ae2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = ExtTextOutW, address = 0x76018192 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = ExtFloodFill, address = 0x7602fd94 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = ExcludeClipRect, address = 0x76019218 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = EnumFontFamiliesExW, address = 0x7601ce94 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = Ellipse, address = 0x760455e3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = DeleteObject, address = 0x76015f14 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = DeleteEnhMetaFile, address = 0x7602bda2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = DeleteDC, address = 0x76016eaa True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateSolidBrush, address = 0x76016b49 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateRectRgn, address = 0x7601633b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreatePenIndirect, address = 0x7602744d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreatePalette, address = 0x7601b1b0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateHalftonePalette, address = 0x7601c2cd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateFontIndirectW, address = 0x7601abfc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateEnhMetaFileW, address = 0x7602cc1f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateDIBitmap, address = 0x7601a379 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateDIBSection, address = 0x76018850 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateCompatibleDC, address = 0x76016888 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateCompatibleBitmap, address = 0x760173ad True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateBrushIndirect, address = 0x7601993c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CreateBitmap, address = 0x76016b79 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CopyEnhMetaFileW, address = 0x7604d651 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CombineRgn, address = 0x7601651e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = CloseEnhMetaFile, address = 0x7602c3fe True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = Chord, address = 0x760454fa True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = BitBlt, address = 0x760172c0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = ArcTo, address = 0x76045436 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = Arc, address = 0x7604534e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\gdi32.dll function = AngleArc, address = 0x76045299 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\version.dll function = VerQueryValueW, address = 0x75201b51 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\version.dll function = GetFileVersionInfoSizeW, address = 0x752019d9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\version.dll function = GetFileVersionInfoW, address = 0x752019f4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WinExec, address = 0x7780e5fd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WaitForSingleObject, address = 0x777cba90 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WaitForMultipleObjectsEx, address = 0x777cbc00 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = VirtualQueryEx, address = 0x777b4e42 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = VirtualProtect, address = 0x777c2341 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SuspendThread, address = 0x777e0ca9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SizeofResource, address = 0x777c3e7f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetThreadPriority, address = 0x777c4815 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetLastError, address = 0x777cbb08 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetFilePointer, address = 0x777cdb36 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetEvent, address = 0x777cbccc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetErrorMode, address = 0x777d4a51 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetEndOfFile, address = 0x777c2319 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = ResumeThread, address = 0x777c0f1c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = ResetEvent, address = 0x777cbcb4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = RemoveDirectoryW, address = 0x777b586a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = ReadFile, address = 0x777c96fb True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = IsDebuggerPresent, address = 0x777c3ea8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = OpenProcess, address = 0x777c59d7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = MulDiv, address = 0x777cb7a0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LockResource, address = 0x777bfd29 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LoadResource, address = 0x777c984d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = LoadLibraryW, address = 0x777d3c01 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = HeapFree, address = 0x777cbbd0 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = HeapDestroy, address = 0x777c2301 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = HeapCreate, address = 0x777d3ea2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = HeapAlloc, address = 0x77bb2dd6 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GlobalUnlock, address = 0x777c9d50 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GlobalSize, address = 0x777beb78 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GlobalLock, address = 0x777c9e05 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GlobalFree, address = 0x777c9cf9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GlobalFindAtomW, address = 0x777c912d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GlobalDeleteAtom, address = 0x777bf16c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GlobalAlloc, address = 0x777c9ce1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GlobalAddAtomW, address = 0x777c70f9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetVolumeInformationW, address = 0x777d7598 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetVersionExW, address = 0x777c3b1a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetUserDefaultLCID, address = 0x777d6584 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetTimeZoneInformation, address = 0x777b8a3b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetThreadPriority, address = 0x777c9147 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetThreadLocale, address = 0x777c153c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetTempPathW, address = 0x777b8b33 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetLocalTime, address = 0x777ca90e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetFullPathNameW, address = 0x777d4543 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetFileSize, address = 0x777c0273 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetFileAttributesW, address = 0x777d64ff True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetExitCodeThread, address = 0x777b6ddd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetEnvironmentVariableW, address = 0x777d65c4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetDiskFreeSpaceW, address = 0x777b3530 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetDateFormatW, address = 0x777cafab True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetCurrentThread, address = 0x777d3351 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetCurrentProcessId, address = 0x777ccac4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetCurrentProcess, address = 0x777ccdcf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetComputerNameW, address = 0x777c03ff True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetCPInfoExW, address = 0x777b8b1b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetCPInfo, address = 0x777d1e2e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FreeResource, address = 0x777bf1bd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = InterlockedExchange, address = 0x777cbf0a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = InterlockedCompareExchange, address = 0x777cbb92 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FormatMessageW, address = 0x777c54a3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FindResourceW, address = 0x777c3e61 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FindNextFileW, address = 0x777c963a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FileTimeToLocalFileTime, address = 0x777d2004 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = FileTimeToDosDateTime, address = 0x777c2ce1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = EnumSystemLocalesW, address = 0x7780f3df True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = EnumCalendarInfoW, address = 0x7780f38f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = DeleteFileW, address = 0x777c0f62 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CreateProcessW, address = 0x7778204d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CreateFileW, address = 0x777ccc56 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CreateEventW, address = 0x777d3386 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = CreateDirectoryW, address = 0x777c3925 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = RegSetValueExW, address = 0x771414d6 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = RegQueryInfoKeyW, address = 0x771446e7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = RegFlushKey, address = 0x7715773f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = RegEnumKeyExW, address = 0x771446c8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = RegCreateKeyExW, address = 0x771440fe True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\advapi32.dll function = GetUserNameW, address = 0x7714157a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = SafeArrayPtrOfIndex, address = 0x77a1e1ce True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = SafeArrayGetUBound, address = 0x77a1e127 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = SafeArrayGetLBound, address = 0x77a1e173 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = SafeArrayCreate, address = 0x77a1e263 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VariantChangeType, address = 0x77a05dee True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VariantCopyInd, address = 0x77a1e86c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VariantCopy, address = 0x77a048f1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VariantClear, address = 0x77a03eae True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = VariantInit, address = 0x77a03ed5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = GetErrorInfo, address = 0x77a03f21 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleaut32.dll function = GetActiveObject, address = 0x77a48f58 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CreateStreamOnHGlobal, address = 0x7764363b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = IsAccelerator, address = 0x776e043e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = OleDraw, address = 0x776a0286 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = OleSetMenuDescriptor, address = 0x7767dc53 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = OleUninitialize, address = 0x7763eba1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = OleInitialize, address = 0x7763efd7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoTaskMemFree, address = 0x77676f41 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoTaskMemAlloc, address = 0x7766ea4c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = ProgIDFromCLSID, address = 0x776aef82 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = StringFromCLSID, address = 0x7763eb17 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoCreateInstance, address = 0x77669d0b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoGetClassObject, address = 0x776554ad True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoUninitialize, address = 0x776686d3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoInitialize, address = 0x7763b636 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = IsEqualGUID, address = 0x776e041c True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = InitializeFlatSB, address = 0x74d6f803 True 2
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_SetScrollProp, address = 0x74d107d0 True 2
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_SetScrollPos, address = 0x74d10894 True 2
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_SetScrollInfo, address = 0x74d108c7 True 2
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_GetScrollPos, address = 0x74d6f80e True 2
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_GetScrollInfo, address = 0x74d108b6 True 2
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = _TrackMouseEvent, address = 0x74d122d1 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_SetIconSize, address = 0x74d7b44e True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_GetIconSize, address = 0x74ca50df True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_Write, address = 0x74cd8b97 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_Read, address = 0x74c93eae True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_GetDragImage, address = 0x74d7afbb True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_DragShowNolock, address = 0x74d7b161 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_DragMove, address = 0x74d7b0f0 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_DragLeave, address = 0x74d7b12a True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_DragEnter, address = 0x74d7b0b3 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_EndDrag, address = 0x74d7a177 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_BeginDrag, address = 0x74d7b021 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_GetIcon, address = 0x74cbaf2e True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_Remove, address = 0x74cbe333 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_DrawEx, address = 0x74ca10fd True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_Draw, address = 0x74d2c687 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_GetBkColor, address = 0x74cae8d2 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_SetBkColor, address = 0x74d10183 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_Add, address = 0x74ce8fa1 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_SetImageCount, address = 0x74ce5249 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_GetImageCount, address = 0x74c9a8b9 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_Destroy, address = 0x74ca6471 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = ImageList_Create, address = 0x74ca3c75 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = EnumDisplayMonitors, address = 0x762834a3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetMonitorInfoW, address = 0x762833e7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MonitorFromPoint, address = 0x762794c9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = MonitorFromWindow, address = 0x76283622 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\msvcrt.dll function = memset, address = 0x761c9790 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\msvcrt.dll function = memcpy, address = 0x761c9910 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\shell32.dll function = ShellExecuteW, address = 0x764f3c71 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\shell32.dll function = Shell_NotifyIconW, address = 0x765001c1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\wininet.dll function = FindNextUrlCacheEntryW, address = 0x7720989c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\wininet.dll function = FindFirstUrlCacheEntryW, address = 0x7720978a True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\wininet.dll function = FindCloseUrlCache, address = 0x77218409 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\wininet.dll function = DeleteUrlCacheEntryW, address = 0x77229573 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GetRawInputData, address = 0x762d4c21 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = RegisterRawInputDevices, address = 0x76275b52 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleacc.dll function = AccessibleObjectFromWindow, address = 0x732a2480 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\oleacc.dll function = AccessibleChildren, address = 0x732a5d25 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetThreadPreferredUILanguages, address = 0x777c22d7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SetThreadPreferredUILanguages, address = 0x777be627 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetThreadUILanguage, address = 0x777bae42 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetNativeSystemInfo, address = 0x777bbe77 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetDiskFreeSpaceExW, address = 0x777bde40 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = InitializeConditionVariable, address = 0x77bb9981 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WakeConditionVariable, address = 0x77c05a7b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = WakeAllConditionVariable, address = 0x77b845a5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = SleepConditionVariableCS, address = 0x777b18be True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetLogicalProcessorInformation, address = 0x777b2004 True 2
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoCreateInstanceEx, address = 0x77669d4e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoInitializeEx, address = 0x776609ad True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoAddRefServerProcess, address = 0x77683cf3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoReleaseServerProcess, address = 0x77684314 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoResumeClassObjects, address = 0x7762ea02 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ole32.dll function = CoSuspendClassObjects, address = 0x7768bb02 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\imm32.dll function = ImmIsIME, address = 0x75fb2ceb True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = AnimateWindow, address = 0x762a0620 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = UninitializeFlatSB, address = 0x74c9d1ea True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_GetScrollProp, address = 0x74d6f81f True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_EnableScrollBar, address = 0x74d6f84b True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_ShowScrollBar, address = 0x74d6f83a True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_GetScrollRange, address = 0x74d6f829 True 1
Fn
GET_PROC_ADDRESS c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll function = FlatSB_SetScrollRange, address = 0x74d108a5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = SetLayeredWindowAttributes, address = 0x7627a6dc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = IsHungAppWindow, address = 0x762a7195 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = HungWindowFromGhostWindow, address = 0x762961f5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\user32.dll function = GhostWindowFromHungWindow, address = 0x7627a561 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ncsi.dll function = OleCreatePropertyFrame, address = 0x732820ea True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ncsi.dll function = OleCreateFontIndirect, address = 0x732820b7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ncsi.dll function = OleCreatePictureIndirect, address = 0x732820c8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ncsi.dll function = OleLoadPicture, address = 0x732820d9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\kernel32.dll function = GetFileSizeEx, address = 0x777c59ef True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ncsi.dll function = InitSecurityInterfaceW, address = 0x75be5b53 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\wtsapi32.dll function = WTSRegisterSessionNotification, address = 0x74691cbc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = BufferedPaintInit, address = 0x74b1940e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = OpenThemeData, address = 0x74b173d2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = CloseThemeData, address = 0x74b16a18 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = DrawThemeBackground, address = 0x74b13982 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = DrawThemeText, address = 0x74b14ea1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeBackgroundContentRect, address = 0x74b1cd2e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeBackgroundExtent, address = 0x74b1f8bf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemePartSize, address = 0x74b1cdb1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeTextExtent, address = 0x74b12d57 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeTextMetrics, address = 0x74b1f992 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeBackgroundRegion, address = 0x74b2165d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = HitTestThemeBackground, address = 0x74b23ce3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = DrawThemeEdge, address = 0x74b33b52 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = DrawThemeIcon, address = 0x74b435e7 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = IsThemePartDefined, address = 0x74b185b4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = IsThemeBackgroundPartiallyTransparent, address = 0x74b160ab True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeColor, address = 0x74b1616c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeMetric, address = 0x74b206e2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeString, address = 0x74b422e4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeBool, address = 0x74b17c1f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeInt, address = 0x74b1616c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeEnumValue, address = 0x74b1616c True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemePosition, address = 0x74b42350 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeFont, address = 0x74b1ff21 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeRect, address = 0x74b23611 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeMargins, address = 0x74b186e9 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeIntList, address = 0x74b423b1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemePropertyOrigin, address = 0x74b33fbb True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = SetWindowTheme, address = 0x74b20134 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeFilename, address = 0x74b42412 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeSysColor, address = 0x74b33274 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeSysColorBrush, address = 0x74b4301e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeSysBool, address = 0x74b43172 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeSysSize, address = 0x74b4320b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeSysFont, address = 0x74b429c4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeSysString, address = 0x74b42b3f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeSysInt, address = 0x74b42bd3 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = IsThemeActive, address = 0x74b1f785 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = IsAppThemed, address = 0x74b1f869 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetWindowTheme, address = 0x74b1df46 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = EnableThemeDialogTexture, address = 0x74b1fcaf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = IsThemeDialogTextureEnabled, address = 0x74b4312b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeAppProperties, address = 0x74b20fb1 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = SetThemeAppProperties, address = 0x74b43296 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetCurrentThemeName, address = 0x74b205dd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = GetThemeDocumentationProperty, address = 0x74b42932 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = DrawThemeParentBackground, address = 0x74b153e5 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = EnableTheming, address = 0x74b42feb True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\uxtheme.dll function = DrawThemeTextEx, address = 0x74b163e6 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = WSAStartup, address = 0x75fd3ab2 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = GetAddrInfoW, address = 0x75fd4889 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = GetNameInfoW, address = 0x75fd66af True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = FreeAddrInfoW, address = 0x75fd4b1b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = InetPtonW, address = 0x75fe39dc True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = InetNtopW, address = 0x75fe3abf True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = GetAddrInfoExW, address = 0x75fdd1ea True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = SetAddrInfoExW, address = 0x75fdf4f6 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = FreeAddrInfoExW, address = 0x75fde14d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\fwpuclnt.dll function = WSASetSocketPeerTargetName, address = 0x7248bb1e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\fwpuclnt.dll function = WSADeleteSocketPeerTargetName, address = 0x7248bb4e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\fwpuclnt.dll function = WSAImpersonateSocketPeer, address = 0x7248bb7e True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\fwpuclnt.dll function = WSAQuerySocketSecurity, address = 0x7248baed True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\fwpuclnt.dll function = WSARevertImpersonation, address = 0x7248bcfd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\idndl.dll function = DownlevelGetLocaleScripts, address = 0x6ee92a5b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\idndl.dll function = DownlevelGetStringScripts, address = 0x6ee92b2f True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\idndl.dll function = DownlevelVerifyScripts, address = 0x6ee92dad True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\normaliz.dll function = IdnToUnicode, address = 0x7781f707 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\normaliz.dll function = IdnToNameprepUnicode, address = 0x7781f6b4 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\normaliz.dll function = IdnToAscii, address = 0x777b8bb8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\normaliz.dll function = IsNormalizedString, address = 0x7781f662 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\normaliz.dll function = NormalizeString, address = 0x7781f5ea True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = socket, address = 0x75fd3eb8 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = getsockopt, address = 0x75fd737d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = setsockopt, address = 0x75fd41b6 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = htons, address = 0x75fd2d8b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = bind, address = 0x75fd4582 True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = getsockname, address = 0x75fd30af True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = ntohs, address = 0x75fd2d8b True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = connect, address = 0x75fd6bdd True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = WSAGetLastError, address = 0x75fd37ad True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = shutdown, address = 0x75fd449d True 1
Fn
GET_PROC_ADDRESS c:\windows\system32\ws2_32.dll function = closesocket, address = 0x75fd3918 True 1
Fn
Registry (13)
+
Operation Key Additional Information Success Count Logfile
OPEN_KEY HKEY_CURRENT_USER\Software\Borland\Locales False 2
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Borland\Locales False 1
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Borland\Delphi\Locales False 2
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Embarcadero\Locales False 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Embarcadero\Locales False 1
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\CodeGear\Locales False 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\CodeGear\Locales False 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes True 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04090409 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes value_name = MS Shell Dlg 2, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes value_name = MS Shell Dlg 2, data_ident_out = Tahoma True 1
Fn
Window (44)
+
Operation Window Name Additional Information Success Count Logfile
CREATE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 18
Fn
CREATE Explorer class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0, window_parameter = 0 True 1
Fn
CREATE Explorer window_name = FrmMwM41n, class_name = TFrmMwM41n, x_coordinate = 18446744073709551164, y_coordinate = 18446744073709551164, width = 320, height = 240, class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0, window_parameter = 0 True 1
Fn
FIND k8w0 False 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE Explorer class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE Explorer class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0 True 1
Fn
SET_ATTRIBUTE FrmMwM41n class_name = TFrmMwM41n, x_coordinate = 18446744073709551164, y_coordinate = 18446744073709551164, width = 320, height = 240 True 1
Fn
SET_ATTRIBUTE FrmMwM41n class_name = TFrmMwM41n, x_coordinate = 18446744073709551164, y_coordinate = 18446744073709551164, width = 320, height = 240 True 1
Fn
SET_ATTRIBUTE Explorer class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0 True 1
Fn
Keyboard (3)
+
Operation Virtual Key Code Additional Information Success Count Logfile
GET_INFO 0 result_out = 4 True 1
Fn
GET_INFO KB_LOCALE_ID os_tid = 0, result_out = 67699721 True 1
Fn
GET_INFO KB_LOCALE_ID True 1
Fn
System (28)
+
Operation Information Success Count Logfile
GET_CURSOR x_out = 1428, y_out = 797 True 17
Fn
GET_CURSOR x_out = 814, y_out = 22 True 4
Fn
SLEEP duration = 1500 milliseconds (1.500 seconds) True 1
Fn
SLEEP duration = 1000 milliseconds (1.000 seconds) True 2
Fn
SLEEP duration = 60000 milliseconds (60.000 seconds) True 2
Fn
SLEEP duration = 600000 milliseconds (600.000 seconds) True 1
Fn
GET_INFO type = Hardware Information True 1
Fn
Network Behavior
DNS (6)
+
Operation Host Additional Information Success Count Logfile
RESOLVE_NAME carvas32ltda.com True 2
Fn
RESOLVE_NAME carva32ssa.com True 2
Fn
RESOLVE_NAME bandeivacomercial.com True 1
Fn
RESOLVE_NAME bandeivacomercio.com True 1
Fn
TCP Outgoing Connection (6)
+
Remote Address Remote Port L7Protocol Success Count
187.191.100.112 80 False 6
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefox with deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image