Malware Uses JAR | Sequential Behavior
Try VMRay Analyzer
Involved Hosts

Host Resolved to Country City Protocol
N3EErvtwsM
adom2.com.br
carvas32ltda.com
carva32ssa.com
bandeivacomercial.com
bandeivacomercio.com
187.191.100.112 BR TCP
localhost 127.0.0.1 HTTP
Monitored Processes
Behavior Information - Sequential View
Process #1: java.exe
(Host: 12432, Network: 356)
+
Information Value
ID / OS PID #1 / 0xb6c
OS Parent PID 0x4f0 (c:\windows\explorer.exe)
Initial Working Directory C:\Users\DSsDPMx042\Desktop
File Name c:\program files\java\jre1.8.0_92\bin\java.exe
Command Line "C:\Program Files\Java\jre1.8.0_92\bin\java.exe" -jar "C:\Users\DSsDPMx042\Desktop\Duplicata0.jar"
Monitor Start Time: 00:00:08, Reason: Analysis Target
Unmonitor End Time: 00:00:30, Reason: Terminated
Monitor Duration 00:00:22
OS Thread IDs
# 1
0x B70
# 2
0x BC0
# 3
0x BC4
# 4
0x BC8
# 5
0x BCC
# 6
0x BD8
# 7
0x BD0
# 8
0x BD4
# 9
0x BE0
# 10
0x BDC
# 11
0x BE4
# 12
0x BEC
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00042fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
private_0x00000000000c0000 0x000c0000 0x000c0fff Private Memory Readable, Writable True False False
private_0x00000000000d0000 0x000d0000 0x000d0fff Private Memory Readable, Writable True False False
private_0x00000000000e0000 0x000e0000 0x0012ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000130000 0x00130000 0x001f7fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000200000 0x00200000 0x00200fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000210000 0x00210000 0x00211fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000220000 0x00220000 0x00226fff Pagefile Backed Memory Readable True False False
private_0x0000000000230000 0x00230000 0x0032ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000330000 0x00330000 0x00430fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000440000 0x00440000 0x00441fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000450000 0x00450000 0x00450fff Private Memory Readable True False False
private_0x0000000000460000 0x00460000 0x00460fff Private Memory Readable, Writable True False False
private_0x0000000000470000 0x00470000 0x004bffff Private Memory Readable, Writable True False False
private_0x00000000004c0000 0x004c0000 0x004cffff Private Memory Readable, Writable True False False
2924 0x004d0000 0x004dffff Memory Mapped File Readable, Writable True False False
private_0x00000000004e0000 0x004e0000 0x0055ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000560000 0x00560000 0x00560fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000590000 0x00590000 0x0059ffff Private Memory Readable, Writable True False False
private_0x00000000005a0000 0x005a0000 0x0069ffff Private Memory Readable, Writable True False False
pagefile_0x00000000006a0000 0x006a0000 0x00a92fff Pagefile Backed Memory Readable True False False
private_0x0000000000aa0000 0x00aa0000 0x00b9ffff Private Memory Readable, Writable True False False
private_0x0000000000ba0000 0x00ba0000 0x00bfffff Private Memory Readable, Writable True False False
private_0x0000000000c10000 0x00c10000 0x00c1ffff Private Memory Readable, Writable True False False
private_0x0000000000c20000 0x00c20000 0x00caffff Private Memory Readable, Writable True False False
private_0x0000000000cb0000 0x00cb0000 0x00cfffff Private Memory Readable, Writable True False False
private_0x0000000000d40000 0x00d40000 0x00d8ffff Private Memory Readable, Writable True False False
java.exe 0x00da0000 0x00dd2fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000de0000 0x00de0000 0x019dffff Pagefile Backed Memory Readable True False False
SortDefault.nls 0x019e0000 0x01caefff Memory Mapped File Readable False False False
private_0x0000000001cb0000 0x01cb0000 0x03caffff Private Memory Readable, Writable True False False
private_0x0000000003cb0000 0x03cb0000 0x03cfffff Private Memory Readable, Writable True False False
kernel32.dll.mui 0x03d00000 0x03dbffff Memory Mapped File Readable, Writable False False False
private_0x0000000003e00000 0x03e00000 0x13dfffff Private Memory Readable, Writable True False False
classes.jsa 0x13e00000 0x143affff Memory Mapped File Readable False False False
private_0x00000000143b0000 0x143b0000 0x1480ffff Private Memory Readable, Writable True False False
private_0x0000000014810000 0x14810000 0x1485ffff Private Memory Readable, Writable True False False
private_0x0000000014870000 0x14870000 0x148bffff Private Memory Readable, Writable True False False
private_0x00000000148d0000 0x148d0000 0x1491ffff Private Memory Readable, Writable True False False
private_0x0000000014990000 0x14990000 0x149dffff Private Memory Readable, Writable True False False
classes.jsa 0x14a00000 0x14f6ffff Memory Mapped File Readable, Writable False False False
private_0x0000000014fb0000 0x14fb0000 0x14ffffff Private Memory Readable, Writable True False False
private_0x0000000015000000 0x15000000 0x151fffff Private Memory Readable, Writable True False False
private_0x0000000015290000 0x15290000 0x1529ffff Private Memory Readable, Writable True False False
private_0x00000000152b0000 0x152b0000 0x152bffff Private Memory Readable, Writable True False False
private_0x0000000015380000 0x15380000 0x153bffff Private Memory Readable, Writable True False False
private_0x0000000015400000 0x15400000 0x1544ffff Private Memory Readable, Writable True False False
private_0x0000000015450000 0x15450000 0x1554ffff Private Memory Readable, Writable True False False
classes.jsa 0x15600000 0x156bffff Memory Mapped File Readable, Writable False False False
private_0x0000000015800000 0x15800000 0x1580ffff Private Memory Readable, Writable True False False
private_0x0000000015940000 0x15940000 0x1597ffff Private Memory Readable, Writable True False False
jvm.dll 0x6d510000 0x6d8dafff Memory Mapped File Readable, Writable, Executable False False False
msvcr100.dll 0x6dee0000 0x6df9efff Memory Mapped File Readable, Writable, Executable False False False
net.dll 0x6e0b0000 0x6e0c5fff Memory Mapped File Readable, Writable, Executable True False False
zip.dll 0x6e0d0000 0x6e0e2fff Memory Mapped File Readable, Writable, Executable True False False
java.dll 0x6e0f0000 0x6e110fff Memory Mapped File Readable, Writable, Executable True False False
pnrpnsp.dll 0x6f1d0000 0x6f1e1fff Memory Mapped File Readable, Writable, Executable False False False
winrnr.dll 0x6f270000 0x6f277fff Memory Mapped File Readable, Writable, Executable False False False
NapiNSP.dll 0x6f280000 0x6f28ffff Memory Mapped File Readable, Writable, Executable False False False
verify.dll 0x6f9b0000 0x6f9bbfff Memory Mapped File Readable, Writable, Executable True False False
winmm.dll 0x70ef0000 0x70f21fff Memory Mapped File Readable, Writable, Executable False False False
FWPUCLNT.DLL 0x721e0000 0x72217fff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x72300000 0x72306fff Memory Mapped File Readable, Writable, Executable False False False
IPHLPAPI.DLL 0x72310000 0x7232bfff Memory Mapped File Readable, Writable, Executable False False False
rasadhlp.dll 0x72350000 0x72355fff Memory Mapped File Readable, Writable, Executable False False False
wsock32.dll 0x72f00000 0x72f06fff Memory Mapped File Readable, Writable, Executable False False False
nlaapi.dll 0x73850000 0x7385ffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x74110000 0x742adfff Memory Mapped File Readable, Writable, Executable False False False
version.dll 0x748a0000 0x748a8fff Memory Mapped File Readable, Writable, Executable False False False
WSHTCPIP.DLL 0x74930000 0x74934fff Memory Mapped File Readable, Writable, Executable False False False
dnsapi.dll 0x74ca0000 0x74ce3fff Memory Mapped File Readable, Writable, Executable False False False
wship6.dll 0x74dd0000 0x74dd5fff Memory Mapped File Readable, Writable, Executable False False False
mswsock.dll 0x74de0000 0x74e1bfff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x75350000 0x7535afff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x759e0000 0x76629fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x76a90000 0x76bebfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76d70000 0x76dc6fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x77340000 0x77345fff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x77360000 0x77364fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x773f0000 0x77424fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffd4000 0x7ffd4000 0x7ffd4fff Private Memory Readable, Writable True False False
private_0x000000007ffd5000 0x7ffd5000 0x7ffd5fff Private Memory Readable, Writable True False False
private_0x000000007ffd6000 0x7ffd6000 0x7ffd6fff Private Memory Readable, Writable True False False
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory Readable, Writable True False False
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory Readable, Writable True False False
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory Readable, Writable True False False
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory Readable, Writable True False False
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory Readable, Writable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Threads
Thread 0xbc0
(Host: 12426, Network: 356)
+
Category Operation Information Success Count Logfile
FILE CREATE file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 4 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 128 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 7 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 1896818 True 1
Fn
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 363 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 120 True 1
Fn
Data
MOD GET_HANDLE module_name = c:\program files\java\jre1.8.0_92\bin\client\jvm.dll, base_address = 0x6d510000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\program files\java\jre1.8.0_92\bin\client\jvm.dll, function = JVM_GetVersionInfo, address = 0x6d60fed0 True 1
Fn
SYS GET_INFO type = Hardware Information True 1
Fn
MOD LOAD module_name = SHELL32.dll, base_address = 0x759e0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\shell32.dll, function = SHGetKnownFolderPath, address = 0x75a94ca0 True 1
Fn
FILE OPEN file_name = STD_OUTPUT_HANDLE True 1
Fn
FILE OPEN file_name = STD_ERROR_HANDLE True 1
Fn
MOD GET_HANDLE module_name = c:\program files\java\jre1.8.0_92\bin\client\jvm.dll, base_address = 0x6d510000 True 1
Fn
MOD GET_FILENAME module_name = c:\program files\java\jre1.8.0_92\bin\client\jvm.dll, file_name = C:\Program Files\Java\jre1.8.0_92\bin\client\jvm.dll True 1
Fn
FILE OPEN file_name = STD_INPUT_HANDLE True 1
Fn
FILE OPEN file_name = STD_OUTPUT_HANDLE True 1
Fn
FILE OPEN file_name = STD_ERROR_HANDLE True 1
Fn
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 1671 True 1
Fn
Data
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetFinalPathNameByHandleW, address = 0x75934e2a True 1
Fn
MOD GET_HANDLE module_name = c:\program files\java\jre1.8.0_92\bin\java.exe, base_address = 0xda0000 True 2
Fn
FILE CREATE file_name = c:\program files\java\jre1.8.0_92\lib\ext\meta-index, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\ext\meta-index, size = 8192 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\ext\meta-index, size = 8192 True 1
Fn
FILE CREATE file_name = c:\users\dssdpmx042\.oracle_jre_usage\90737d32e3abaa4.timestamp, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE WRITE file_name = c:\users\dssdpmx042\.oracle_jre_usage\90737d32e3abaa4.timestamp, size = 50 True 1
Fn
Data
FILE CREATE file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = OPEN_EXISTING, file_attributes = FILE_FLAG_BACKUP_SEMANTICS True 1
Fn
FILE CREATE file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 4 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 128 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 1188 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 123 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 1016 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 1132 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 985 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 1132 True 1
Fn
Data
FILE CREATE file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = OPEN_EXISTING, file_attributes = FILE_FLAG_BACKUP_SEMANTICS True 1
Fn
FILE CREATE file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 4 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 128 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 1188 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 123 True 2
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 160 True 2
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 123 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 2339 True 1
Fn
Data
FILE CREATE file_name = c:\program files\java\jre1.8.0_92\lib\meta-index, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\meta-index, size = 8192 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\meta-index, size = 8192 True 1
Fn
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 160 True 1
Fn
Data
FILE CREATE file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = OPEN_EXISTING, file_attributes = FILE_FLAG_BACKUP_SEMANTICS True 1
Fn
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 352 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 123 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 561 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 879 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 755 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 2044 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 2423 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 91 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 1157 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 91 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 8192 True 2
Fn
Data
FILE READ file_name = c:\users\dssdpmx042\desktop\duplicata0.jar, size = 3879 True 1
Fn
Data
MOD GET_HANDLE module_name = c:\program files\java\jre1.8.0_92\bin\java.exe, base_address = 0xda0000 True 1
Fn
SCK CREATE address_family = AF_INET6, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
DNS GET_HOSTNAME name = N3EErvtwsM True 1
Fn
DNS RESOLVE_NAME host = N3EErvtwsM True 1
Fn
FILE CREATE file_name = c:\program files\java\jre1.8.0_92\lib\security\java.security, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\security\java.security, size = 8192 True 3
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\security\java.security, size = 8192 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\security\java.security, size = 8192 True 1
Fn
FILE CREATE_DIR file_name = c:\users\public\n3eg True 1
Fn
FILE CREATE file_name = c:\users\public\n3eg\id, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE WRITE file_name = c:\users\public\n3eg\id, size = 7 True 1
Fn
Data
FILE CREATE file_name = c:\users\public\n3eg\idw, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE WRITE file_name = c:\users\public\n3eg\idw, size = 2 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 44725 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 800 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 1085 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 792 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 1194 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 792 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 1127 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 737 True 1
Fn
Data
FILE CREATE file_name = c:\program files\java\jre1.8.0_92\lib\net.properties, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\net.properties, size = 8192 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\net.properties, size = 8192 True 1
Fn
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 16003 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 4482 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 973 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 4050 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 975 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 3674 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 621 True 1
Fn
Data
MOD GET_HANDLE module_name = c:\program files\java\jre1.8.0_92\bin\java.exe, base_address = 0xda0000 True 1
Fn
DNS RESOLVE_NAME host = adom2.com.br True 1
Fn
SCK CREATE address_family = AF_INET6, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
SCK CONNECT remote_address = 0, remote_port = 80 True 1
Fn
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 751 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 1874 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 7198 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 920 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 1936 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 281 True 1
Fn
Data
SCK SEND size = 182, flags = NO_FLAG_SET, size_out = 182 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 748 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 2693 True 1
Fn
Data
SCK RECV size = 8192, flags = NO_FLAG_SET, size_out = 8192 True 1
Fn
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 3379 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 3246 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 100 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 2082 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 2282 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 683 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 681 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 2654 True 1
Fn
Data
SCK RECV size = 8192, flags = NO_FLAG_SET, size_out = 8192 True 201
Fn
SCK RECV size = 8192, flags = NO_FLAG_SET, size_out = 7142 True 1
Fn
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 1459 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 1396 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 285 True 1
Fn
Data
FILE CREATE file_name = c:\users\public\n3eg\n3eg1.zip, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE WRITE file_name = c:\users\public\n3eg\n3eg1.zip, size = 1661608 True 1
Fn
SCK SEND size = 182, flags = NO_FLAG_SET, size_out = 182 True 1
Fn
Data
SCK RECV size = 8192, flags = NO_FLAG_SET, size_out = 8192 True 91
Fn
SCK RECV size = 8192, flags = NO_FLAG_SET, size_out = 3326 True 1
Fn
FILE CREATE file_name = c:\users\public\n3eg\n3eg2.zip, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE WRITE file_name = c:\users\public\n3eg\n3eg2.zip, size = 748483 True 1
Fn
Data
SCK SEND size = 182, flags = NO_FLAG_SET, size_out = 182 True 1
Fn
Data
SCK RECV size = 8192, flags = NO_FLAG_SET, size_out = 8192 True 51
Fn
SCK RECV size = 8192, flags = NO_FLAG_SET, size_out = 3816 True 1
Fn
FILE CREATE file_name = c:\users\public\n3eg\n3eg4.zip, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE WRITE file_name = c:\users\public\n3eg\n3eg4.zip, size = 421293 True 1
Fn
Data
FILE CREATE file_name = c:\users\public\n3eg\n3eg4.zip, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 30 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 5 True 1
Fn
Data
FILE CREATE file_name = c:\users\public\n3eg\ljkg4, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 142 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 930 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 806 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 882 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 761 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 830 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 913 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 812 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 638 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 614 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 633 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 730 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 738 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 747 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 747 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 715 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 738 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 859 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 741 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 687 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 926 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 779 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 867 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 834 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 407 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 2
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 285 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 673 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 808 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 719 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 701 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 706 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 667 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 651 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 746 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 756 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 855 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 830 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 987 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 763 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 700 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 836 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 842 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 868 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 909 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 751 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 871 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 876 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 754 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 885 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 774 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 827 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 21 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 211 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1009 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 709 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 946 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 794 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 63 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 876 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 879 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 62 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 77 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 847 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 851 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 532 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 296 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 936 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 834 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 908 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 968 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1000 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 964 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 884 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 930 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 939 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 811 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 838 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 959 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 869 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 873 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 746 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 804 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 786 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 787 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 805 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 142 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1019 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 11 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 759 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 902 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 29 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 76 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 982 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 449 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 552 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 567 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 587 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 587 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 634 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 684 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 603 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 802 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 583 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 496 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 141 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 516 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 1024 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 479 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 538 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 490 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 495 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 496 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 496 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 492 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 496 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 496 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 494 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 495 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 493 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 493 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 488 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 496 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 494 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 494 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 491 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 505 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 507 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 507 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 507 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 507 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 507 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 507 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 507 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
FILE READ file_name = c:\users\public\n3eg\n3eg4.zip, size = 512 True 1
Fn
Data
FILE WRITE file_name = c:\users\public\n3eg\ljkg4, size = 512 True 1
Fn
Data
For performance reasons, the remaining 11264 entries are omitted.
Click to download all 12264 entries as text file (5.52 MB).
Thread 0xbec
(Host: 6, Network: 0)
+
Category Operation Information Success Count Logfile
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 1124 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 160 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 30 True 1
Fn
Data
FILE READ file_name = c:\program files\java\jre1.8.0_92\lib\rt.jar, size = 3434 True 1
Fn
Data
Process #2: regsvr32.exe
(Host: 90, Network: 0)
+
Information Value
ID / OS PID #2 / 0xbf8
OS Parent PID 0xb6c (c:\program files\java\jre1.8.0_92\bin\java.exe)
Initial Working Directory C:\Users\DSsDPMx042\Desktop
File Name c:\windows\system32\regsvr32.exe
Command Line regsvr32.exe /s \"C:\\Users\\Public\\N3Eg\\N3Eg2.51N3E\" #96
Monitor Start Time: 00:00:26, Reason: Child Process
Unmonitor End Time: 00:00:30, Reason: Terminated
Monitor Duration 00:00:04
OS Thread IDs
# 13
0x BFC
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00041fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
pagefile_0x00000000000c0000 0x000c0000 0x000c1fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000000d0000 0x000d0000 0x000dffff Private Memory Readable, Writable True False False
pagefile_0x00000000000e0000 0x000e0000 0x001a7fff Pagefile Backed Memory Readable True False False
regsvr32.exe.mui 0x001b0000 0x001b1fff Memory Mapped File Readable, Writable False False False
private_0x00000000001c0000 0x001c0000 0x001c0fff Private Memory Readable, Writable True False False
private_0x00000000001d0000 0x001d0000 0x001d0fff Private Memory Readable, Writable True False False
pagefile_0x00000000001f0000 0x001f0000 0x001f1fff Pagefile Backed Memory Readable True False False
private_0x0000000000200000 0x00200000 0x0023ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000240000 0x00240000 0x00340fff Pagefile Backed Memory Readable True False False
private_0x0000000000350000 0x00350000 0x0044ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000450000 0x00450000 0x0052efff Pagefile Backed Memory Readable True False False
private_0x0000000000610000 0x00610000 0x0064ffff Private Memory Readable, Writable True False False
regsvr32.exe 0x006a0000 0x006a6fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x00000000006b0000 0x006b0000 0x012affff Pagefile Backed Memory Readable True False False
N3Eg2.51N3E 0x012b0000 0x01404fff Memory Mapped File Readable, Writable, Executable True True False
private_0x0000000001410000 0x01410000 0x0154ffff Private Memory Readable, Writable True False False
SortDefault.nls 0x01550000 0x0181efff Memory Mapped File Readable False False False
uxtheme.dll 0x74090000 0x740cffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x74110000 0x742adfff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x752a0000 0x752abfff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x76a90000 0x76bebfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76d70000 0x76dc6fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x76ee0000 0x76f6efff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Threads
Thread 0xbfc
(Host: 90, Network: 0)
+
Category Operation Information Success Count Logfile
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetThreadPreferredUILanguages, address = 0x759422d7 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetThreadPreferredUILanguages, address = 0x7593e627 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetThreadUILanguage, address = 0x7593ae42 True 1
Fn
SYS GET_INFO type = Hardware Information True 1
Fn
MOD GET_FILENAME file_name = C:\Users\Public\N3Eg\N3Eg2.51N3E True 1
Fn
MOD GET_FILENAME file_name = C:\Windows\system32\regsvr32.exe True 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Embarcadero\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Embarcadero\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\CodeGear\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\CodeGear\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Borland\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Borland\Delphi\Locales False 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetNativeSystemInfo, address = 0x7593be77 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetDiskFreeSpaceExW, address = 0x7593de40 True 1
Fn
MOD GET_FILENAME file_name = C:\Windows\system32\regsvr32.exe True 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Embarcadero\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Embarcadero\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\CodeGear\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\CodeGear\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Borland\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Borland\Delphi\Locales False 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\oleaut32.dll, base_address = 0x76ee0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VariantChangeTypeEx, address = 0x76ee4c28 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarNeg, address = 0x76f5c802 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarNot, address = 0x76f5ec66 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarAdd, address = 0x76f05934 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarSub, address = 0x76f5d332 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarMul, address = 0x76f5dbd4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarDiv, address = 0x76f5e405 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarIdiv, address = 0x76f5f00a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarMod, address = 0x76f5f15e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarAnd, address = 0x76f05a98 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarOr, address = 0x76f5ecfa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarXor, address = 0x76f5ee2e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarCmp, address = 0x76efb0dc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarI4FromStr, address = 0x76ef6fab True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarR4FromStr, address = 0x76f001a0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarR8FromStr, address = 0x76ef699e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarDateFromStr, address = 0x76f06ba7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarCyFromStr, address = 0x76f26c12 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBoolFromStr, address = 0x76efdbd1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromCy, address = 0x76f07fdc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromDate, address = 0x76ef7a2a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromBool, address = 0x76f00355 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = InitializeConditionVariable, address = 0x77259981 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WakeConditionVariable, address = 0x772a5a7b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WakeAllConditionVariable, address = 0x772245a5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SleepConditionVariableCS, address = 0x759318be True 1
Fn
MOD GET_FILENAME file_name = C:\Windows\system32\regsvr32.exe True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateToolhelp32Snapshot, address = 0x7593f731 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Heap32ListFirst, address = 0x759902e7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Heap32ListNext, address = 0x75990391 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Heap32First, address = 0x75990429 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Heap32Next, address = 0x75990614 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Toolhelp32ReadProcessMemory, address = 0x75990819 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32First, address = 0x7596443d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32Next, address = 0x75964505 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32FirstW, address = 0x7593fa35 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32NextW, address = 0x7593faca True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32FirstW, address = 0x7593fa35 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32NextW, address = 0x7593faca True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Thread32First, address = 0x75967e4c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Thread32Next, address = 0x75967edc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32First, address = 0x75990859 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32Next, address = 0x75990942 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32FirstW, address = 0x7593c59e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32NextW, address = 0x7593c11f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32FirstW, address = 0x7593c59e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32NextW, address = 0x7593c11f True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualAllocEx, address = 0x7593c1b6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WriteProcessMemory, address = 0x7593c1de True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateRemoteThread, address = 0x7598f33b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = OpenProcess, address = 0x759459d7 True 1
Fn
PROC OPEN process_name = c:\windows\explorer.exe, os_pid = 0x4f0, desired_access = PROCESS_ALL_ACCESS True 1
Fn
MEM ALLOC address = 0x4fd0000, process_name = c:\windows\explorer.exe, os_pid = 0x4f0, size = 66, allocation_type = MEM_COMMIT, protection = PAGE_READWRITE True 1
Fn
MEM WRITE address = 0x4fd0000, process_name = c:\windows\explorer.exe, os_pid = 0x4f0, size = 66 True 1
Fn
Data
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LoadLibraryW, address = 0x75953c01 True 1
Fn
THREAD CREATE process_name = c:\windows\explorer.exe, os_tid = 0xc00, os_pid = 0x4f0, proc_address = 0x75953c01, flags = THREAD_RUNS_IMMEDIATELY True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLogicalProcessorInformation, address = 0x75932004 True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLogicalProcessorInformation, address = 0x75932004 True 1
Fn
Process #3: explorer.exe
(Host: 890, Network: 46)
+
Information Value
ID / OS PID #3 / 0x4f0
OS Parent PID 0xffffffffffffffff (Unknown)
Initial Working Directory C:\Windows\system32
File Name c:\windows\explorer.exe
Command Line C:\Windows\Explorer.EXE
Monitor Start Time: 00:00:29, Reason: Injection
Unmonitor End Time: 00:03:50, Reason: Terminated
Monitor Duration 00:03:21
OS Thread IDs
# 14
0x AB8
# 15
0x 9DC
# 16
0x 9D0
# 17
0x 9C4
# 18
0x 9B8
# 19
0x 9B4
# 20
0x 988
# 21
0x 93C
# 22
0x 91C
# 23
0x 914
# 24
0x 8C8
# 25
0x 4BC
# 26
0x 6A0
# 27
0x 678
# 28
0x 670
# 29
0x 658
# 30
0x 654
# 31
0x 5FC
# 32
0x 5E8
# 33
0x 5E0
# 34
0x 5C8
# 35
0x 5C4
# 36
0x 5C0
# 37
0x 5BC
# 38
0x 5B8
# 39
0x 5AC
# 40
0x 5A8
# 41
0x 5A4
# 42
0x 59C
# 43
0x 528
# 44
0x 524
# 45
0x 51C
# 46
0x 518
# 47
0x 514
# 48
0x 4FC
# 49
0x 4F4
# 50
0x C00
# 51
0x C04
# 52
0x C28
# 53
0x CAC
# 81
0x F00
# 94
0x F7C
# 101
0x 48C
# 102
0x 470
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00021fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00041fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000050000 0x00050000 0x00056fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00061fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000070000 0x00070000 0x00070fff Private Memory Readable, Writable True False False
private_0x0000000000080000 0x00080000 0x0017ffff Private Memory Readable, Writable True False False
locale.nls 0x00180000 0x001e6fff Memory Mapped File Readable False False False
private_0x00000000001f0000 0x001f0000 0x0022ffff Private Memory Readable, Writable True False False
private_0x0000000000230000 0x00230000 0x00230fff Private Memory Readable, Writable True False False
private_0x0000000000240000 0x00240000 0x0025ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000260000 0x00260000 0x00260fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000270000 0x00270000 0x00271fff Pagefile Backed Memory Readable True False False
private_0x0000000000280000 0x00280000 0x00280fff Private Memory Readable, Writable True False False
pagefile_0x0000000000290000 0x00290000 0x00291fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000002a0000 0x002a0000 0x002a0fff Pagefile Backed Memory Readable True False False
private_0x00000000002b0000 0x002b0000 0x002bffff Private Memory Readable, Writable True False False
pagefile_0x00000000002c0000 0x002c0000 0x00387fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000390000 0x00390000 0x00490fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000004a0000 0x004a0000 0x00892fff Pagefile Backed Memory Readable True False False
private_0x00000000008a0000 0x008a0000 0x0099ffff Private Memory Readable, Writable True False False
pagefile_0x00000000009a0000 0x009a0000 0x009a0fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000009b0000 0x009b0000 0x009b1fff Pagefile Backed Memory Readable True False False
private_0x00000000009c0000 0x009c0000 0x009fffff Private Memory Readable, Writable True False False
pagefile_0x0000000000a00000 0x00a00000 0x00adefff Pagefile Backed Memory Readable True False False
private_0x0000000000ae0000 0x00ae0000 0x00b0bfff Private Memory Readable, Writable True False False
private_0x0000000000b10000 0x00b10000 0x00b3ffff Private Memory Readable, Writable True False False
private_0x0000000000b40000 0x00b40000 0x00bbffff Private Memory Readable, Writable True False False
explorer.exe 0x00bc0000 0x00e40fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000e50000 0x00e50000 0x01a4ffff Pagefile Backed Memory Readable True False False
private_0x0000000001a50000 0x01a50000 0x01a8ffff Private Memory Readable, Writable True False False
SortDefault.nls 0x01a90000 0x01d5efff Memory Mapped File Readable False False False
pagefile_0x0000000001d60000 0x01d60000 0x01d61fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001d70000 0x01d70000 0x01d71fff Pagefile Backed Memory Readable True False False
private_0x0000000001d80000 0x01d80000 0x01d80fff Private Memory Readable, Writable True False False
comctl32.dll.mui 0x01d90000 0x01d92fff Memory Mapped File Readable, Writable False False False
private_0x0000000001da0000 0x01da0000 0x01da0fff Private Memory Readable, Writable True False False
private_0x0000000001db0000 0x01db0000 0x01deffff Private Memory Readable, Writable True False False
private_0x0000000001df0000 0x01df0000 0x01dfffff Private Memory Readable, Writable True False False
private_0x0000000001e00000 0x01e00000 0x01e08fff Private Memory Readable, Writable True False False
private_0x0000000001e10000 0x01e10000 0x01e4ffff Private Memory Readable, Writable True False False
pagefile_0x0000000001e10000 0x01e10000 0x01e11fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001e20000 0x01e20000 0x01e21fff Pagefile Backed Memory Readable True False False
ActionCenter.dll.mui 0x01e30000 0x01e34fff Memory Mapped File Readable, Writable False False False
private_0x0000000001e50000 0x01e50000 0x01e57fff Private Memory Readable, Writable True False False
private_0x0000000001e60000 0x01e60000 0x01f07fff Private Memory Readable, Writable True False False
private_0x0000000001f10000 0x01f10000 0x01fc3fff Private Memory Readable, Writable True False False
private_0x0000000001fd0000 0x01fd0000 0x01fd0fff Private Memory Readable, Writable True False False
private_0x0000000001fe0000 0x01fe0000 0x01fe0fff Private Memory Readable, Writable True False False
{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000000c.db 0x01ff0000 0x0200cfff Memory Mapped File Readable True False False
pagefile_0x0000000002010000 0x02010000 0x02010fff Pagefile Backed Memory Readable, Writable True False False
cversions.2.db 0x02020000 0x02023fff Memory Mapped File Readable True False False
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000007.db 0x02030000 0x0205ffff Memory Mapped File Readable True False False
cversions.2.db 0x02060000 0x02063fff Memory Mapped File Readable True False False
pagefile_0x0000000002070000 0x02070000 0x02071fff Pagefile Backed Memory Readable True False False
private_0x0000000002080000 0x02080000 0x020bffff Private Memory Readable, Writable True False False
private_0x0000000002080000 0x02080000 0x020affff Private Memory Readable, Writable True False False
pagefile_0x00000000020c0000 0x020c0000 0x020c1fff Pagefile Backed Memory Readable True False False
private_0x00000000020d0000 0x020d0000 0x020d3fff Private Memory Readable, Writable True False False
thumbcache_1024.db 0x020e0000 0x020e0fff Memory Mapped File Readable, Writable True False False
thumbcache_sr.db 0x020f0000 0x020f0fff Memory Mapped File Readable, Writable True False False
thumbcache_idx.db 0x02100000 0x02101fff Memory Mapped File Readable, Writable True False False
private_0x0000000002110000 0x02110000 0x0230ffff Private Memory Readable, Writable True False False
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db 0x02310000 0x02375fff Memory Mapped File Readable True False False
private_0x0000000002380000 0x02380000 0x02380fff Private Memory Readable, Writable True False False
private_0x0000000002390000 0x02390000 0x023cffff Private Memory Readable, Writable True False False
private_0x00000000023d0000 0x023d0000 0x023d3fff Private Memory Readable, Writable True False False
private_0x00000000023e0000 0x023e0000 0x023e3fff Private Memory Readable, Writable True False False
pagefile_0x00000000023f0000 0x023f0000 0x023f1fff Pagefile Backed Memory Readable True False False
private_0x0000000002400000 0x02400000 0x02400fff Private Memory Readable, Writable True False False
private_0x0000000002410000 0x02410000 0x02410fff Private Memory Readable, Writable True False False
private_0x0000000002420000 0x02420000 0x02420fff Private Memory Readable, Writable True False False
private_0x0000000002430000 0x02430000 0x0246ffff Private Memory Readable, Writable True False False
private_0x0000000002470000 0x02470000 0x02470fff Private Memory Readable, Writable True False False
thumbcache_1024.db 0x02480000 0x02480fff Memory Mapped File Readable, Writable True False False
thumbcache_sr.db 0x02490000 0x02490fff Memory Mapped File Readable, Writable True False False
thumbcache_idx.db 0x024a0000 0x024a1fff Memory Mapped File Readable, Writable True False False
pagefile_0x00000000024b0000 0x024b0000 0x024b0fff Pagefile Backed Memory Readable True False False
private_0x00000000024c0000 0x024c0000 0x024c0fff Private Memory Readable, Writable True False False
private_0x00000000024d0000 0x024d0000 0x0250ffff Private Memory Readable, Writable True False False
pagefile_0x0000000002510000 0x02510000 0x02510fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000002520000 0x02520000 0x02521fff Pagefile Backed Memory Readable True False False
cversions.2.db 0x02530000 0x02533fff Memory Mapped File Readable True False False
pagefile_0x0000000002540000 0x02540000 0x02541fff Pagefile Backed Memory Readable True False False
{7CD55808-3D38-4DD5-90C9-62F0E6EE60D4}.2.ver0x0000000000000001.db 0x02550000 0x02550fff Memory Mapped File Readable True False False
private_0x0000000002560000 0x02560000 0x02560fff Private Memory Readable, Writable True False False
private_0x0000000002570000 0x02570000 0x02570fff Private Memory Readable, Writable True False False
private_0x0000000002580000 0x02580000 0x02580fff Private Memory Readable, Writable True False False
private_0x0000000002590000 0x02590000 0x02590fff Private Memory Readable, Writable True False False
private_0x00000000025a0000 0x025a0000 0x025a0fff Private Memory Readable, Writable True False False
private_0x00000000025b0000 0x025b0000 0x025b0fff Private Memory Readable, Writable True False False
private_0x00000000025c0000 0x025c0000 0x025fffff Private Memory Readable, Writable True False False
StaticCache.dat 0x02600000 0x02f2ffff Memory Mapped File Readable False False False
private_0x0000000002f30000 0x02f30000 0x0302ffff Private Memory Readable, Writable True False False
private_0x0000000003030000 0x03030000 0x03030fff Private Memory Readable, Writable True False False
private_0x0000000003040000 0x03040000 0x03040fff Private Memory Readable, Writable True False False
private_0x0000000003050000 0x03050000 0x03050fff Private Memory Readable, Writable True False False
private_0x0000000003060000 0x03060000 0x03060fff Private Memory Readable, Writable True False False
private_0x0000000003070000 0x03070000 0x030affff Private Memory Readable, Writable True False False
wdmaud.drv.mui 0x030b0000 0x030b0fff Memory Mapped File Readable, Writable False False False
MMDevAPI.dll.mui 0x030c0000 0x030c0fff Memory Mapped File Readable, Writable False False False
private_0x00000000030d0000 0x030d0000 0x030d1fff Private Memory Readable, Writable True False False
thumbcache_1024.db 0x030e0000 0x030e0fff Memory Mapped File Readable, Writable True False False
private_0x00000000030f0000 0x030f0000 0x0312ffff Private Memory Readable, Writable True False False
private_0x0000000003130000 0x03130000 0x0316ffff Private Memory Readable, Writable True False False
private_0x0000000003130000 0x03130000 0x0316ffff Private Memory Readable, Writable True False False
thumbcache_sr.db 0x03170000 0x03170fff Memory Mapped File Readable, Writable True False False
thumbcache_idx.db 0x03180000 0x03181fff Memory Mapped File Readable, Writable True False False
pagefile_0x0000000003190000 0x03190000 0x03191fff Pagefile Backed Memory Readable True False False
private_0x00000000031a0000 0x031a0000 0x031dffff Private Memory Readable, Writable True False False
private_0x00000000031e0000 0x031e0000 0x0321ffff Private Memory Readable, Writable True False False
pagefile_0x0000000003220000 0x03220000 0x03221fff Pagefile Backed Memory Readable True False False
cversions.2.db 0x03230000 0x03233fff Memory Mapped File Readable True False False
private_0x0000000003240000 0x03240000 0x03240fff Private Memory Readable, Writable, Executable True False False
pagefile_0x0000000003250000 0x03250000 0x03250fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000003260000 0x03260000 0x03260fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000003270000 0x03270000 0x03270fff Private Memory Readable, Writable True False False
private_0x0000000003280000 0x03280000 0x03280fff Private Memory Readable, Writable True False False
private_0x0000000003290000 0x03290000 0x03292fff Private Memory Readable, Writable True False False
pagefile_0x00000000032a0000 0x032a0000 0x032a1fff Pagefile Backed Memory Readable True False False
private_0x00000000032b0000 0x032b0000 0x032f7fff Private Memory Readable, Writable True False False
private_0x0000000003300000 0x03300000 0x03332fff Private Memory Readable, Writable True False False
pagefile_0x0000000003340000 0x03340000 0x03341fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000003350000 0x03350000 0x03351fff Pagefile Backed Memory Readable True False False
thumbcache_1024.db 0x03360000 0x03360fff Memory Mapped File Readable, Writable True False False
thumbcache_sr.db 0x03370000 0x03370fff Memory Mapped File Readable, Writable True False False
thumbcache_idx.db 0x03380000 0x03381fff Memory Mapped File Readable, Writable True False False
pagefile_0x0000000003390000 0x03390000 0x03391fff Pagefile Backed Memory Readable True False False
private_0x00000000033a0000 0x033a0000 0x033dffff Private Memory Readable, Writable True False False
private_0x00000000033a0000 0x033a0000 0x033dffff Private Memory Readable, Writable True False False
private_0x00000000033e0000 0x033e0000 0x0341ffff Private Memory Readable, Writable True False False
private_0x00000000033f0000 0x033f0000 0x0342ffff Private Memory Readable, Writable True False False
thumbcache_32.db 0x03420000 0x0351ffff Memory Mapped File Readable, Writable True False False
private_0x0000000003520000 0x03520000 0x0356ffff Private Memory Readable, Writable True False False
oleaccrc.dll 0x03570000 0x03570fff Memory Mapped File Readable False False False
thumbcache_96.db 0x03580000 0x0367ffff Memory Mapped File Readable, Writable True False False
private_0x00000000035b0000 0x035b0000 0x035effff Private Memory Readable, Writable True False False
private_0x00000000035f0000 0x035f0000 0x0362ffff Private Memory Readable, Writable True False False
thumbcache_256.db 0x03680000 0x0377ffff Memory Mapped File Readable, Writable True False False
pagefile_0x0000000003780000 0x03780000 0x03781fff Pagefile Backed Memory Readable True False False
private_0x0000000003790000 0x03790000 0x037cffff Private Memory Readable, Writable True False False
bthprops.cpl.mui 0x037d0000 0x037d6fff Memory Mapped File Readable, Writable False False False
pagefile_0x00000000037e0000 0x037e0000 0x037e1fff Pagefile Backed Memory Readable True False False
private_0x00000000037f0000 0x037f0000 0x0382ffff Private Memory Readable, Writable True False False
imageres.dll 0x03830000 0x04b84fff Memory Mapped File Readable False False False
private_0x0000000004b90000 0x04b90000 0x04f91fff Private Memory Readable, Writable True False False
pagefile_0x0000000004fa0000 0x04fa0000 0x04fa1fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000004fb0000 0x04fb0000 0x04fb1fff Pagefile Backed Memory Readable True False False
prnfldr.dll.mui 0x04fc0000 0x04fc3fff Memory Mapped File Readable, Writable False False False
private_0x0000000004fd0000 0x04fd0000 0x04fd0fff Private Memory Readable, Writable True False False
private_0x0000000004fe0000 0x04fe0000 0x04fe0fff Private Memory Readable, Writable, Executable True False False
private_0x0000000004ff0000 0x04ff0000 0x04ffffff Private Memory Readable, Writable True False False
index.dat 0x05000000 0x05013fff Memory Mapped File Readable, Writable True True False
private_0x0000000005020000 0x05020000 0x0505ffff Private Memory Readable, Writable True False False
thumbcache_32.db 0x05060000 0x0515ffff Memory Mapped File Readable, Writable True False False
thumbcache_96.db 0x05160000 0x0525ffff Memory Mapped File Readable, Writable True False False
thumbcache_256.db 0x05260000 0x0535ffff Memory Mapped File Readable, Writable True False False
private_0x0000000005360000 0x05360000 0x0539ffff Private Memory Readable, Writable True False False
private_0x00000000053a0000 0x053a0000 0x053dffff Private Memory Readable, Writable True False False
index.dat 0x053e0000 0x053e7fff Memory Mapped File Readable, Writable True True False
index.dat 0x053f0000 0x053fbfff Memory Mapped File Readable, Writable True True False
private_0x0000000005410000 0x05410000 0x0544ffff Private Memory Readable, Writable True False False
private_0x0000000005450000 0x05450000 0x0564ffff Private Memory Readable, Writable True False False
private_0x0000000005650000 0x05650000 0x0568ffff Private Memory Readable, Writable True False False
private_0x0000000005690000 0x05690000 0x056cffff Private Memory Readable, Writable True False False
private_0x00000000056d0000 0x056d0000 0x0570ffff Private Memory Readable, Writable True False False
thumbcache_256.db 0x05710000 0x057bffff Memory Mapped File Readable, Writable True False False
thumbcache_32.db 0x057c0000 0x058bffff Memory Mapped File Readable, Writable True False False
thumbcache_96.db 0x058c0000 0x059bffff Memory Mapped File Readable, Writable True False False
thumbcache_256.db 0x059c0000 0x05abffff Memory Mapped File Readable, Writable True False False
thumbcache_256.db 0x05ac0000 0x05b6ffff Memory Mapped File Readable, Writable True False False
thumbcache_32.db 0x05b70000 0x05c6ffff Memory Mapped File Readable, Writable True False False
thumbcache_96.db 0x05c70000 0x05d6ffff Memory Mapped File Readable, Writable True False False
thumbcache_256.db 0x05d70000 0x05e6ffff Memory Mapped File Readable, Writable True False False
private_0x0000000005e70000 0x05e70000 0x05eaffff Private Memory Readable, Writable True False False
private_0x0000000005ed0000 0x05ed0000 0x05f0ffff Private Memory Readable, Writable True False False
private_0x0000000005f30000 0x05f30000 0x05f6ffff Private Memory Readable, Writable True False False
private_0x0000000005fb0000 0x05fb0000 0x05feffff Private Memory Readable, Writable True False False
private_0x0000000005ff0000 0x05ff0000 0x0602ffff Private Memory Readable, Writable True False False
private_0x00000000060a0000 0x060a0000 0x060dffff Private Memory Readable, Writable True False False
private_0x0000000006100000 0x06100000 0x0613ffff Private Memory Readable, Writable True False False
private_0x0000000006190000 0x06190000 0x061cffff Private Memory Readable, Writable True False False
private_0x00000000061f0000 0x061f0000 0x0622ffff Private Memory Readable, Writable True False False
private_0x00000000062a0000 0x062a0000 0x062affff Private Memory Readable, Writable True False False
KernelBase.dll.mui 0x062b0000 0x0636ffff Memory Mapped File Readable, Writable False False False
private_0x0000000006370000 0x06370000 0x063affff Private Memory Readable, Writable True False False
private_0x0000000006410000 0x06410000 0x0641ffff Private Memory Readable, Writable True False False
private_0x0000000006450000 0x06450000 0x0648ffff Private Memory Readable, Writable True False False
private_0x00000000064c0000 0x064c0000 0x064fffff Private Memory Readable, Writable True False False
private_0x0000000006550000 0x06550000 0x0658ffff Private Memory Readable, Writable True False False
private_0x00000000065b0000 0x065b0000 0x065bffff Private Memory Readable, Writable True False False
thumbcache_256.db 0x065c0000 0x0666ffff Memory Mapped File Readable, Writable True False False
N3Eg4.51N3E 0x06670000 0x066e4fff Memory Mapped File Readable, Writable, Executable True True False
private_0x0000000006730000 0x06730000 0x0676ffff Private Memory Readable, Writable True False False
private_0x0000000006770000 0x06770000 0x0686ffff Private Memory - True False False
private_0x00000000068c0000 0x068c0000 0x068fffff Private Memory Readable, Writable True False False
private_0x0000000006900000 0x06900000 0x06b92fff Private Memory Readable, Writable True False False
private_0x0000000006ba0000 0x06ba0000 0x06e3bfff Private Memory Readable, Writable True False False
private_0x0000000006e40000 0x06e40000 0x070dffff Private Memory - True False False
private_0x00000000070e0000 0x070e0000 0x0721ffff Private Memory Readable, Writable True False False
private_0x00000000072e0000 0x072e0000 0x0731ffff Private Memory Readable, Writable True False False
private_0x0000000007450000 0x07450000 0x0748ffff Private Memory Readable, Writable True False False
ieproxy.dll 0x6c3f0000 0x6c41afff Memory Mapped File Readable, Writable, Executable False False False
hcproviders.dll 0x6cea0000 0x6cea8fff Memory Mapped File Readable, Writable, Executable False False False
wercplsupport.dll 0x6ceb0000 0x6cec1fff Memory Mapped File Readable, Writable, Executable False False False
werconcpl.dll 0x6ced0000 0x6cfd5fff Memory Mapped File Readable, Writable, Executable False False False
wscui.cpl 0x6cfe0000 0x6d0f9fff Memory Mapped File Readable, Writable, Executable False False False
framedynos.dll 0x6d5e0000 0x6d614fff Memory Mapped File Readable, Writable, Executable False False False
wscinterop.dll 0x6d620000 0x6d639fff Memory Mapped File Readable, Writable, Executable False False False
wscapi.dll 0x6d930000 0x6d93efff Memory Mapped File Readable, Writable, Executable False False False
idndl.dll 0x6e0f0000 0x6e0fafff Memory Mapped File Readable, Writable, Executable False False False
olepro32.dll 0x6e100000 0x6e118fff Memory Mapped File Readable, Writable, Executable False False False
FXSRESM.dll 0x6e120000 0x6e202fff Memory Mapped File Readable, Writable, Executable False False False
FXSAPI.dll 0x6e210000 0x6e249fff Memory Mapped File Readable, Writable, Executable False False False
FXSST.dll 0x6e250000 0x6e321fff Memory Mapped File Readable, Writable, Executable False False False
provsvc.dll 0x6e330000 0x6e35afff Memory Mapped File Readable, Writable, Executable False False False
imapi2.dll 0x6e360000 0x6e3c3fff Memory Mapped File Readable, Writable, Executable False False False
ActionCenter.dll 0x6e3d0000 0x6e489fff Memory Mapped File Readable, Writable, Executable False False False
SyncCenter.dll 0x6e490000 0x6e69dfff Memory Mapped File Readable, Writable, Executable False False False
ieframe.dll 0x6e6a0000 0x6f11ffff Memory Mapped File Readable, Writable, Executable False False False
bthprops.cpl 0x6f120000 0x6f1cffff Memory Mapped File Readable, Writable, Executable False False False
srchadmin.dll 0x6f1f0000 0x6f23cfff Memory Mapped File Readable, Writable, Executable False False False
cscobj.dll 0x6f240000 0x6f264fff Memory Mapped File Readable, Writable, Executable False False False
QAGENT.DLL 0x6f290000 0x6f2bdfff Memory Mapped File Readable, Writable, Executable False False False
WWanAPI.dll 0x6f2c0000 0x6f307fff Memory Mapped File Readable, Writable, Executable False False False
wlanapi.dll 0x6f310000 0x6f325fff Memory Mapped File Readable, Writable, Executable False False False
wwapi.dll 0x6f330000 0x6f339fff Memory Mapped File Readable, Writable, Executable False False False
wlanutil.dll 0x6f340000 0x6f345fff Memory Mapped File Readable, Writable, Executable False False False
QUTIL.DLL 0x6f520000 0x6f536fff Memory Mapped File Readable, Writable, Executable False False False
pnidui.dll 0x6f540000 0x6f6edfff Memory Mapped File Readable, Writable, Executable False False False
PortableDeviceTypes.dll 0x6f6f0000 0x6f71afff Memory Mapped File Readable, Writable, Executable False False False
WPDShServiceObj.dll 0x6f720000 0x6f73cfff Memory Mapped File Readable, Writable, Executable False False False
netshell.dll 0x6f740000 0x6f9a4fff Memory Mapped File Readable, Writable, Executable False False False
security.dll 0x6f9b0000 0x6f9b2fff Memory Mapped File Readable, Writable, Executable False False False
ehSSO.dll 0x6f9c0000 0x6f9c7fff Memory Mapped File Readable, Writable, Executable False False False
AltTab.dll 0x6f9d0000 0x6f9ddfff Memory Mapped File Readable, Writable, Executable False False False
UIAnimation.dll 0x6f9e0000 0x6f9fafff Memory Mapped File Readable, Writable, Executable False False False
Syncreg.dll 0x6fa00000 0x6fa0ffff Memory Mapped File Readable, Writable, Executable False False False
DXP.dll 0x6fa10000 0x6fa73fff Memory Mapped File Readable, Writable, Executable False False False
PortableDeviceApi.dll 0x6fae0000 0x6fb68fff Memory Mapped File Readable, Writable, Executable False False False
winspool.drv 0x6fba0000 0x6fbf0fff Memory Mapped File Readable, Writable, Executable False False False
prnfldr.dll 0x6fc00000 0x6fc63fff Memory Mapped File Readable, Writable, Executable False False False
batmeter.dll 0x6fc70000 0x6fd26fff Memory Mapped File Readable, Writable, Executable False False False
stobject.dll 0x6fd30000 0x6fd69fff Memory Mapped File Readable, Writable, Executable False False False
msftedit.dll 0x6fe90000 0x6ff23fff Memory Mapped File Readable, Writable, Executable False False False
netprofm.dll 0x70690000 0x706e9fff Memory Mapped File Readable, Writable, Executable False False False
midimap.dll 0x70da0000 0x70da6fff Memory Mapped File Readable, Writable, Executable False False False
msacm32.dll 0x70db0000 0x70dc3fff Memory Mapped File Readable, Writable, Executable False False False
msacm32.drv 0x70dd0000 0x70dd7fff Memory Mapped File Readable, Writable, Executable False False False
AudioSes.dll 0x70e70000 0x70ea5fff Memory Mapped File Readable, Writable, Executable False False False
ksuser.dll 0x70eb0000 0x70eb3fff Memory Mapped File Readable, Writable, Executable False False False
wdmaud.drv 0x70ec0000 0x70eeffff Memory Mapped File Readable, Writable, Executable False False False
winmm.dll 0x70ef0000 0x70f21fff Memory Mapped File Readable, Writable, Executable False False False
networkexplorer.dll 0x70f30000 0x710c7fff Memory Mapped File Readable, Writable, Executable False False False
thumbcache.dll 0x710d0000 0x710e5fff Memory Mapped File Readable, Writable, Executable False False False
tiptsf.dll 0x71390000 0x713e7fff Memory Mapped File Readable, Writable, Executable False False False
msls31.dll 0x713f0000 0x71419fff Memory Mapped File Readable, Writable, Executable False False False
npmproxy.dll 0x714b0000 0x714b7fff Memory Mapped File Readable, Writable, Executable False False False
wer.dll 0x714c0000 0x71520fff Memory Mapped File Readable, Writable, Executable False False False
gameux.dll 0x71530000 0x717a7fff Memory Mapped File Readable, Writable, Executable False False False
linkinfo.dll 0x717b0000 0x717b8fff Memory Mapped File Readable, Writable, Executable False False False
shdocvw.dll 0x717c0000 0x717edfff Memory Mapped File Readable, Writable, Executable False False False
actxprxy.dll 0x717f0000 0x7183dfff Memory Mapped File Readable, Writable, Executable False False False
timedate.cpl 0x71840000 0x718b7fff Memory Mapped File Readable, Writable, Executable False False False
IconCodecService.dll 0x71950000 0x71955fff Memory Mapped File Readable, Writable, Executable False False False
ntshrui.dll 0x71960000 0x719cffff Memory Mapped File Readable, Writable, Executable False False False
cscapi.dll 0x71a20000 0x71a2afff Memory Mapped File Readable, Writable, Executable False False False
cscdll.dll 0x71a30000 0x71a38fff Memory Mapped File Readable, Writable, Executable False False False
cscui.dll 0x71a40000 0x71aa9fff Memory Mapped File Readable, Writable, Executable False False False
EhStorShell.dll 0x71ab0000 0x71ae0fff Memory Mapped File Readable, Writable, Executable False False False
apphelp.dll 0x71af0000 0x71b3bfff Memory Mapped File Readable, Writable, Executable False False False
ExplorerFrame.dll 0x71b40000 0x71caefff Memory Mapped File Readable, Writable, Executable False False False
dhcpcsvc.dll 0x72100000 0x72111fff Memory Mapped File Readable, Writable, Executable False False False
dhcpcsvc6.dll 0x72120000 0x7212cfff Memory Mapped File Readable, Writable, Executable False False False
hgcpl.dll 0x72140000 0x7218efff Memory Mapped File Readable, Writable, Executable False False False
oleacc.dll 0x72190000 0x721cbfff Memory Mapped File Readable, Writable, Executable False False False
FWPUCLNT.DLL 0x721e0000 0x72217fff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x72300000 0x72306fff Memory Mapped File Readable, Writable, Executable False False False
IPHLPAPI.DLL 0x72310000 0x7232bfff Memory Mapped File Readable, Writable, Executable False False False
rasadhlp.dll 0x72350000 0x72355fff Memory Mapped File Readable, Writable, Executable False False False
webio.dll 0x73530000 0x7357efff Memory Mapped File Readable, Writable, Executable False False False
winhttp.dll 0x73580000 0x735d7fff Memory Mapped File Readable, Writable, Executable False False False
es.dll 0x736c0000 0x73706fff Memory Mapped File Readable, Writable, Executable False False False
slc.dll 0x73710000 0x73719fff Memory Mapped File Readable, Writable, Executable False False False
taskschd.dll 0x73770000 0x737ecfff Memory Mapped File Readable, Writable, Executable False False False
atl.dll 0x73800000 0x73813fff Memory Mapped File Readable, Writable, Executable False False False
nlaapi.dll 0x73850000 0x7385ffff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x739c0000 0x739e0fff Memory Mapped File Readable, Writable, Executable False False False
samcli.dll 0x73b20000 0x73b2efff Memory Mapped File Readable, Writable, Executable False False False
wkscli.dll 0x73b30000 0x73b3efff Memory Mapped File Readable, Writable, Executable False False False
netutils.dll 0x73b40000 0x73b48fff Memory Mapped File Readable, Writable, Executable False False False
wtsapi32.dll 0x73c50000 0x73c5cfff Memory Mapped File Readable, Writable, Executable False False False
WindowsCodecs.dll 0x73c70000 0x73d6afff Memory Mapped File Readable, Writable, Executable False False False
xmllite.dll 0x73d70000 0x73d9efff Memory Mapped File Readable, Writable, Executable False False False
dwmapi.dll 0x73da0000 0x73db2fff Memory Mapped File Readable, Writable, Executable False False False
hid.dll 0x73dc0000 0x73dc8fff Memory Mapped File Readable, Writable, Executable False False False
SndVolSSO.dll 0x73dd0000 0x73e07fff Memory Mapped File Readable, Writable, Executable False False False
duser.dll 0x73e10000 0x73e3efff Memory Mapped File Readable, Writable, Executable False False False
dui70.dll 0x73e40000 0x73ef1fff Memory Mapped File Readable, Writable, Executable False False False
GdiPlus.dll 0x73f00000 0x7408ffff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x74090000 0x740cffff Memory Mapped File Readable, Writable, Executable False False False
samlib.dll 0x740d0000 0x740e1fff Memory Mapped File Readable, Writable, Executable False False False
shacct.dll 0x740f0000 0x7410dfff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x74110000 0x742adfff Memory Mapped File Readable, Writable, Executable False False False
cryptui.dll 0x742b0000 0x743a7fff Memory Mapped File Readable, Writable, Executable False False False
authui.dll 0x743b0000 0x74566fff Memory Mapped File Readable, Writable, Executable False False False
avrt.dll 0x74590000 0x74596fff Memory Mapped File Readable, Writable, Executable False False False
propsys.dll 0x745a0000 0x74694fff Memory Mapped File Readable, Writable, Executable False False False
MMDevAPI.dll 0x746a0000 0x746d8fff Memory Mapped File Readable, Writable, Executable False False False
powrprof.dll 0x746e0000 0x74704fff Memory Mapped File Readable, Writable, Executable False False False
version.dll 0x748a0000 0x748a8fff Memory Mapped File Readable, Writable, Executable False False False
WSHTCPIP.DLL 0x74930000 0x74934fff Memory Mapped File Readable, Writable, Executable False False False
userenv.dll 0x74a00000 0x74a16fff Memory Mapped File Readable, Writable, Executable False False False
credssp.dll 0x74af0000 0x74af7fff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x74bc0000 0x74bfafff Memory Mapped File Readable, Writable, Executable False False False
dnsapi.dll 0x74ca0000 0x74ce3fff Memory Mapped File Readable, Writable, Executable False False False
wship6.dll 0x74dd0000 0x74dd5fff Memory Mapped File Readable, Writable, Executable False False False
mswsock.dll 0x74de0000 0x74e1bfff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x74e20000 0x74e35fff Memory Mapped File Readable, Writable, Executable False False False
wevtapi.dll 0x74fe0000 0x75021fff Memory Mapped File Readable, Writable, Executable False False False
srvcli.dll 0x751f0000 0x75208fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x75260000 0x75267fff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75280000 0x7529afff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x752a0000 0x752abfff Memory Mapped File Readable, Writable, Executable False False False
sxs.dll 0x752b0000 0x7530efff Memory Mapped File Readable, Writable, Executable False False False
winsta.dll 0x75310000 0x75338fff Memory Mapped File Readable, Writable, Executable False False False
RpcRtRemote.dll 0x75340000 0x7534dfff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x75350000 0x7535afff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x753c0000 0x753cbfff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x753d0000 0x754ecfff Memory Mapped File Readable, Writable, Executable False False False
devobj.dll 0x754f0000 0x75501fff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
wintrust.dll 0x75560000 0x7558cfff Memory Mapped File Readable, Writable, Executable False False False
cfgmgr32.dll 0x75590000 0x755b6fff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75650000 0x75744fff Memory Mapped File Readable, Writable, Executable False False False
Wldap32.dll 0x757d0000 0x75814fff Memory Mapped File Readable, Writable, Executable False False False
normaliz.dll 0x75820000 0x75822fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x759e0000 0x76629fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
setupapi.dll 0x766f0000 0x7688cfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x76890000 0x76a8afff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x76a90000 0x76bebfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76d70000 0x76dc6fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x76e20000 0x76ea2fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x76ee0000 0x76f6efff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x770c0000 0x771f5fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x77340000 0x77345fff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x77360000 0x77364fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x773f0000 0x77424fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
private_0x000000007ff9a000 0x7ff9a000 0x7ff9afff Private Memory Readable, Writable True False False
private_0x000000007ff9b000 0x7ff9b000 0x7ff9bfff Private Memory Readable, Writable True False False
private_0x000000007ff9c000 0x7ff9c000 0x7ff9cfff Private Memory Readable, Writable True False False
private_0x000000007ff9d000 0x7ff9d000 0x7ff9dfff Private Memory Readable, Writable True False False
private_0x000000007ff9e000 0x7ff9e000 0x7ff9efff Private Memory Readable, Writable True False False
private_0x000000007ff9f000 0x7ff9f000 0x7ff9ffff Private Memory Readable, Writable True False False
private_0x000000007ffa0000 0x7ffa0000 0x7ffa0fff Private Memory Readable, Writable True False False
private_0x000000007ffa1000 0x7ffa1000 0x7ffa1fff Private Memory Readable, Writable True False False
private_0x000000007ffa2000 0x7ffa2000 0x7ffa2fff Private Memory Readable, Writable True False False
private_0x000000007ffa3000 0x7ffa3000 0x7ffa3fff Private Memory Readable, Writable True False False
private_0x000000007ffa4000 0x7ffa4000 0x7ffa4fff Private Memory Readable, Writable True False False
private_0x000000007ffa5000 0x7ffa5000 0x7ffa5fff Private Memory Readable, Writable True False False
private_0x000000007ffa6000 0x7ffa6000 0x7ffa6fff Private Memory Readable, Writable True False False
private_0x000000007ffa7000 0x7ffa7000 0x7ffa7fff Private Memory Readable, Writable True False False
private_0x000000007ffa8000 0x7ffa8000 0x7ffa8fff Private Memory Readable, Writable True False False
private_0x000000007ffa9000 0x7ffa9000 0x7ffa9fff Private Memory Readable, Writable True False False
private_0x000000007ffaa000 0x7ffaa000 0x7ffaafff Private Memory Readable, Writable True False False
private_0x000000007ffab000 0x7ffab000 0x7ffabfff Private Memory Readable, Writable True False False
private_0x000000007ffac000 0x7ffac000 0x7ffacfff Private Memory Readable, Writable True False False
private_0x000000007ffad000 0x7ffad000 0x7ffadfff Private Memory Readable, Writable True False False
private_0x000000007ffae000 0x7ffae000 0x7ffaefff Private Memory Readable, Writable True False False
private_0x000000007ffaf000 0x7ffaf000 0x7ffaffff Private Memory Readable, Writable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffd3000 0x7ffd3000 0x7ffd3fff Private Memory Readable, Writable True False False
private_0x000000007ffd4000 0x7ffd4000 0x7ffd4fff Private Memory Readable, Writable True False False
private_0x000000007ffd5000 0x7ffd5000 0x7ffd5fff Private Memory Readable, Writable True False False
private_0x000000007ffd5000 0x7ffd5000 0x7ffd5fff Private Memory Readable, Writable True False False
private_0x000000007ffd6000 0x7ffd6000 0x7ffd6fff Private Memory Readable, Writable True False False
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory Readable, Writable True False False
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory Readable, Writable True False False
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory Readable, Writable True False False
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory Readable, Writable True False False
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory Readable, Writable True False False
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory Readable, Writable True False False
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory Readable, Writable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Injection Information
+
Injection Type Source Process Source Os Thread ID Injection Info Success Count Logfile
Modify Memory c:\windows\system32\regsvr32.exe 0xbfc address = 0x4fd0000, size = 66 True 1
Fn
Data
Create Remote Thread c:\windows\system32\regsvr32.exe 0xbfc os_thread_id = 0xc00, address = 0x75953c01, flags = THREAD_RUNS_IMMEDIATELY True 1
Fn
Threads
Thread 0xc00
(Host: 33, Network: 0)
+
Category Operation Information Success Count Logfile
KEYBOARD GET_INFO type = 0, result_out = 4 True 1
Fn
MOD GET_FILENAME file_name = C:\Users\Public\N3Eg\N3Eg4.51N3E True 1
Fn
MOD GET_FILENAME file_name = C:\Windows\Explorer.EXE True 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Borland\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Borland\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Borland\Delphi\Locales False 1
Fn
MOD LOAD module_name = C:\Users\Public\N3Eg\N3Eg4.ENU, base_address = 0x0 False 1
Fn
MOD LOAD module_name = C:\Users\Public\N3Eg\N3Eg4.EN, base_address = 0x0 False 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetDiskFreeSpaceExA, address = 0x7598f46f True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\oleaut32.dll, base_address = 0x76ee0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VariantChangeTypeEx, address = 0x76ee4c28 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarNeg, address = 0x76f5c802 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarNot, address = 0x76f5ec66 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarAdd, address = 0x76f05934 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarSub, address = 0x76f5d332 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarMul, address = 0x76f5dbd4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarDiv, address = 0x76f5e405 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarIdiv, address = 0x76f5f00a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarMod, address = 0x76f5f15e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarAnd, address = 0x76f05a98 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarOr, address = 0x76f5ecfa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarXor, address = 0x76f5ee2e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarCmp, address = 0x76efb0dc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarI4FromStr, address = 0x76ef6fab True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarR4FromStr, address = 0x76f001a0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarR8FromStr, address = 0x76ef699e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarDateFromStr, address = 0x76f06ba7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarCyFromStr, address = 0x76f26c12 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBoolFromStr, address = 0x76efdbd1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromCy, address = 0x76f07fdc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromDate, address = 0x76ef7a2a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromBool, address = 0x76f00355 True 1
Fn
Thread 0xc04
(Host: 857, Network: 46)
+
Category Operation Information Success Count Logfile
FILE CREATE file_name = c:\users\public\n3eg\n3eg1.51n3e, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE READ file_name = c:\users\public\n3eg\n3eg1.51n3e, size = 2689537 True 1
Fn
MOD LOAD module_name = oleaut32.dll, base_address = 0x76ee0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = SysFreeString, address = 0x76ee3e59 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = SysReAllocStringLen, address = 0x76ee7810 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = SysAllocStringLen, address = 0x76ee45d2 True 1
Fn
MOD LOAD module_name = advapi32.dll, base_address = 0x76650000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegQueryValueExW, address = 0x766646ad True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegOpenKeyExW, address = 0x7666468d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegCloseKey, address = 0x7666469d True 1
Fn
MOD LOAD module_name = user32.dll, base_address = 0x76ca0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MessageBoxA, address = 0x76cfea11 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CharNextW, address = 0x76cb0be6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = LoadStringW, address = 0x76cadfba True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Sleep, address = 0x7594ba46 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualFree, address = 0x75951da4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualAlloc, address = 0x75952fb6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = lstrlenW, address = 0x7594d9e8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualQuery, address = 0x759576d6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = QueryPerformanceCounter, address = 0x7594bb9f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetTickCount, address = 0x7594ba60 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetSystemInfo, address = 0x75953728 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetVersion, address = 0x7594154e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CompareStringW, address = 0x75949bee True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = IsValidLocale, address = 0x75943de4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetThreadLocale, address = 0x759688e6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetSystemDefaultUILanguage, address = 0x7593731d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetUserDefaultUILanguage, address = 0x759422ef True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLocaleInfoW, address = 0x75956596 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WideCharToMultiByte, address = 0x7595450e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = MultiByteToWideChar, address = 0x7595452b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetACP, address = 0x759539aa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LoadLibraryExW, address = 0x75944775 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetStartupInfoW, address = 0x75953891 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetProcAddress, address = 0x759533d3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetModuleHandleW, address = 0x7595374d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetModuleFileNameW, address = 0x75953c26 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetCommandLineW, address = 0x7595679e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FreeLibrary, address = 0x7594d9d0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLastError, address = 0x7594bf00 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = UnhandledExceptionFilter, address = 0x7595ed38 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = RtlUnwind, address = 0x75937f70 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = RaiseException, address = 0x7593eb60 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = ExitProcess, address = 0x7595214f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = ExitThread, address = 0x7722f611 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SwitchToThread, address = 0x7593eb24 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetCurrentThreadId, address = 0x7594bb80 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateThread, address = 0x7595375d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = DeleteCriticalSection, address = 0x77259ac5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LeaveCriticalSection, address = 0x77247760 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = EnterCriticalSection, address = 0x772477a0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = InitializeCriticalSection, address = 0x7725a149 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FindFirstFileW, address = 0x759553b2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FindClose, address = 0x75950e62 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WriteFile, address = 0x75951400 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetStdHandle, address = 0x75951e46 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CloseHandle, address = 0x7594ca7c True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetProcAddress, address = 0x759533d3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = RaiseException, address = 0x7593eb60 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LoadLibraryA, address = 0x7595395c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLastError, address = 0x7594bf00 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = TlsSetValue, address = 0x7594da88 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = TlsGetValue, address = 0x7594da70 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = TlsFree, address = 0x759513b8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = TlsAlloc, address = 0x759535a1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LocalFree, address = 0x7594ca64 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LocalAlloc, address = 0x75953363 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FreeLibrary, address = 0x7594d9d0 True 1
Fn
MOD LOAD module_name = user32.dll, base_address = 0x76ca0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetClassLongW, address = 0x76ca658b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetClassLongW, address = 0x76cb3860 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetWindowLongW, address = 0x76cb4449 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetWindowLongW, address = 0x76cb61b8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CreateWindowExW, address = 0x76caec7c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = keybd_event, address = 0x76cfec3b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = WindowFromPoint, address = 0x76cd6be9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = WaitMessage, address = 0x76cb66bd True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = WaitForInputIdle, address = 0x76cd0397 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = UpdateWindow, address = 0x76caffa8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = UnregisterClassW, address = 0x76cab9ae True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = UnhookWindowsHookEx, address = 0x76caadf9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = TranslateMessage, address = 0x76cb64c7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = TranslateMDISysAccel, address = 0x76cd1a5a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = TrackPopupMenu, address = 0x76cc2228 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SystemParametersInfoW, address = 0x76cae09a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SwitchDesktop, address = 0x76ca476b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ShowWindow, address = 0x76caf2a9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ShowScrollBar, address = 0x76cd3c89 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ShowOwnedPopups, address = 0x76cd28ca True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ShowCaret, address = 0x76ca9334 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetWindowRgn, address = 0x76ca99ec True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetWindowsHookExW, address = 0x76cae30c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetWindowTextW, address = 0x76cb612b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetWindowPos, address = 0x76cb1bc4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetWindowPlacement, address = 0x76ca7f78 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetTimer, address = 0x76cb52ef True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetScrollRange, address = 0x76ca8ec5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetScrollPos, address = 0x76cd04be True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetScrollInfo, address = 0x76cb48da True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetRect, address = 0x76cb498b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetPropW, address = 0x76cb5dc5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetParent, address = 0x76ca8314 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetMenuItemInfoW, address = 0x76cb1799 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetMenu, address = 0x76cd6b0e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetKeyboardState, address = 0x76cd695a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetForegroundWindow, address = 0x76cab225 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetFocus, address = 0x76caabad True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetCursorPos, address = 0x76cec1b0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetCursor, address = 0x76cb3075 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetCapture, address = 0x76cd6932 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetActiveWindow, address = 0x76cb333a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SendMessageTimeoutW, address = 0x76cae459 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SendMessageA, address = 0x76caad60 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SendMessageW, address = 0x76cb5539 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ScrollWindow, address = 0x76ccfc1d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ScreenToClient, address = 0x76caa506 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = RemovePropW, address = 0x76cb5fe1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = RemoveMenu, address = 0x76ca86e8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ReleaseDC, address = 0x76cb5421 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ReleaseCapture, address = 0x76cd69f2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = RegisterWindowMessageW, address = 0x76cadf8d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = RegisterClipboardFormatW, address = 0x76cadf8d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = RegisterClassW, address = 0x76caed4a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = RedrawWindow, address = 0x76cb29bc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = PostQuitMessage, address = 0x76cab308 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = PostMessageW, address = 0x76cb447b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = PeekMessageA, address = 0x76cb19a5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = PeekMessageW, address = 0x76cb634a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = OpenDesktopW, address = 0x76cac669 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MsgWaitForMultipleObjectsEx, address = 0x76cae369 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MsgWaitForMultipleObjects, address = 0x76cb37d8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MoveWindow, address = 0x76ca8d29 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MessageBoxW, address = 0x76cfea5f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MessageBeep, address = 0x76cd2939 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MapWindowPoints, address = 0x76cb5caa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MapVirtualKeyW, address = 0x76cd6a7c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = LoadStringW, address = 0x76cadfba True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = LoadKeyboardLayoutW, address = 0x76cec874 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = LoadIconW, address = 0x76caf142 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = LoadCursorW, address = 0x76caed90 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = LoadBitmapW, address = 0x76ca6460 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = KillTimer, address = 0x76cb64f7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsZoomed, address = 0x76cb4ce9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsWindowVisible, address = 0x76cb4d69 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsWindowUnicode, address = 0x76cb2f55 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsWindowEnabled, address = 0x76caa9b9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsWindow, address = 0x76cb53ba True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsIconic, address = 0x76cb4c8e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsDialogMessageA, address = 0x76cc2019 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsDialogMessageW, address = 0x76cb4104 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsChild, address = 0x76cb3a83 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = InvalidateRect, address = 0x76cb566d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = InsertMenuItemW, address = 0x76caaac5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = InsertMenuW, address = 0x76ca869a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = HideCaret, address = 0x76ca9348 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetWindowThreadProcessId, address = 0x76caee32 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetWindowTextW, address = 0x76cab8c5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetWindowRect, address = 0x76cb558c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetWindowPlacement, address = 0x76cd69de True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetWindowDC, address = 0x76cb4ab7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetTopWindow, address = 0x76cd24d9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetSystemMetrics, address = 0x76cb67cf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetSystemMenu, address = 0x76cafd8b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetSysColorBrush, address = 0x76caf1ed True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetSysColor, address = 0x76cbdb7a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetSubMenu, address = 0x76ca9c19 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetScrollRange, address = 0x76cd045a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetScrollPos, address = 0x76cd0e43 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetScrollInfo, address = 0x76cb2da3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetPropW, address = 0x76cb5bbe True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetParent, address = 0x76cb6029 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetWindow, address = 0x76cb2780 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMessageTime, address = 0x76cd4231 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMessagePos, address = 0x76cd6703 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMessageExtraInfo, address = 0x76cab705 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMenuStringW, address = 0x76cd6528 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMenuState, address = 0x76cd67d2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMenuItemInfoW, address = 0x76caaefa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMenuItemID, address = 0x76ca9cd4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMenuItemCount, address = 0x76caae39 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMenu, address = 0x76cd6b68 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetLastActivePopup, address = 0x76cd6894 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetKeyboardState, address = 0x76cd6946 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetKeyboardLayoutNameW, address = 0x76cefa13 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetKeyboardLayoutList, address = 0x76ca935c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetKeyboardLayout, address = 0x76cb3800 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetKeyState, address = 0x76cb2b4d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetKeyNameTextW, address = 0x76cefa03 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetIconInfo, address = 0x76cb2989 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetGUIThreadInfo, address = 0x76cb237e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetForegroundWindow, address = 0x76cb335d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetFocus, address = 0x76cb3a34 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetDlgCtrlID, address = 0x76cab4e8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetDesktopWindow, address = 0x76cb01a9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetDCEx, address = 0x76cb2d57 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetDC, address = 0x76cb544c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetCursorPos, address = 0x76caa4b3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetCursor, address = 0x76cd6408 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetClipboardData, address = 0x76cc2ba7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetClientRect, address = 0x76cb54dd True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetClassNameW, address = 0x76cb2a29 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetClassInfoExW, address = 0x76cb095e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetClassInfoW, address = 0x76cb0ac2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetCapture, address = 0x76ca9dc7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetActiveWindow, address = 0x76cd3b33 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = FrameRect, address = 0x76cd0eb0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = FindWindowExW, address = 0x76cd712b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = FindWindowW, address = 0x76caae0d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = FillRect, address = 0x76cb5d56 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EnumWindows, address = 0x76cb375b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EnumThreadWindows, address = 0x76cab712 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EnumChildWindows, address = 0x76cb2948 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EndPaint, address = 0x76cb5d42 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EndMenu, address = 0x76ca8302 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EnableWindow, address = 0x76ca8d02 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EnableScrollBar, address = 0x76cd19ce True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EnableMenuItem, address = 0x76cd43bc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DrawTextExW, address = 0x76cb5894 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DrawTextW, address = 0x76cb5b6a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DrawMenuBar, address = 0x76cd15ae True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DrawIconEx, address = 0x76cb2c32 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DrawIcon, address = 0x76ca6427 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DrawFrameControl, address = 0x76ccb4f9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DrawFocusRect, address = 0x76cd3091 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DrawEdge, address = 0x76cb311a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DispatchMessageA, address = 0x76cb2e32 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DispatchMessageW, address = 0x76cbcc61 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DestroyWindow, address = 0x76cab2f4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DestroyMenu, address = 0x76ca87f7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DestroyIcon, address = 0x76caa77f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DestroyCursor, address = 0x76caa77f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DeleteMenu, address = 0x76ca83c2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DefWindowProcW, address = 0x76cb507d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DefMDIChildProcW, address = 0x76cd150a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DefFrameProcW, address = 0x76cd152b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CreatePopupMenu, address = 0x76ca867c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CreateMenu, address = 0x76cd6aed True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CreateIcon, address = 0x76cc7510 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CreateDesktopW, address = 0x76ca40cf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CopyImage, address = 0x76ca87a6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CloseDesktop, address = 0x76cac4ce True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ClientToScreen, address = 0x76cb1316 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CheckMenuItem, address = 0x76ccee7c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CharUpperBuffW, address = 0x76cbebd5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CharUpperW, address = 0x76cbe981 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CharNextW, address = 0x76cb0be6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CharLowerBuffW, address = 0x76cb3afe True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CharLowerW, address = 0x76caba8a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CallWindowProcW, address = 0x76cb1b3c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CallNextHookEx, address = 0x76caabe1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = BeginPaint, address = 0x76cb5d14 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = AdjustWindowRectEx, address = 0x76cb48ba True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ActivateKeyboardLayout, address = 0x76ca8203 True 1
Fn
MOD LOAD module_name = gdi32.dll, base_address = 0x76dd0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = UnrealizeObject, address = 0x76ddfb63 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = StretchBlt, address = 0x76ddf467 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetWindowOrgEx, address = 0x76dd8546 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetWinMetaFileBits, address = 0x76e0d957 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetViewportOrgEx, address = 0x76dd834f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetTextColor, address = 0x76dd6906 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetStretchBltMode, address = 0x76dd7705 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetROP2, address = 0x76ddf9e0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetPixel, address = 0x76df14f3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetMapMode, address = 0x76ddefbf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetEnhMetaFileBits, address = 0x76deb380 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetDIBits, address = 0x76dda995 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetDIBColorTable, address = 0x76df1492 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetBrushOrgEx, address = 0x76ddc4c5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetBkMode, address = 0x76dd69b1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetBkColor, address = 0x76dd6a3c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SelectPalette, address = 0x76dda1f6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SelectObject, address = 0x76dd6640 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SaveDC, address = 0x76dda74b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = RoundRect, address = 0x76df016d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = RestoreDC, address = 0x76dda67b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = Rectangle, address = 0x76ddf1ff True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = RectVisible, address = 0x76dd8f13 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = RealizePalette, address = 0x76ddef91 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = Polyline, address = 0x76de05cf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = Polygon, address = 0x76ddfb87 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = PolyBezierTo, address = 0x76e06c25 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = PolyBezier, address = 0x76e06b03 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = PlayEnhMetaFile, address = 0x76de990d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = Pie, address = 0x76e0569f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = PatBlt, address = 0x76dd62af True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = MoveToEx, address = 0x76dd8c21 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = MaskBlt, address = 0x76ddc7ad True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = LineTo, address = 0x76ddf59b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = LPtoDP, address = 0x76dd8484 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = IntersectClipRect, address = 0x76dd7dfe True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetWindowOrgEx, address = 0x76ddd1bf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetWinMetaFileBits, address = 0x76e0d7cb True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetTextMetricsW, address = 0x76dd7b8f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetTextExtentPointW, address = 0x76ddb358 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetTextExtentPoint32W, address = 0x76ddb4b5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetSystemPaletteEntries, address = 0x76ddc2e1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetStockObject, address = 0x76dd5ddf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetRgnBox, address = 0x76dd621f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetPixel, address = 0x76ddc3d5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetPaletteEntries, address = 0x76ddc2aa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetObjectW, address = 0x76dd7568 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetEnhMetaFilePaletteEntries, address = 0x76e0d1ac True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetEnhMetaFileHeader, address = 0x76decd3a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetEnhMetaFileDescriptionW, address = 0x76e0dc6b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetEnhMetaFileBits, address = 0x76decdc8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetDeviceCaps, address = 0x76dd6f7f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetDIBits, address = 0x76dda23b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetDIBColorTable, address = 0x76dda149 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetCurrentPositionEx, address = 0x76dd8d78 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetClipBox, address = 0x76dd8525 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetBrushOrgEx, address = 0x76ddc943 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetBitmapBits, address = 0x76ddc1ba True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GdiFlush, address = 0x76dd5fe4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = FrameRgn, address = 0x76e05ae2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = ExtTextOutW, address = 0x76dd8192 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = ExtFloodFill, address = 0x76defd94 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = ExcludeClipRect, address = 0x76dd9218 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = EnumFontFamiliesExW, address = 0x76ddce94 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = Ellipse, address = 0x76e055e3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = DeleteObject, address = 0x76dd5f14 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = DeleteEnhMetaFile, address = 0x76debda2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = DeleteDC, address = 0x76dd6eaa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateSolidBrush, address = 0x76dd6b49 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateRectRgn, address = 0x76dd633b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreatePenIndirect, address = 0x76de744d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreatePalette, address = 0x76ddb1b0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateHalftonePalette, address = 0x76ddc2cd True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateFontIndirectW, address = 0x76ddabfc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateEnhMetaFileW, address = 0x76decc1f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateDIBitmap, address = 0x76dda379 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateDIBSection, address = 0x76dd8850 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateCompatibleDC, address = 0x76dd6888 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateCompatibleBitmap, address = 0x76dd73ad True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateBrushIndirect, address = 0x76dd993c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateBitmap, address = 0x76dd6b79 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CopyEnhMetaFileW, address = 0x76e0d651 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CombineRgn, address = 0x76dd651e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CloseEnhMetaFile, address = 0x76dec3fe True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = Chord, address = 0x76e054fa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = BitBlt, address = 0x76dd72c0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = ArcTo, address = 0x76e05436 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = Arc, address = 0x76e0534e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = AngleArc, address = 0x76e05299 True 1
Fn
MOD LOAD module_name = version.dll, base_address = 0x748a0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\version.dll, function = VerQueryValueW, address = 0x748a1b51 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\version.dll, function = GetFileVersionInfoSizeW, address = 0x748a19d9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\version.dll, function = GetFileVersionInfoW, address = 0x748a19f4 True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WriteFile, address = 0x75951400 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WinExec, address = 0x7598e5fd True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WideCharToMultiByte, address = 0x7595450e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WaitForSingleObject, address = 0x7594ba90 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WaitForMultipleObjectsEx, address = 0x7594bc00 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualQueryEx, address = 0x75934e42 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualQuery, address = 0x759576d6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualProtect, address = 0x75942341 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualFree, address = 0x75951da4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualAlloc, address = 0x75952fb6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SwitchToThread, address = 0x7593eb24 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SuspendThread, address = 0x75960ca9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Sleep, address = 0x7594ba46 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SizeofResource, address = 0x75943e7f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetThreadPriority, address = 0x75944815 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetThreadLocale, address = 0x759688e6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetLastError, address = 0x7594bb08 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetFilePointer, address = 0x7594db36 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetEvent, address = 0x7594bccc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetErrorMode, address = 0x75954a51 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetEndOfFile, address = 0x75942319 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = ResumeThread, address = 0x75940f1c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = ResetEvent, address = 0x7594bcb4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = RemoveDirectoryW, address = 0x7593586a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = ReadFile, address = 0x759496fb True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = RaiseException, address = 0x7593eb60 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address = 0x75943ea8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = OpenProcess, address = 0x759459d7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = MulDiv, address = 0x7594b7a0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LockResource, address = 0x7593fd29 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LocalFree, address = 0x7594ca64 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LoadResource, address = 0x7594984d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LoadLibraryW, address = 0x75953c01 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LeaveCriticalSection, address = 0x77247760 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = IsValidLocale, address = 0x75943de4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = InitializeCriticalSection, address = 0x7725a149 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = HeapFree, address = 0x7594bbd0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = HeapDestroy, address = 0x75942301 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = HeapCreate, address = 0x75953ea2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = HeapAlloc, address = 0x77252dd6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GlobalUnlock, address = 0x75949d50 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GlobalSize, address = 0x7593eb78 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GlobalLock, address = 0x75949e05 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GlobalFree, address = 0x75949cf9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GlobalFindAtomW, address = 0x7594912d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GlobalDeleteAtom, address = 0x7593f16c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GlobalAlloc, address = 0x75949ce1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GlobalAddAtomW, address = 0x759470f9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetVolumeInformationW, address = 0x75957598 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetVersionExW, address = 0x75943b1a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetVersion, address = 0x7594154e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetUserDefaultLCID, address = 0x75956584 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetTimeZoneInformation, address = 0x75938a3b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetTickCount, address = 0x7594ba60 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetThreadPriority, address = 0x75949147 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetThreadLocale, address = 0x7594153c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetTempPathW, address = 0x75938b33 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetStdHandle, address = 0x75951e46 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetProcAddress, address = 0x759533d3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetModuleHandleW, address = 0x7595374d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetModuleFileNameW, address = 0x75953c26 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLocaleInfoW, address = 0x75956596 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLocalTime, address = 0x7594a90e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLastError, address = 0x7594bf00 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetFullPathNameW, address = 0x75954543 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetFileSize, address = 0x75940273 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetFileAttributesW, address = 0x759564ff True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetExitCodeThread, address = 0x75936ddd True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetEnvironmentVariableW, address = 0x759565c4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetDiskFreeSpaceW, address = 0x75933530 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetDateFormatW, address = 0x7594afab True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetCurrentThreadId, address = 0x7594bb80 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetCurrentThread, address = 0x75953351 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetCurrentProcessId, address = 0x7594cac4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetCurrentProcess, address = 0x7594cdcf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetComputerNameW, address = 0x759403ff True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetCPInfoExW, address = 0x75938b1b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetCPInfo, address = 0x75951e2e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetACP, address = 0x759539aa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FreeResource, address = 0x7593f1bd True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = InterlockedExchange, address = 0x7594bf0a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = InterlockedCompareExchange, address = 0x7594bb92 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FreeLibrary, address = 0x7594d9d0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FormatMessageW, address = 0x759454a3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FindResourceW, address = 0x75943e61 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FindNextFileW, address = 0x7594963a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FindFirstFileW, address = 0x759553b2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FindClose, address = 0x75950e62 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FileTimeToLocalFileTime, address = 0x75952004 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FileTimeToDosDateTime, address = 0x75942ce1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = EnumSystemLocalesW, address = 0x7598f3df True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = EnumCalendarInfoW, address = 0x7598f38f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = EnterCriticalSection, address = 0x772477a0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = DeleteFileW, address = 0x75940f62 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = DeleteCriticalSection, address = 0x77259ac5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateThread, address = 0x7595375d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateProcessW, address = 0x7590204d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateFileW, address = 0x7594cc56 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateEventW, address = 0x75953386 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateDirectoryW, address = 0x75943925 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CompareStringW, address = 0x75949bee True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CloseHandle, address = 0x7594ca7c True 1
Fn
MOD LOAD module_name = advapi32.dll, base_address = 0x76650000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegSetValueExW, address = 0x766614d6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegQueryValueExW, address = 0x766646ad True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegQueryInfoKeyW, address = 0x766646e7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegOpenKeyExW, address = 0x7666468d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegFlushKey, address = 0x7667773f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegEnumKeyExW, address = 0x766646c8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegCreateKeyExW, address = 0x766640fe True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegCloseKey, address = 0x7666469d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = GetUserNameW, address = 0x7666157a True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Sleep, address = 0x7594ba46 True 1
Fn
MOD LOAD module_name = oleaut32.dll, base_address = 0x76ee0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = SafeArrayPtrOfIndex, address = 0x76efe1ce True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = SafeArrayGetUBound, address = 0x76efe127 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = SafeArrayGetLBound, address = 0x76efe173 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = SafeArrayCreate, address = 0x76efe263 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VariantChangeType, address = 0x76ee5dee True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VariantCopyInd, address = 0x76efe86c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VariantCopy, address = 0x76ee48f1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VariantClear, address = 0x76ee3eae True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VariantInit, address = 0x76ee3ed5 True 1
Fn
MOD LOAD module_name = oleaut32.dll, base_address = 0x76ee0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = GetErrorInfo, address = 0x76ee3f21 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = GetActiveObject, address = 0x76f28f58 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = SysFreeString, address = 0x76ee3e59 True 1
Fn
MOD LOAD module_name = ole32.dll, base_address = 0x76a90000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CreateStreamOnHGlobal, address = 0x76ab363b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = IsAccelerator, address = 0x76b5043e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = OleDraw, address = 0x76b10286 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = OleSetMenuDescriptor, address = 0x76aedc53 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = OleUninitialize, address = 0x76aaeba1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = OleInitialize, address = 0x76aaefd7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoTaskMemFree, address = 0x76ae6f41 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoTaskMemAlloc, address = 0x76adea4c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = ProgIDFromCLSID, address = 0x76b1ef82 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = StringFromCLSID, address = 0x76aaeb17 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoCreateInstance, address = 0x76ad9d0b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoGetClassObject, address = 0x76ac54ad True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoUninitialize, address = 0x76ad86d3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoInitialize, address = 0x76aab636 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = IsEqualGUID, address = 0x76b5041c True 1
Fn
MOD LOAD module_name = comctl32.dll, base_address = 0x74110000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = InitializeFlatSB, address = 0x741ef803 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_SetScrollProp, address = 0x741907d0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_SetScrollPos, address = 0x74190894 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_SetScrollInfo, address = 0x741908c7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_GetScrollPos, address = 0x741ef80e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_GetScrollInfo, address = 0x741908b6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = _TrackMouseEvent, address = 0x741922d1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_SetIconSize, address = 0x741fb44e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_GetIconSize, address = 0x741250df True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_Write, address = 0x74158b97 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_Read, address = 0x74113eae True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_GetDragImage, address = 0x741fafbb True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_DragShowNolock, address = 0x741fb161 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_DragMove, address = 0x741fb0f0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_DragLeave, address = 0x741fb12a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_DragEnter, address = 0x741fb0b3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_EndDrag, address = 0x741fa177 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_BeginDrag, address = 0x741fb021 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_GetIcon, address = 0x7413af2e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_Remove, address = 0x7413e333 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_DrawEx, address = 0x741210fd True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_Draw, address = 0x741ac687 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_GetBkColor, address = 0x7412e8d2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_SetBkColor, address = 0x74190183 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_Add, address = 0x74168fa1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_SetImageCount, address = 0x74165249 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_GetImageCount, address = 0x7411a8b9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_Destroy, address = 0x74126471 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_Create, address = 0x74123c75 True 1
Fn
MOD LOAD module_name = user32.dll, base_address = 0x76ca0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EnumDisplayMonitors, address = 0x76cb34a3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMonitorInfoW, address = 0x76cb33e7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MonitorFromPoint, address = 0x76ca94c9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MonitorFromWindow, address = 0x76cb3622 True 1
Fn
MOD LOAD module_name = msvcrt.dll, base_address = 0x76f70000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\msvcrt.dll, function = memset, address = 0x76f79790 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\msvcrt.dll, function = memcpy, address = 0x76f79910 True 1
Fn
MOD LOAD module_name = shell32.dll, base_address = 0x759e0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\shell32.dll, function = ShellExecuteW, address = 0x759f3c71 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\shell32.dll, function = Shell_NotifyIconW, address = 0x75a001c1 True 1
Fn
MOD LOAD module_name = wininet.dll, base_address = 0x75650000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\wininet.dll, function = FindNextUrlCacheEntryW, address = 0x7568989c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\wininet.dll, function = FindFirstUrlCacheEntryW, address = 0x7568978a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\wininet.dll, function = FindCloseUrlCache, address = 0x75698409 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\wininet.dll, function = DeleteUrlCacheEntryW, address = 0x756a9573 True 1
Fn
MOD LOAD module_name = user32.dll, base_address = 0x76ca0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetRawInputData, address = 0x76d04c21 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = RegisterRawInputDevices, address = 0x76ca5b52 True 1
Fn
MOD LOAD module_name = oleacc.dll, base_address = 0x72190000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleacc.dll, function = AccessibleObjectFromWindow, address = 0x72192480 True 1
Fn
MOD LOAD module_name = OLEACC.DLL, base_address = 0x72190000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleacc.dll, function = AccessibleChildren, address = 0x72195d25 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetThreadPreferredUILanguages, address = 0x759422d7 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetThreadPreferredUILanguages, address = 0x7593e627 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetThreadUILanguage, address = 0x7593ae42 True 1
Fn
SYS GET_INFO type = Hardware Information True 1
Fn
MOD GET_FILENAME file_name = False 1
Fn
MOD GET_FILENAME file_name = C:\Windows\Explorer.EXE True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetNativeSystemInfo, address = 0x7593be77 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetDiskFreeSpaceExW, address = 0x7593de40 True 1
Fn
MOD GET_FILENAME file_name = C:\Windows\Explorer.EXE True 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Embarcadero\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Embarcadero\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\CodeGear\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\CodeGear\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Borland\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Borland\Delphi\Locales False 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\oleaut32.dll, base_address = 0x76ee0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VariantChangeTypeEx, address = 0x76ee4c28 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarNeg, address = 0x76f5c802 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarNot, address = 0x76f5ec66 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarAdd, address = 0x76f05934 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarSub, address = 0x76f5d332 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarMul, address = 0x76f5dbd4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarDiv, address = 0x76f5e405 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarIdiv, address = 0x76f5f00a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarMod, address = 0x76f5f15e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarAnd, address = 0x76f05a98 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarOr, address = 0x76f5ecfa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarXor, address = 0x76f5ee2e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarCmp, address = 0x76efb0dc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarI4FromStr, address = 0x76ef6fab True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarR4FromStr, address = 0x76f001a0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarR8FromStr, address = 0x76ef699e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarDateFromStr, address = 0x76f06ba7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarCyFromStr, address = 0x76f26c12 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBoolFromStr, address = 0x76efdbd1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromCy, address = 0x76f07fdc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromDate, address = 0x76ef7a2a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromBool, address = 0x76f00355 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = InitializeConditionVariable, address = 0x77259981 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WakeConditionVariable, address = 0x772a5a7b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WakeAllConditionVariable, address = 0x772245a5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SleepConditionVariableCS, address = 0x759318be True 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes, value_name = MS Shell Dlg 2, data_ident_out = 0 True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes, value_name = MS Shell Dlg 2, data_ident_out = Tahoma True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLogicalProcessorInformation, address = 0x75932004 True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLogicalProcessorInformation, address = 0x75932004 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\ole32.dll, base_address = 0x76a90000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoCreateInstanceEx, address = 0x76ad9d4e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoInitializeEx, address = 0x76ad09ad True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoAddRefServerProcess, address = 0x76af3cf3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoReleaseServerProcess, address = 0x76af4314 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoResumeClassObjects, address = 0x76a9ea02 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoSuspendClassObjects, address = 0x76afbb02 True 1
Fn
MOD LOAD module_name = imm32.dll, base_address = 0x76630000 True 1
Fn
KEYBOARD GET_INFO type = KB_LOCALE_ID, os_tid = 0, result_out = 67699721 True 1
Fn
MOD GET_FILENAME file_name = C:\Windows\Explorer.EXE True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
KEYBOARD GET_INFO type = KB_LOCALE_ID True 1
Fn
MOD LOAD module_name = imm32.dll, base_address = 0x76630000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\imm32.dll, function = ImmIsIME, address = 0x76632ceb True 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04090409 False 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\user32.dll, base_address = 0x76ca0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = AnimateWindow, address = 0x76cd0620 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, base_address = 0x74110000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = InitializeFlatSB, address = 0x741ef803 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = UninitializeFlatSB, address = 0x7411d1ea True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_GetScrollProp, address = 0x741ef81f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_SetScrollProp, address = 0x741907d0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_EnableScrollBar, address = 0x741ef84b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_ShowScrollBar, address = 0x741ef83a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_GetScrollRange, address = 0x741ef829 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_GetScrollInfo, address = 0x741908b6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_GetScrollPos, address = 0x741ef80e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_SetScrollPos, address = 0x74190894 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_SetScrollInfo, address = 0x741908c7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_SetScrollRange, address = 0x741908a5 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\user32.dll, base_address = 0x76ca0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetLayeredWindowAttributes, address = 0x76caa6dc True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\user32.dll, base_address = 0x76ca0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsHungAppWindow, address = 0x76cd7195 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = HungWindowFromGhostWindow, address = 0x76cc61f5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GhostWindowFromHungWindow, address = 0x76caa561 True 1
Fn
MOD LOAD module_name = olepro32.dll, base_address = 0x6e100000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\olepro32.dll, function = OleCreatePropertyFrame, address = 0x6e1020ea True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\olepro32.dll, function = OleCreateFontIndirect, address = 0x6e1020b7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\olepro32.dll, function = OleCreatePictureIndirect, address = 0x6e1020c8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\olepro32.dll, function = OleLoadPicture, address = 0x6e1020d9 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetFileSizeEx, address = 0x759459ef True 1
Fn
MOD LOAD module_name = security.dll, base_address = 0x6f9b0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\security.dll, function = InitSecurityInterfaceW, address = 0x75285b53 True 1
Fn
WND CREATE window_name = Explorer, class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0, window_parameter = 0 True 1
Fn
MOD LOAD module_name = wtsapi32.dll, base_address = 0x73c50000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\wtsapi32.dll, function = WTSRegisterSessionNotification, address = 0x73c51cbc True 1
Fn
MOD LOAD module_name = uxtheme.dll, base_address = 0x74090000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = BufferedPaintInit, address = 0x7409940e True 1
Fn
WND SET_ATTRIBUTE window_name = Explorer, class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0 True 1
Fn
MOD LOAD module_name = uxtheme.dll, base_address = 0x74090000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = OpenThemeData, address = 0x740973d2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = CloseThemeData, address = 0x74096a18 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = DrawThemeBackground, address = 0x74093982 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = DrawThemeText, address = 0x74094ea1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeBackgroundContentRect, address = 0x7409cd2e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeBackgroundExtent, address = 0x7409f8bf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemePartSize, address = 0x7409cdb1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeTextExtent, address = 0x74092d57 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeTextMetrics, address = 0x7409f992 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeBackgroundRegion, address = 0x740a165d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = HitTestThemeBackground, address = 0x740a3ce3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = DrawThemeEdge, address = 0x740b3b52 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = DrawThemeIcon, address = 0x740c35e7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = IsThemePartDefined, address = 0x740985b4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = IsThemeBackgroundPartiallyTransparent, address = 0x740960ab True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeColor, address = 0x7409616c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeMetric, address = 0x740a06e2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeString, address = 0x740c22e4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeBool, address = 0x74097c1f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeInt, address = 0x7409616c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeEnumValue, address = 0x7409616c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemePosition, address = 0x740c2350 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeFont, address = 0x7409ff21 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeRect, address = 0x740a3611 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeMargins, address = 0x740986e9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeIntList, address = 0x740c23b1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemePropertyOrigin, address = 0x740b3fbb True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = SetWindowTheme, address = 0x740a0134 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeFilename, address = 0x740c2412 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeSysColor, address = 0x740b3274 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeSysColorBrush, address = 0x740c301e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeSysBool, address = 0x740c3172 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeSysSize, address = 0x740c320b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeSysFont, address = 0x740c29c4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeSysString, address = 0x740c2b3f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeSysInt, address = 0x740c2bd3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = IsThemeActive, address = 0x7409f785 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = IsAppThemed, address = 0x7409f869 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetWindowTheme, address = 0x7409df46 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = EnableThemeDialogTexture, address = 0x7409fcaf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = IsThemeDialogTextureEnabled, address = 0x740c312b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeAppProperties, address = 0x740a0fb1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = SetThemeAppProperties, address = 0x740c3296 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetCurrentThemeName, address = 0x740a05dd True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeDocumentationProperty, address = 0x740c2932 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = DrawThemeParentBackground, address = 0x740953e5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = EnableTheming, address = 0x740c2feb True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = DrawThemeTextEx, address = 0x740963e6 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SYS SLEEP duration = 1500 milliseconds (1.500 seconds) True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SYS SLEEP duration = 1000 milliseconds (1.000 seconds) True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SYS SLEEP duration = 60000 milliseconds (60.000 seconds) True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SYS SLEEP duration = 1000 milliseconds (1.000 seconds) True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SYS SLEEP duration = 60000 milliseconds (60.000 seconds) True 1
Fn
WND SET_ATTRIBUTE window_name = Explorer, class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0 True 1
Fn
WND CREATE window_name = Explorer, window_name = FrmMwM41n, class_name = TFrmMwM41n, x_coordinate = 18446744073709551164, y_coordinate = 18446744073709551164, width = 320, height = 240, class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = FrmMwM41n, class_name = TFrmMwM41n, x_coordinate = 18446744073709551164, y_coordinate = 18446744073709551164, width = 320, height = 240 True 1
Fn
WND SET_ATTRIBUTE window_name = FrmMwM41n, class_name = TFrmMwM41n, x_coordinate = 18446744073709551164, y_coordinate = 18446744073709551164, width = 320, height = 240 True 1
Fn
WND FIND window_name = k8w0 False 1
Fn
SYS SLEEP duration = 600000 milliseconds (600.000 seconds) True 1
Fn
FILE DELETE file_name = c:\users\public\n3eg\n3e.vbs False 1
Fn
FILE CREATE file_name = c:\users\public\n3eg\wvs, desired_access = GENERIC_WRITE, GENERIC_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE WRITE file_name = c:\users\public\n3eg\wvs, size = 4 True 1
Fn
Data
FILE CREATE file_name = c:\users\public\n3eg\idw, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE READ file_name = c:\users\public\n3eg\idw, size = 2 True 1
Fn
Data
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run True 1
Fn
REG WRITE_VALUE reg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, value_name = xacwe, data = regsvr32.exe /s "C:\Users\Public\N3Eg\N3Eg2.51N3E" #96 True 1
Fn
SYS SLEEP duration = 20000 milliseconds (20.000 seconds) True 1
Fn
FILE CREATE file_name = c:\users\public\n3eg\idx, desired_access = GENERIC_WRITE, GENERIC_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE WRITE file_name = c:\users\public\n3eg\idx, size = 10 True 1
Fn
Data
SYS SLEEP duration = 70000 milliseconds (70.000 seconds) True 1
Fn
WND SET_ATTRIBUTE window_name = Explorer, class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0 True 1
Fn
SYS GET_CURSOR x_out = 991, y_out = 872 True 12
Fn
SYS GET_CURSOR x_out = 1126, y_out = 518 True 10
Fn
MOD LOAD module_name = WS2_32.DLL, base_address = 0x773f0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = WSAStartup, address = 0x773f3ab2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = GetAddrInfoW, address = 0x773f4889 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = GetNameInfoW, address = 0x773f66af True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = FreeAddrInfoW, address = 0x773f4b1b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = InetPtonW, address = 0x774039dc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = InetNtopW, address = 0x77403abf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = GetAddrInfoExW, address = 0x773fd1ea True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = SetAddrInfoExW, address = 0x773ff4f6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = FreeAddrInfoExW, address = 0x773fe14d True 1
Fn
MOD LOAD module_name = Fwpuclnt.dll, base_address = 0x721e0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\fwpuclnt.dll, function = WSASetSocketPeerTargetName, address = 0x721fbb1e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\fwpuclnt.dll, function = WSADeleteSocketPeerTargetName, address = 0x721fbb4e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\fwpuclnt.dll, function = WSAImpersonateSocketPeer, address = 0x721fbb7e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\fwpuclnt.dll, function = WSAQuerySocketSecurity, address = 0x721fbaed True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\fwpuclnt.dll, function = WSARevertImpersonation, address = 0x721fbcfd True 1
Fn
MOD LOAD module_name = IdnDL.dll, base_address = 0x6e0f0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\idndl.dll, function = DownlevelGetLocaleScripts, address = 0x6e0f2a5b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\idndl.dll, function = DownlevelGetStringScripts, address = 0x6e0f2b2f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\idndl.dll, function = DownlevelVerifyScripts, address = 0x6e0f2dad True 1
Fn
MOD LOAD module_name = Normaliz.dll, base_address = 0x75820000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\normaliz.dll, function = IdnToUnicode, address = 0x7599f707 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\normaliz.dll, function = IdnToNameprepUnicode, address = 0x7599f6b4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\normaliz.dll, function = IdnToAscii, address = 0x75938bb8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\normaliz.dll, function = IsNormalizedString, address = 0x7599f662 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\normaliz.dll, function = NormalizeString, address = 0x7599f5ea True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = socket, address = 0x773f3eb8 True 1
Fn
SCK CREATE address_family = AF_INET, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = getsockopt, address = 0x773f737d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = setsockopt, address = 0x773f41b6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = htons, address = 0x773f2d8b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = bind, address = 0x773f4582 True 1
Fn
SCK BIND local_address = 0.0.0.0, local_port = 0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = getsockname, address = 0x773f30af True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = ntohs, address = 0x773f2d8b True 1
Fn
DNS RESOLVE_NAME host = carvas32ltda.com True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = connect, address = 0x773f6bdd True 1
Fn
SCK CONNECT remote_address = 187.191.100.112, remote_port = 80 False 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = WSAGetLastError, address = 0x773f37ad True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = shutdown, address = 0x773f449d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = closesocket, address = 0x773f3918 True 1
Fn
SCK CREATE address_family = AF_INET, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
SCK BIND local_address = 0.0.0.0, local_port = 0 True 1
Fn
DNS RESOLVE_NAME host = carva32ssa.com True 1
Fn
SCK CONNECT remote_address = 187.191.100.112, remote_port = 80 False 1
Fn
SCK CREATE address_family = AF_INET, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
SCK BIND local_address = 0.0.0.0, local_port = 0 True 1
Fn
DNS RESOLVE_NAME host = bandeivacomercial.com True 1
Fn
SCK CONNECT remote_address = 187.191.100.112, remote_port = 80 False 1
Fn
SCK CREATE address_family = AF_INET, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
SCK BIND local_address = 0.0.0.0, local_port = 0 True 1
Fn
DNS RESOLVE_NAME host = bandeivacomercio.com True 1
Fn
SCK CONNECT remote_address = 187.191.100.112, remote_port = 80 False 1
Fn
SYS SLEEP duration = 600000 milliseconds (600.000 seconds) True 1
Fn
SCK CREATE address_family = AF_INET, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
SCK BIND local_address = 0.0.0.0, local_port = 0 True 1
Fn
DNS RESOLVE_NAME host = carvas32ltda.com True 1
Fn
SCK CONNECT remote_address = 187.191.100.112, remote_port = 80 False 1
Fn
SCK CREATE address_family = AF_INET, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
SCK BIND local_address = 0.0.0.0, local_port = 0 True 1
Fn
DNS RESOLVE_NAME host = carva32ssa.com True 1
Fn
SCK CONNECT remote_address = 187.191.100.112, remote_port = 80 False 1
Fn
SCK CREATE address_family = AF_INET, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
SCK BIND local_address = 0.0.0.0, local_port = 0 True 1
Fn
DNS RESOLVE_NAME host = bandeivacomercial.com True 1
Fn
SCK CONNECT remote_address = 187.191.100.112, remote_port = 80 False 1
Fn
SCK CREATE address_family = AF_INET, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
SCK BIND local_address = 0.0.0.0, local_port = 0 True 1
Fn
DNS RESOLVE_NAME host = bandeivacomercio.com True 1
Fn
SCK CONNECT remote_address = 187.191.100.112, remote_port = 80 False 1
Fn
USER GET_CURRENT user_name = DSsDPMx042 True 2
Fn
FILE CREATE file_name = c:\users\public\n3eg\n3e.vbs, desired_access = GENERIC_WRITE, GENERIC_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE WRITE file_name = c:\users\public\n3eg\n3e.vbs, size = 4199 True 1
Fn
Data
PROC CREATE process_name = cmd /k "C:\Users\Public\N3Eg\N3E.vbs", show_window = SW_HIDE True 1
Fn
FILE CREATE file_name = c:\users\public\n3eg\id, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE READ file_name = c:\users\public\n3eg\id, size = 7 True 1
Fn
Data
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateToolhelp32Snapshot, address = 0x7593f731 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Heap32ListFirst, address = 0x759902e7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Heap32ListNext, address = 0x75990391 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Heap32First, address = 0x75990429 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Heap32Next, address = 0x75990614 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Toolhelp32ReadProcessMemory, address = 0x75990819 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32First, address = 0x7596443d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32Next, address = 0x75964505 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32FirstW, address = 0x7593fa35 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32NextW, address = 0x7593faca True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32FirstW, address = 0x7593fa35 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32NextW, address = 0x7593faca True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Thread32First, address = 0x75967e4c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Thread32Next, address = 0x75967edc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32First, address = 0x75990859 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32Next, address = 0x75990942 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32FirstW, address = 0x7593c59e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32NextW, address = 0x7593c11f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32FirstW, address = 0x7593c59e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32NextW, address = 0x7593c11f True 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion False 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VerLanguageNameW, address = 0x75938ca1 True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetSystemDefaultLangID, address = 0x7593db6e True 1
Fn
SCK CREATE address_family = AF_INET, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
SCK BIND local_address = 0.0.0.0, local_port = 0 True 1
Fn
DNS RESOLVE_NAME host = adom2.com.br True 1
Fn
SCK CONNECT remote_address = 127.0.0.1, remote_port = 80 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = getpeername, address = 0x773f7147 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = send, address = 0x773f6f01 True 1
Fn
SCK SEND size = 331, flags = NO_FLAG_SET, size_out = 331 True 1
Fn
Data
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = select, address = 0x773f6989 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = recv, address = 0x773f6b0e True 1
Fn
SCK RECV size = 32768, flags = NO_FLAG_SET, size_out = 523 True 1
Fn
SCK RECV size = 32768, flags = NO_FLAG_SET, size_out = 453 True 1
Fn
SCK RECV size = 32768, flags = NO_FLAG_SET, size_out = 246 True 1
Fn
SCK RECV size = 32768, flags = NO_FLAG_SET, size_out = 200 True 1
Fn
SCK RECV size = 32768, flags = NO_FLAG_SET, size_out = 9 True 1
Fn
SCK CREATE address_family = AF_INET, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
SCK BIND local_address = 0.0.0.0, local_port = 0 True 1
Fn
DNS RESOLVE_NAME host = carvas32ltda.com True 1
Fn
SCK CONNECT remote_address = 187.191.100.112, remote_port = 80 False 1
Fn
Process #5: cmd.exe
(Host: 39, Network: 0)
+
Information Value
ID / OS PID #5 / 0xef8
OS Parent PID 0x4f0 (c:\windows\explorer.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\cmd.exe
Command Line cmd /k "C:\Users\Public\N3Eg\N3E.vbs"
Monitor Start Time: 00:03:41, Reason: Child Process
Unmonitor End Time: 00:03:50, Reason: Terminated
Monitor Duration 00:00:09
OS Thread IDs
# 80
0x EFC
# 82
0x F18
# 83
0x F1C
# 84
0x F20
# 85
0x F24
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
private_0x00000000000c0000 0x000c0000 0x001bffff Private Memory Readable, Writable True False False
pagefile_0x00000000001c0000 0x001c0000 0x001c6fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000001d0000 0x001d0000 0x001d1fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000001e0000 0x001e0000 0x001e0fff Private Memory Readable, Writable True False False
private_0x00000000001f0000 0x001f0000 0x001f0fff Private Memory Readable, Writable True False False
pagefile_0x0000000000200000 0x00200000 0x00201fff Pagefile Backed Memory Readable True False False
private_0x0000000000210000 0x00210000 0x0021ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000220000 0x00220000 0x002e7fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000002f0000 0x002f0000 0x002f0fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000300000 0x00300000 0x00301fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000310000 0x00310000 0x00310fff Pagefile Backed Memory Readable True False False
private_0x0000000000320000 0x00320000 0x0041ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000420000 0x00420000 0x00520fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000530000 0x00530000 0x0112ffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001130000 0x01130000 0x013bafff Pagefile Backed Memory Readable True False False
SortDefault.nls 0x013c0000 0x0168efff Memory Mapped File Readable False False False
pagefile_0x0000000001690000 0x01690000 0x01690fff Pagefile Backed Memory Readable True False False
cversions.2.db 0x016a0000 0x016a3fff Memory Mapped File Readable True False False
{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000000c.db 0x016b0000 0x016ccfff Memory Mapped File Readable True False False
pagefile_0x00000000016d0000 0x016d0000 0x016d0fff Pagefile Backed Memory Readable, Writable True False False
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000007.db 0x016e0000 0x0170ffff Memory Mapped File Readable True False False
cversions.2.db 0x01710000 0x01713fff Memory Mapped File Readable True False False
pagefile_0x0000000001720000 0x01720000 0x01720fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000001740000 0x01740000 0x0183ffff Private Memory Readable, Writable True False False
pagefile_0x0000000001840000 0x01840000 0x0191efff Pagefile Backed Memory Readable True False False
private_0x0000000001950000 0x01950000 0x0198ffff Private Memory Readable, Writable True False False
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db 0x01990000 0x019f5fff Memory Mapped File Readable True False False
pagefile_0x0000000001a00000 0x01a00000 0x01df2fff Pagefile Backed Memory Readable True False False
private_0x0000000001e00000 0x01e00000 0x01efffff Private Memory Readable, Writable True False False
private_0x0000000001f90000 0x01f90000 0x0208ffff Private Memory Readable, Writable True False False
private_0x0000000002160000 0x02160000 0x0225ffff Private Memory Readable, Writable True False False
cmd.exe 0x4a810000 0x4a85bfff Memory Mapped File Readable, Writable, Executable True False False
winbrand.dll 0x6dd80000 0x6dd86fff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x739c0000 0x739e0fff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x74090000 0x740cffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x74110000 0x742adfff Memory Mapped File Readable, Writable, Executable False False False
propsys.dll 0x745a0000 0x74694fff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75280000 0x7529afff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x752a0000 0x752abfff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x75350000 0x7535afff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x753c0000 0x753cbfff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x753d0000 0x754ecfff Memory Mapped File Readable, Writable, Executable False False False
devobj.dll 0x754f0000 0x75501fff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
cfgmgr32.dll 0x75590000 0x755b6fff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75650000 0x75744fff Memory Mapped File Readable, Writable, Executable False False False
Wldap32.dll 0x757d0000 0x75814fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x759e0000 0x76629fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
setupapi.dll 0x766f0000 0x7688cfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x76890000 0x76a8afff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x76a90000 0x76bebfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76d70000 0x76dc6fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x76e20000 0x76ea2fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x76ee0000 0x76f6efff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x770c0000 0x771f5fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffd3000 0x7ffd3000 0x7ffd3fff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory Readable, Writable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Threads
Thread 0xefc
(Host: 39, Network: 0)
+
Category Operation Information Success Count Logfile
MOD GET_HANDLE module_name = c:\windows\system32\cmd.exe, base_address = 0x4a810000 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address = 0x759524c2 True 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
FILE OPEN file_name = STD_OUTPUT_HANDLE True 3
Fn
FILE OPEN file_name = STD_INPUT_HANDLE True 2
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data_ident_out = 0 False 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data_ident_out = 0 True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data_ident_out = 64 True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data_ident_out = 64 True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data_ident_out = 64 False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data_ident_out = 64 False 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data_ident_out = 0 True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data_ident_out = 9 True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data_ident_out = 9 True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data_ident_out = 9 False 1
Fn
MOD GET_FILENAME file_name = C:\Windows\system32\cmd.exe True 1
Fn
PROC SET_CURDIR process_name = c:\windows\system32\cmd.exe, os_pid = 0xef8, new_path_name = c:\windows\system32 True 1
Fn
FILE OPEN file_name = STD_OUTPUT_HANDLE True 4
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address = 0x7593ac6c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address = 0x75943ea8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address = 0x75952732 True 1
Fn
PROC CREATE process_name = C:\Users\Public\N3Eg\N3E.vbs, os_tid = 0x0, os_pid = 0x0, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, current_directory = C:\Windows\system32, show_window = SW_SHOWNORMAL False 1
Fn
MOD LOAD module_name = SHELL32.dll, base_address = 0x759e0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\shell32.dll, function = ShellExecuteExW, address = 0x75a01e46 True 1
Fn
PROC CREATE process_name = C:\Users\Public\N3Eg\N3E.vbs, current_directory = C:\Windows\system32, show_window = SW_SHOWNORMAL True 1
Fn
Process #6: wscript.exe
(Host: 92, Network: 0)
+
Information Value
ID / OS PID #6 / 0xf28
OS Parent PID 0xef8 (c:\windows\system32\cmd.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\wscript.exe
Command Line "C:\Windows\System32\WScript.exe" "C:\Users\Public\N3Eg\N3E.vbs"
Monitor Start Time: 00:03:42, Reason: Child Process
Unmonitor End Time: 00:03:50, Reason: Terminated
Monitor Duration 00:00:08
OS Thread IDs
# 86
0x F2C
# 87
0x F30
# 88
0x F34
# 89
0x F38
# 90
0x F3C
# 91
0x F40
# 92
0x F44
# 93
0x F48
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00041fff Pagefile Backed Memory Readable, Writable True False False
wscript.exe.mui 0x00050000 0x00052fff Memory Mapped File Readable, Writable False False False
private_0x0000000000060000 0x00060000 0x00060fff Private Memory Readable, Writable True False False
private_0x0000000000070000 0x00070000 0x00070fff Private Memory Readable, Writable True False False
wscript.exe 0x00080000 0x000a5fff Memory Mapped File Readable, Writable, Executable True False False
private_0x00000000000b0000 0x000b0000 0x001affff Private Memory Readable, Writable True False False
private_0x00000000001b0000 0x001b0000 0x002affff Private Memory Readable, Writable True False False
locale.nls 0x002b0000 0x00316fff Memory Mapped File Readable False False False
wscript.exe 0x00320000 0x0032efff Memory Mapped File Readable True False False
pagefile_0x0000000000330000 0x00330000 0x00330fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000340000 0x00340000 0x00340fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000350000 0x00350000 0x00351fff Pagefile Backed Memory Readable True False False
private_0x0000000000350000 0x00350000 0x0035ffff Private Memory Readable, Writable True False False
private_0x0000000000360000 0x00360000 0x0036ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000370000 0x00370000 0x00437fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000440000 0x00440000 0x00540fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000550000 0x00550000 0x0114ffff Pagefile Backed Memory Readable True False False
scrrun.dll 0x01150000 0x01164fff Memory Mapped File Readable True False False
shell32.dll 0x01170000 0x01182fff Memory Mapped File Readable False False False
pagefile_0x0000000001190000 0x01190000 0x01190fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x00000000011a0000 0x011a0000 0x011a1fff Pagefile Backed Memory Readable True False False
oleaccrc.dll 0x011b0000 0x011b0fff Memory Mapped File Readable False False False
pagefile_0x00000000011c0000 0x011c0000 0x011c1fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000011d0000 0x011d0000 0x011d1fff Pagefile Backed Memory Readable True False False
cversions.2.db 0x011e0000 0x011e3fff Memory Mapped File Readable True False False
pagefile_0x00000000011f0000 0x011f0000 0x011f0fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000001200000 0x01200000 0x0123ffff Private Memory Readable, Writable True False False
pagefile_0x0000000001240000 0x01240000 0x0131efff Pagefile Backed Memory Readable True False False
{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000000c.db 0x01320000 0x0133cfff Memory Mapped File Readable True False False
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000007.db 0x01340000 0x0136ffff Memory Mapped File Readable True False False
cversions.2.db 0x01370000 0x01373fff Memory Mapped File Readable True False False
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db 0x01380000 0x013e5fff Memory Mapped File Readable True False False
pagefile_0x00000000013f0000 0x013f0000 0x013f0fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000001400000 0x01400000 0x014fffff Private Memory Readable, Writable True False False
private_0x0000000001500000 0x01500000 0x015fffff Private Memory Readable, Writable True False False
SortDefault.nls 0x01600000 0x018cefff Memory Mapped File Readable False False False
private_0x0000000001920000 0x01920000 0x01a1ffff Private Memory Readable, Writable True False False
private_0x0000000001a60000 0x01a60000 0x01b5ffff Private Memory Readable, Writable True False False
pagefile_0x0000000001b60000 0x01b60000 0x01f5ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000002050000 0x02050000 0x0205ffff Private Memory Readable, Writable True False False
private_0x0000000002060000 0x02060000 0x0215ffff Private Memory Readable, Writable True False False
private_0x0000000002200000 0x02200000 0x022fffff Private Memory Readable, Writable True False False
private_0x00000000023b0000 0x023b0000 0x024affff Private Memory Readable, Writable True False False
pagefile_0x00000000024b0000 0x024b0000 0x028a2fff Pagefile Backed Memory Readable True False False
private_0x00000000028b0000 0x028b0000 0x029affff Private Memory Readable, Writable True False False
comctl32.dll 0x6c1c0000 0x6c243fff Memory Mapped File Readable, Writable, Executable False False False
vbscript.dll 0x6c4c0000 0x6c52afff Memory Mapped File Readable, Writable, Executable True False False
scrrun.dll 0x6dab0000 0x6dad9fff Memory Mapped File Readable, Writable, Executable True False False
scrobj.dll 0x6dae0000 0x6db0cfff Memory Mapped File Readable, Writable, Executable True False False
wshext.dll 0x6db10000 0x6db25fff Memory Mapped File Readable, Writable, Executable True False False
msisip.dll 0x6dd30000 0x6dd37fff Memory Mapped File Readable, Writable, Executable False False False
ieframe.dll 0x6e6a0000 0x6f11ffff Memory Mapped File Readable, Writable, Executable False False False
apphelp.dll 0x71af0000 0x71b3bfff Memory Mapped File Readable, Writable, Executable False False False
mpr.dll 0x72080000 0x72091fff Memory Mapped File Readable, Writable, Executable False False False
oleacc.dll 0x72190000 0x721cbfff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x739c0000 0x739e0fff Memory Mapped File Readable, Writable, Executable False False False
dwmapi.dll 0x73da0000 0x73db2fff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x74090000 0x740cffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x74110000 0x742adfff Memory Mapped File Readable, Writable, Executable False False False
propsys.dll 0x745a0000 0x74694fff Memory Mapped File Readable, Writable, Executable False False False
version.dll 0x748a0000 0x748a8fff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x74bc0000 0x74bfafff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x74e20000 0x74e35fff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75280000 0x7529afff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x752a0000 0x752abfff Memory Mapped File Readable, Writable, Executable False False False
sxs.dll 0x752b0000 0x7530efff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x75350000 0x7535afff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x753c0000 0x753cbfff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x753d0000 0x754ecfff Memory Mapped File Readable, Writable, Executable False False False
devobj.dll 0x754f0000 0x75501fff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
wintrust.dll 0x75560000 0x7558cfff Memory Mapped File Readable, Writable, Executable False False False
cfgmgr32.dll 0x75590000 0x755b6fff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75650000 0x75744fff Memory Mapped File Readable, Writable, Executable False False False
Wldap32.dll 0x757d0000 0x75814fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x759e0000 0x76629fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
setupapi.dll 0x766f0000 0x7688cfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x76890000 0x76a8afff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x76a90000 0x76bebfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76d70000 0x76dc6fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x76e20000 0x76ea2fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x76ee0000 0x76f6efff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x770c0000 0x771f5fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x77360000 0x77364fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory Readable, Writable True False False
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory Readable, Writable True False False
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory Readable, Writable True False False
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory Readable, Writable True False False
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory Readable, Writable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Threads
Thread 0xf2c
(Host: 90, Network: 0)
+
Category Operation Information Success Count Logfile
MOD GET_HANDLE module_name = c:\windows\system32\wscript.exe, base_address = 0x80000 True 2
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data_ident_out = 0 False 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data_ident_out = 0 False 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data_ident_out = 0 False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data_ident_out = 255 False 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data_ident_out = 255 False 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data_ident_out = 255 False 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = HeapSetInformation, address = 0x75954157 True 1
Fn
COM METHOD interface = IMessageFilter, method = AddRef False 1
Fn
MOD GET_FILENAME module_name = c:\windows\system32\wscript.exe, file_name = C:\Windows\System32\WScript.exe True 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data_ident_out = 18 False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data_ident_out = 171 False 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data_ident_out = 18 False 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data_ident_out = 171 False 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data_ident_out = 1 True 1
Fn
REG CREATE_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data_ident_out = 20 False 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data_ident_out = 1 True 1
Fn
REG CREATE_KEY reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data_ident_out = 20 False 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data_ident_out = 49 False 1
Fn
COM METHOD interface = ITypeLib, method = GetTypeInfoType True 4
Fn
SYS SLEEP duration = -1 (infinite) True 1
Fn
REG OPEN_KEY reg_name = HKEY_CLASSES_ROOT\.vbs True 1
Fn
REG READ_VALUE reg_name = HKEY_CLASSES_ROOT\.vbs, data_ident_out = VBSFile True 1
Fn
REG OPEN_KEY reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine True 1
Fn
REG READ_VALUE reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine, data_ident_out = VBScript True 1
Fn
COM CREATE class_name = VBScriptEngine5, interface = IUnknown, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
COM CREATE class_name = VBScriptEngine5, interface = IClassFactory, True 1
Fn
COM METHOD class_name = VBScriptEngine5, interface = IClassFactory, new_interface = IUnknown, method = CreateInstance True 1
Fn
COM QUERY class_name = VBScriptEngine5, interface = IClassFactory, new_interface = IUnknown, True 1
Fn
COM METHOD class_name = VBScriptEngine5, interface = IUnknown, method = AddRef False 1
Fn
COM QUERY class_name = VBScriptEngine5, interface = IUnknown, new_interface = IUnknown True 1
Fn
MOD LOAD module_name = ole32.dll, base_address = 0x76a90000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoCreateInstance, address = 0x76ad9d0b True 1
Fn
COM CREATE class_name = {6C736DB1-BD94-11D0-8A23-00AA00B58E10}, interface = ISystemDebugEventFire, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM METHOD interface = ISystemDebugEventFire, method = AddRef False 1
Fn
COM METHOD interface = ISystemDebugEventFire, method = BeginSession True 1
Fn
FILE CREATE file_name = c:\users\public\n3eg\n3e.vbs, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTING, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN True 1
Fn
MOD CREATE_MAPPING file_name = c:\users\public\n3eg\n3e.vbs, module_name = Nameless FileMapping, maximum_size = 4199, protection = PAGE_READONLY True 1
Fn
MOD MAP file_name = c:\users\public\n3eg\n3e.vbs, process_name = c:\windows\system32\wscript.exe, os_pid = 0xf28, module_name = Nameless FileMapping, desired_access = FILE_MAP_READ, file_offset = 0, address = 0x350000 True 1
Fn
MOD UNMAP process_name = c:\windows\system32\wscript.exe, os_pid = 0xf28, base_address = 0x350000 True 1
Fn
MOD LOAD module_name = C:\Windows\system32\advapi32.dll, base_address = 0x76650000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = SaferIdentifyLevel, address = 0x76672102 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = SaferComputeTokenFromLevel, address = 0x76673352 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = SaferCloseLevel, address = 0x76673825 True 1
Fn
FILE READ file_name = c:\users\public\n3eg\n3e.vbs, module_name = Nameless FileMapping, size = 4199 True 1
Fn
Data
COM CREATE class_name = {06290BD1-48AA-11D2-8432-006008C3FBFC}, interface = {E4D1C9B0-46E8-11D4-A2A6-00104BD35090}, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM CREATE class_name = {06290BD1-48AA-11D2-8432-006008C3FBFC}, interface = IClassFactory, True 1
Fn
COM METHOD interface = IClassFactory, method = CreateInstance True 1
Fn
COM QUERY interface = IClassFactory, new_interface = {E4D1C9B0-46E8-11D4-A2A6-00104BD35090}, True 1
Fn
SYS GET_INFO type = Hardware Information True 1
Fn
COM METHOD interface = None, method = AddRef False 1
Fn
COM QUERY interface = None, new_interface = {E4D1C9B0-46E8-11D4-A2A6-00104BD35090} True 1
Fn
COM METHOD interface = ISystemDebugEventFire, method = IsActive False 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\ole32.dll, base_address = 0x76a90000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CLSIDFromProgIDEx, address = 0x76aa0782 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoGetClassObject, address = 0x76ac54ad True 1
Fn
COM CREATE class_name = FileSystemObject, interface = IClassFactory, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
COM METHOD interface = ITypeLib, method = GetTypeInfoType True 1
Fn
COM CREATE class_name = Shell, interface = IClassFactory, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
COM QUERY class_name = Shell, interface = IClassFactory, new_interface = {342D1EA0-AE25-11D1-89C5-006008C3FBFC}, False 1
Fn
COM METHOD class_name = Shell, interface = IClassFactory, new_interface = IUnknown, method = CreateInstance True 1
Fn
COM QUERY class_name = Shell, interface = IClassFactory, new_interface = IUnknown, True 1
Fn
COM QUERY class_name = Shell, interface = IUnknown, new_interface = IObjectWithSite True 1
Fn
COM METHOD class_name = Shell, interface = IObjectWithSite, method = SetSite True 1
Fn
COM METHOD class_name = FileSystemObject, interface = IClassFactory, method = AddRef False 1
Fn
COM QUERY class_name = Shell, interface = IUnknown, new_interface = IDispatch True 1
Fn
COM METHOD class_name = Shell, interface = IUnknown, method = AddRef False 2
Fn
COM QUERY class_name = Shell, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = Shell, interface = IUnknown, method = GetIDsOfNames True 1
Fn
COM METHOD class_name = Shell, interface = IUnknown, method = AddRef False 1
Fn
COM QUERY class_name = Shell, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = Shell, interface = IUnknown, method = Invoke True 1
Fn
SYS SLEEP duration = 1000 milliseconds (1.000 seconds) True 3
Fn
SYS SLEEP duration = 1000 milliseconds (1.000 seconds) False 1
Fn
Thread 0xf34
(Host: 2, Network: 0)
+
Category Operation Information Success Count Logfile
WND CREATE class_name = WSH-Timer, x_coordinate = 0, y_coordinate = 0, width = 1, height = 1, window_parameter = 3548128 True 1
Fn
WND SET_ATTRIBUTE class_name = WSH-Timer, x_coordinate = 0, y_coordinate = 0, width = 1, height = 1 False 1
Fn
Process #7: wscript.exe
(Host: 804, Network: 0)
+
Information Value
ID / OS PID #7 / 0x494
OS Parent PID 0xf28 (c:\windows\system32\wscript.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\wscript.exe
Command Line "C:\Windows\System32\wscript.exe" "C:\Users\Public\N3Eg\N3E.vbs" uac
Monitor Start Time: 00:03:46, Reason: Child Process
Unmonitor End Time: 00:03:49, Reason: Terminated
Monitor Duration 00:00:03
OS Thread IDs
# 96
0x 8C0
# 97
0x 8C4
# 98
0x 490
# 99
0x 478
# 100
0x 488
# 103
0x 268
# 104
0x 948
# 105
0x 968
# 107
0x 990
# 113
0x 9C8
# 115
0x 690
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00041fff Pagefile Backed Memory Readable, Writable True False False
wscript.exe.mui 0x00050000 0x00052fff Memory Mapped File Readable, Writable False False False
private_0x0000000000060000 0x00060000 0x00060fff Private Memory Readable, Writable True False False
private_0x0000000000070000 0x00070000 0x00070fff Private Memory Readable, Writable True False False
wscript.exe 0x00080000 0x000a5fff Memory Mapped File Readable, Writable, Executable True False False
locale.nls 0x000b0000 0x00116fff Memory Mapped File Readable False False False
wscript.exe 0x00120000 0x0012efff Memory Mapped File Readable True False False
pagefile_0x0000000000130000 0x00130000 0x00130fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000140000 0x00140000 0x00140fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000150000 0x00150000 0x00151fff Pagefile Backed Memory Readable True False False
private_0x0000000000150000 0x00150000 0x0015ffff Private Memory Readable, Writable True False False
private_0x0000000000160000 0x00160000 0x0025ffff Private Memory Readable, Writable True False False
scrrun.dll 0x00260000 0x00274fff Memory Mapped File Readable True False False
wshom.ocx 0x00280000 0x0028bfff Memory Mapped File Readable True False False
private_0x0000000000290000 0x00290000 0x0029ffff Private Memory Readable, Writable True False False
private_0x00000000002a0000 0x002a0000 0x002affff Private Memory Readable, Writable True False False
pagefile_0x00000000002b0000 0x002b0000 0x00377fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000380000 0x00380000 0x00380fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000390000 0x00390000 0x0048ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000490000 0x00490000 0x00590fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000005a0000 0x005a0000 0x0119ffff Pagefile Backed Memory Readable True False False
pagefile_0x00000000011a0000 0x011a0000 0x011a1fff Pagefile Backed Memory Readable True False False
oleaccrc.dll 0x011b0000 0x011b0fff Memory Mapped File Readable False False False
private_0x00000000011c0000 0x011c0000 0x011fffff Private Memory Readable, Writable True False False
pagefile_0x0000000001200000 0x01200000 0x012defff Pagefile Backed Memory Readable True False False
pagefile_0x00000000012e0000 0x012e0000 0x012e1fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000012f0000 0x012f0000 0x012f1fff Pagefile Backed Memory Readable True False False
cversions.2.db 0x01300000 0x01303fff Memory Mapped File Readable True False False
private_0x0000000001310000 0x01310000 0x0140ffff Private Memory Readable, Writable True False False
SortDefault.nls 0x01410000 0x016defff Memory Mapped File Readable False False False
{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000000c.db 0x016e0000 0x016fcfff Memory Mapped File Readable True False False
pagefile_0x0000000001700000 0x01700000 0x01700fff Pagefile Backed Memory Readable, Writable True False False
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000007.db 0x01710000 0x0173ffff Memory Mapped File Readable True False False
cversions.2.db 0x01740000 0x01743fff Memory Mapped File Readable True False False
pagefile_0x0000000001750000 0x01750000 0x01750fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000001760000 0x01760000 0x01760fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000001770000 0x01770000 0x0186ffff Private Memory Readable, Writable True False False
private_0x0000000001870000 0x01870000 0x0196ffff Private Memory Readable, Writable True False False
FirewallAPI.dll 0x01970000 0x0197afff Memory Mapped File Readable False False False
stdole2.tlb 0x01980000 0x01983fff Memory Mapped File Readable False False False
private_0x0000000001990000 0x01990000 0x01a8ffff Private Memory Readable, Writable True False False
pagefile_0x0000000001a90000 0x01a90000 0x01e8ffff Pagefile Backed Memory Readable, Writable True False False
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db 0x01e90000 0x01ef5fff Memory Mapped File Readable True False False
private_0x0000000001f80000 0x01f80000 0x0207ffff Private Memory Readable, Writable True False False
private_0x0000000002080000 0x02080000 0x0217ffff Private Memory Readable, Writable True False False
private_0x0000000002160000 0x02160000 0x0225ffff Private Memory Readable, Writable True False False
private_0x0000000002280000 0x02280000 0x0237ffff Private Memory Readable, Writable True False False
private_0x00000000023f0000 0x023f0000 0x024effff Private Memory Readable, Writable True False False
pagefile_0x00000000024f0000 0x024f0000 0x028e2fff Pagefile Backed Memory Readable True False False
comctl32.dll 0x6c1c0000 0x6c243fff Memory Mapped File Readable, Writable, Executable False False False
wshom.ocx 0x6c420000 0x6c440fff Memory Mapped File Readable, Writable, Executable True False False
vbscript.dll 0x6c4c0000 0x6c52afff Memory Mapped File Readable, Writable, Executable True False False
scrrun.dll 0x6dab0000 0x6dad9fff Memory Mapped File Readable, Writable, Executable True False False
scrobj.dll 0x6dae0000 0x6db0cfff Memory Mapped File Readable, Writable, Executable True False False
wshext.dll 0x6db10000 0x6db25fff Memory Mapped File Readable, Writable, Executable True False False
msisip.dll 0x6dd30000 0x6dd37fff Memory Mapped File Readable, Writable, Executable False False False
ieframe.dll 0x6e6a0000 0x6f11ffff Memory Mapped File Readable, Writable, Executable False False False
apphelp.dll 0x71af0000 0x71b3bfff Memory Mapped File Readable, Writable, Executable False False False
mpr.dll 0x72080000 0x72091fff Memory Mapped File Readable, Writable, Executable False False False
oleacc.dll 0x72190000 0x721cbfff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x739c0000 0x739e0fff Memory Mapped File Readable, Writable, Executable False False False
dwmapi.dll 0x73da0000 0x73db2fff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x74090000 0x740cffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x74110000 0x742adfff Memory Mapped File Readable, Writable, Executable False False False
propsys.dll 0x745a0000 0x74694fff Memory Mapped File Readable, Writable, Executable False False False
version.dll 0x748a0000 0x748a8fff Memory Mapped File Readable, Writable, Executable False False False
FirewallAPI.dll 0x748b0000 0x74925fff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x74bc0000 0x74bfafff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x74e20000 0x74e35fff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75280000 0x7529afff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x752a0000 0x752abfff Memory Mapped File Readable, Writable, Executable False False False
sxs.dll 0x752b0000 0x7530efff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x75350000 0x7535afff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x753c0000 0x753cbfff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x753d0000 0x754ecfff Memory Mapped File Readable, Writable, Executable False False False
devobj.dll 0x754f0000 0x75501fff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
wintrust.dll 0x75560000 0x7558cfff Memory Mapped File Readable, Writable, Executable False False False
cfgmgr32.dll 0x75590000 0x755b6fff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x75650000 0x75744fff Memory Mapped File Readable, Writable, Executable False False False
Wldap32.dll 0x757d0000 0x75814fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x759e0000 0x76629fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
setupapi.dll 0x766f0000 0x7688cfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x76890000 0x76a8afff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x76a90000 0x76bebfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76d70000 0x76dc6fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x76e20000 0x76ea2fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x76ee0000 0x76f6efff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x770c0000 0x771f5fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x77360000 0x77364fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory Readable, Writable True False False
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory Readable, Writable True False False
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory Readable, Writable True False False
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory Readable, Writable True False False
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory Readable, Writable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Threads
Thread 0x8c0
(Host: 802, Network: 0)
+
Category Operation Information Success Count Logfile
MOD GET_HANDLE module_name = c:\windows\system32\wscript.exe, base_address = 0x80000 True 2
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data_ident_out = 0 False 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data_ident_out = 0 False 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data_ident_out = 0 False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data_ident_out = 0 False 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data_ident_out = 0 False 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data_ident_out = 0 False 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = HeapSetInformation, address = 0x75954157 True 1
Fn
COM METHOD interface = IMessageFilter, method = AddRef False 1
Fn
MOD GET_FILENAME module_name = c:\windows\system32\wscript.exe, file_name = C:\Windows\System32\wscript.exe True 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data_ident_out = 237 False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data_ident_out = 143 False 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data_ident_out = 237 False 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data_ident_out = 143 False 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data_ident_out = 1 True 1
Fn
REG CREATE_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data_ident_out = 176 False 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data_ident_out = 1 True 1
Fn
REG CREATE_KEY reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data_ident_out = 176 False 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data_ident_out = 49 False 1
Fn
COM METHOD interface = ITypeLib, method = GetTypeInfoType True 4
Fn
SYS SLEEP duration = -1 (infinite) True 1
Fn
REG OPEN_KEY reg_name = HKEY_CLASSES_ROOT\.vbs True 1
Fn
REG READ_VALUE reg_name = HKEY_CLASSES_ROOT\.vbs, data_ident_out = VBSFile True 1
Fn
REG OPEN_KEY reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine True 1
Fn
REG READ_VALUE reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine, data_ident_out = VBScript True 1
Fn
COM CREATE class_name = VBScriptEngine5, interface = IUnknown, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
COM CREATE class_name = VBScriptEngine5, interface = IClassFactory, True 1
Fn
COM METHOD class_name = VBScriptEngine5, interface = IClassFactory, new_interface = IUnknown, method = CreateInstance True 1
Fn
COM QUERY class_name = VBScriptEngine5, interface = IClassFactory, new_interface = IUnknown, True 1
Fn
COM METHOD class_name = VBScriptEngine5, interface = IUnknown, method = AddRef False 1
Fn
COM QUERY class_name = VBScriptEngine5, interface = IUnknown, new_interface = IUnknown True 1
Fn
MOD LOAD module_name = ole32.dll, base_address = 0x76a90000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoCreateInstance, address = 0x76ad9d0b True 1
Fn
COM CREATE class_name = {6C736DB1-BD94-11D0-8A23-00AA00B58E10}, interface = ISystemDebugEventFire, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM METHOD interface = ISystemDebugEventFire, method = AddRef False 1
Fn
COM METHOD interface = ISystemDebugEventFire, method = BeginSession True 1
Fn
FILE CREATE file_name = c:\users\public\n3eg\n3e.vbs, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTING, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN True 1
Fn
MOD CREATE_MAPPING file_name = c:\users\public\n3eg\n3e.vbs, module_name = Nameless FileMapping, maximum_size = 4199, protection = PAGE_READONLY True 1
Fn
MOD MAP file_name = c:\users\public\n3eg\n3e.vbs, process_name = c:\windows\system32\wscript.exe, os_pid = 0x494, module_name = Nameless FileMapping, desired_access = FILE_MAP_READ, file_offset = 0, address = 0x150000 True 1
Fn
MOD UNMAP process_name = c:\windows\system32\wscript.exe, os_pid = 0x494, base_address = 0x150000 True 1
Fn
MOD LOAD module_name = C:\Windows\system32\advapi32.dll, base_address = 0x76650000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = SaferIdentifyLevel, address = 0x76672102 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = SaferComputeTokenFromLevel, address = 0x76673352 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = SaferCloseLevel, address = 0x76673825 True 1
Fn
FILE READ file_name = c:\users\public\n3eg\n3e.vbs, module_name = Nameless FileMapping, size = 4199 True 1
Fn
Data
COM CREATE class_name = {06290BD1-48AA-11D2-8432-006008C3FBFC}, interface = {E4D1C9B0-46E8-11D4-A2A6-00104BD35090}, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM CREATE class_name = {06290BD1-48AA-11D2-8432-006008C3FBFC}, interface = IClassFactory, True 1
Fn
COM METHOD interface = IClassFactory, method = CreateInstance True 1
Fn
COM QUERY interface = IClassFactory, new_interface = {E4D1C9B0-46E8-11D4-A2A6-00104BD35090}, True 1
Fn
SYS GET_INFO type = Hardware Information True 1
Fn
COM METHOD interface = None, method = AddRef False 1
Fn
COM QUERY interface = None, new_interface = {E4D1C9B0-46E8-11D4-A2A6-00104BD35090} True 1
Fn
COM METHOD interface = ISystemDebugEventFire, method = IsActive False 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\ole32.dll, base_address = 0x76a90000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CLSIDFromProgIDEx, address = 0x76aa0782 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoGetClassObject, address = 0x76ac54ad True 1
Fn
COM CREATE class_name = FileSystemObject, interface = IClassFactory, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
COM METHOD interface = ITypeLib, method = GetTypeInfoType True 1
Fn
COM CREATE class_name = WshShell, interface = IUnknown, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
COM CREATE class_name = WshShell, interface = IClassFactory, True 1
Fn
COM METHOD class_name = FileSystemObject, interface = IClassFactory, new_interface = IUnknown, method = CreateInstance True 1
Fn
COM QUERY class_name = FileSystemObject, interface = IClassFactory, new_interface = IUnknown, True 1
Fn
MOD GET_FILENAME file_name = C:\Windows\System32\wscript.exe True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\wscript.exe, base_address = 0x80000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\wscript.exe, function = 1, address = 0x82bb9 True 1
Fn
COM METHOD class_name = FileSystemObject, interface = IUnknown, method = AddRef False 1
Fn
COM QUERY class_name = FileSystemObject, interface = IUnknown, new_interface = IUnknown True 1
Fn
COM METHOD interface = ITypeLib, method = GetTypeInfoType True 1
Fn
REG CREATE_KEY reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System True 1
Fn
REG WRITE_VALUE reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System, value_name = EnableLUA, data = 0 True 1
Fn
REG CREATE_KEY reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System True 1
Fn
REG WRITE_VALUE reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System, value_name = ConsentPromptBehaviorAdmin, data = 0 True 1
Fn
REG CREATE_KEY reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System True 1
Fn
REG WRITE_VALUE reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System, value_name = PromptOnSecureDesktop, data = 0 True 1
Fn
REG CREATE_KEY reg_name = HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download True 1
Fn
REG WRITE_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download, value_name = CheckExeSignatures, data = no True 1
Fn
REG CREATE_KEY reg_name = HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download True 1
Fn
REG WRITE_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download, value_name = RunInvalidSignatures, data = 00000001 True 1
Fn
REG CREATE_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center True 1
Fn
REG WRITE_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center, value_name = AntiVirusDisableNotify, data = 1 True 1
Fn
REG CREATE_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center True 1
Fn
REG WRITE_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center, value_name = UpdatesDisableNotify, data = 1 True 1
Fn
MOD LOAD module_name = shell32.dll, base_address = 0x759e0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\shell32.dll, function = ShellExecuteExW, address = 0x75a01e46 True 1
Fn
PROC CREATE process_name = sc, operation = Open, show_window = SW_HIDE True 1
Fn
PROC CREATE process_name = net, operation = Open, show_window = SW_HIDE True 1
Fn
COM CREATE class_name = NetFwPolicy2, interface = IClassFactory, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IClassFactory, new_interface = {342D1EA0-AE25-11D1-89C5-006008C3FBFC}, False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IClassFactory, new_interface = IUnknown, method = CreateInstance True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IClassFactory, new_interface = IUnknown, True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {FC4801A3-2BA9-11CF-A229-00AA003D7352} False 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = IDispatch True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = AddRef False 2
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = GetIDsOfNames True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = AddRef False 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, new_interface = IDispatch, method = Invoke True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IDispatch, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IDispatch, method = AddRef False 2
Fn
COM QUERY class_name = NetFwPolicy2, interface = IDispatch, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IDispatch, new_interface = IUnknown, method = Invoke True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {00020400-0000-0000-C000-000000000046} False 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = IEnumVARIANT True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IDispatch, method = AddRef False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Next False 1
Fn
COM CREATE class_name = NetFwRule, interface = IClassFactory, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {342D1EA0-AE25-11D1-89C5-006008C3FBFC}, False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, new_interface = IUnknown, method = CreateInstance True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = IUnknown, True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {FC4801A3-2BA9-11CF-A229-00AA003D7352} False 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = IDispatch True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = AddRef False 2
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = GetIDsOfNames True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = AddRef False 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Invoke True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = GetIDsOfNames True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = AddRef False 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Invoke True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = GetIDsOfNames True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = AddRef False 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Invoke True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = GetIDsOfNames True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = AddRef False 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Invoke True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = GetIDsOfNames True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = AddRef False 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Invoke True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = GetIDsOfNames True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = AddRef False 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Invoke True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = GetIDsOfNames True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = AddRef False 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Invoke True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = GetIDsOfNames True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = AddRef False 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Invoke True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = GetIDsOfNames True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = AddRef False 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Invoke True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = GetIDsOfNames True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = AddRef False 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Invoke True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = GetIDsOfNames True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = AddRef False 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IUnknown, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IUnknown, method = Invoke True 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IDispatch, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IDispatch, method = GetIDsOfNames True 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IDispatch, method = AddRef False 1
Fn
COM QUERY class_name = NetFwPolicy2, interface = IDispatch, new_interface = {A6EF9860-C720-11D0-9337-00A0C90DCAA9} False 1
Fn
COM METHOD class_name = NetFwPolicy2, interface = IDispatch, new_interface = IDispatch, method = Invoke True 1
Fn
PROC CREATE process_name = cmd, operation = Open, show_window = SW_HIDE True 2
Fn
COM METHOD interface = ISystemDebugEventFire, method = IsActive False 1
Fn
COM METHOD interface = ISystemDebugEventFire, method = EndSession True 1
Fn
SYS SLEEP duration = -1 (infinite) True 1
Fn
Thread 0x490
(Host: 2, Network: 0)
+
Category Operation Information Success Count Logfile
WND CREATE class_name = WSH-Timer, x_coordinate = 0, y_coordinate = 0, width = 1, height = 1, window_parameter = 2761696 True 1
Fn
WND SET_ATTRIBUTE class_name = WSH-Timer, x_coordinate = 0, y_coordinate = 0, width = 1, height = 1 False 1
Fn
Process #8: sc.exe
(Host: 8, Network: 0)
+
Information Value
ID / OS PID #8 / 0x960
OS Parent PID 0x494 (c:\windows\system32\wscript.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\sc.exe
Command Line "C:\Windows\System32\sc.exe" config WinDefend start= disabled
Monitor Start Time: 00:03:47, Reason: Child Process
Unmonitor End Time: 00:03:48, Reason: Terminated
Monitor Duration 00:00:01
OS Thread IDs
# 106
0x 994
# 109
0x 6AC
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory Readable True False False
private_0x0000000000080000 0x00080000 0x000bffff Private Memory Readable, Writable True False False
locale.nls 0x000c0000 0x00126fff Memory Mapped File Readable False False False
private_0x00000000001f0000 0x001f0000 0x001fffff Private Memory Readable, Writable True False False
private_0x0000000000220000 0x00220000 0x0031ffff Private Memory Readable, Writable True False False
sc.exe 0x00ec0000 0x00ecbfff Memory Mapped File Readable, Writable, Executable True False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Threads
Thread 0x994
(Host: 8, Network: 0)
+
Category Operation Information Success Count Logfile
MOD GET_HANDLE module_name = c:\windows\system32\sc.exe, base_address = 0xec0000 True 1
Fn
FILE OPEN file_name = STD_OUTPUT_HANDLE True 1
Fn
SVC OPEN_MGR database_name = SERVICES_ACTIVE_DATABASE, host = Localhost, desired_access = SC_MANAGER_CONNECT True 1
Fn
SVC OPEN service_name = WinDefend, database_name = SERVICES_ACTIVE_DATABASE, desired_access = SERVICE_QUERY_CONFIG, SERVICE_CHANGE_CONFIG True 1
Fn
SVC GET_INFO service_name = WinDefend, type = SERVICE_CONFIG_DELAYED_AUTO_START_INFO True 1
Fn
SVC SET_CONFIG service_name = WinDefend True 1
Fn
SVC SET_CONFIG service_name = WinDefend, new_service_type = SERVICE_NO_CHANGE, new_start_type = SERVICE_DISABLED True 1
Fn
FILE WRITE file_name = STD_OUTPUT_HANDLE, size = 34 True 1
Fn
Data
Process #9: net.exe
+
Information Value
ID / OS PID #9 / 0x6b0
OS Parent PID 0x494 (c:\windows\system32\wscript.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\net.exe
Command Line "C:\Windows\System32\net.exe" localgroup HomeUsers /delete DSsDPMx042
Monitor Start Time: 00:03:47, Reason: Child Process
Unmonitor End Time: 00:03:48, Reason: Terminated
Monitor Duration 00:00:01
OS Thread IDs
# 108
0x 954
Remarks No high level activity detected in monitored regions
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
net.exe 0x00130000 0x00147fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000270000 0x00270000 0x002effff Private Memory Readable, Writable True False False
private_0x0000000000430000 0x00430000 0x0043ffff Private Memory Readable, Writable True False False
private_0x0000000000490000 0x00490000 0x0058ffff Private Memory Readable, Writable True False False
browcli.dll 0x6dca0000 0x6dcacfff Memory Mapped File Readable, Writable, Executable False False False
mpr.dll 0x72080000 0x72091fff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x72300000 0x72306fff Memory Mapped File Readable, Writable, Executable False False False
IPHLPAPI.DLL 0x72310000 0x7232bfff Memory Mapped File Readable, Writable, Executable False False False
samcli.dll 0x73b20000 0x73b2efff Memory Mapped File Readable, Writable, Executable False False False
wkscli.dll 0x73b30000 0x73b3efff Memory Mapped File Readable, Writable, Executable False False False
netutils.dll 0x73b40000 0x73b48fff Memory Mapped File Readable, Writable, Executable False False False
srvcli.dll 0x751f0000 0x75208fff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x77340000 0x77345fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Process #10: net1.exe
(Host: 9, Network: 0)
+
Information Value
ID / OS PID #10 / 0x9bc
OS Parent PID 0x6b0 (c:\windows\system32\net.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\net1.exe
Command Line C:\Windows\system32\net1 localgroup HomeUsers /delete DSsDPMx042
Monitor Start Time: 00:03:48, Reason: Child Process
Unmonitor End Time: 00:03:48, Reason: Terminated
Monitor Duration 00:00:00
OS Thread IDs
# 110
0x 66C
# 111
0x 668
# 112
0x 664
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory Readable True False False
private_0x0000000000050000 0x00050000 0x000cffff Private Memory Readable, Writable True False False
locale.nls 0x000d0000 0x00136fff Memory Mapped File Readable False False False
private_0x00000000002b0000 0x002b0000 0x003affff Private Memory Readable, Writable True False False
private_0x00000000003d0000 0x003d0000 0x0044ffff Private Memory Readable, Writable True False False
private_0x00000000004d0000 0x004d0000 0x0054ffff Private Memory Readable, Writable True False False
private_0x0000000000550000 0x00550000 0x0055ffff Private Memory Readable, Writable True False False
net1.exe 0x00a70000 0x00a99fff Memory Mapped File Readable, Writable, Executable True False False
netmsg.dll 0x6c3c0000 0x6c3c1fff Memory Mapped File Readable, Writable, Executable False False False
browcli.dll 0x6dca0000 0x6dcacfff Memory Mapped File Readable, Writable, Executable False False False
ntdsapi.dll 0x72e10000 0x72e27fff Memory Mapped File Readable, Writable, Executable False False False
dsrole.dll 0x73720000 0x73728fff Memory Mapped File Readable, Writable, Executable False False False
samcli.dll 0x73b20000 0x73b2efff Memory Mapped File Readable, Writable, Executable False False False
wkscli.dll 0x73b30000 0x73b3efff Memory Mapped File Readable, Writable, Executable False False False
netutils.dll 0x73b40000 0x73b48fff Memory Mapped File Readable, Writable, Executable False False False
netapi32.dll 0x73b50000 0x73b60fff Memory Mapped File Readable, Writable, Executable False False False
samlib.dll 0x740d0000 0x740e1fff Memory Mapped File Readable, Writable, Executable False False False
logoncli.dll 0x74c70000 0x74c91fff Memory Mapped File Readable, Writable, Executable False False False
srvcli.dll 0x751f0000 0x75208fff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x77340000 0x77345fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x773f0000 0x77424fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory Readable, Writable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Threads
Thread 0x66c
(Host: 9, Network: 0)
+
Category Operation Information Success Count Logfile
MOD GET_HANDLE module_name = c:\windows\system32\net1.exe, base_address = 0xa70000 True 1
Fn
FILE OPEN file_name = STD_OUTPUT_HANDLE True 1
Fn
FILE OPEN file_name = STD_ERROR_HANDLE True 1
Fn
MOD GET_FILENAME file_name = C:\Windows\system32\net1.exe True 1
Fn
MOD LOAD module_name = NETMSG, base_address = 0x6c3c0000 True 1
Fn
FILE WRITE file_name = STD_ERROR_HANDLE, size = 33 True 1
Fn
Data
FILE WRITE file_name = STD_ERROR_HANDLE, size = 2 True 1
Fn
Data
FILE WRITE file_name = STD_ERROR_HANDLE, size = 43 True 1
Fn
Data
FILE WRITE file_name = STD_ERROR_HANDLE, size = 2 True 1
Fn
Data
Process #11: cmd.exe
(Host: 65, Network: 0)
+
Information Value
ID / OS PID #11 / 0x69c
OS Parent PID 0x494 (c:\windows\system32\wscript.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\cmd.exe
Command Line "C:\Windows\System32\cmd.exe" /k echo a > "C:\Users\Public\N3Eg\uc"
Monitor Start Time: 00:03:48, Reason: Child Process
Unmonitor End Time: 00:03:50, Reason: Terminated
Monitor Duration 00:00:02
OS Thread IDs
# 114
0x 9CC
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x0012ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000130000 0x00130000 0x00133fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000140000 0x00140000 0x00140fff Pagefile Backed Memory Readable True False False
locale.nls 0x00150000 0x001b6fff Memory Mapped File Readable False False False
pagefile_0x00000000001c0000 0x001c0000 0x00287fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000290000 0x00290000 0x00296fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000002a0000 0x002a0000 0x002a1fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000002b0000 0x002b0000 0x002b0fff Private Memory Readable, Writable True False False
private_0x00000000002c0000 0x002c0000 0x003bffff Private Memory Readable, Writable True False False
pagefile_0x00000000003c0000 0x003c0000 0x004c0fff Pagefile Backed Memory Readable True False False
private_0x00000000004d0000 0x004d0000 0x004d0fff Private Memory Readable, Writable True False False
private_0x0000000000500000 0x00500000 0x0050ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000510000 0x00510000 0x0110ffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001110000 0x01110000 0x0139afff Pagefile Backed Memory Readable True False False
cmd.exe 0x4a810000 0x4a85bfff Memory Mapped File Readable, Writable, Executable True False False
winbrand.dll 0x6dd80000 0x6dd86fff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Threads
Thread 0x9cc
(Host: 65, Network: 0)
+
Category Operation Information Success Count Logfile
MOD GET_HANDLE module_name = c:\windows\system32\cmd.exe, base_address = 0x4a810000 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address = 0x759524c2 True 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
FILE OPEN file_name = STD_OUTPUT_HANDLE True 3
Fn
FILE OPEN file_name = STD_INPUT_HANDLE True 2
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data_ident_out = 88 False 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data_ident_out = 0 True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data_ident_out = 64 True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data_ident_out = 64 True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data_ident_out = 64 False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data_ident_out = 64 False 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data_ident_out = 0 True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data_ident_out = 9 True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data_ident_out = 9 True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data_ident_out = 9 False 1
Fn
MOD GET_FILENAME file_name = C:\Windows\System32\cmd.exe True 1
Fn
PROC SET_CURDIR process_name = c:\windows\system32\cmd.exe, os_pid = 0x69c, new_path_name = c:\windows\system32 True 1
Fn
FILE OPEN file_name = STD_OUTPUT_HANDLE True 4
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address = 0x7593ac6c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address = 0x75943ea8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address = 0x75952732 True 1
Fn
FILE OPEN file_name = STD_OUTPUT_HANDLE True 4
Fn
FILE CREATE file_name = c:\users\public\n3eg\uc, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE OPEN file_name = c:\users\public\n3eg\uc True 3
Fn
FILE WRITE file_name = c:\users\public\n3eg\uc, size = 4 True 1
Fn
Data
FILE OPEN file_name = c:\users\public\n3eg\uc True 2
Fn
FILE OPEN file_name = STD_INPUT_HANDLE True 3
Fn
FILE OPEN file_name = c:\users\public\n3eg\uc True 1
Fn
FILE OPEN file_name = STD_OUTPUT_HANDLE True 1
Fn
FILE OPEN file_name = c:\users\public\n3eg\uc True 1
Fn
FILE WRITE file_name = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
FILE OPEN file_name = c:\users\public\n3eg\uc True 1
Fn
FILE OPEN file_name = STD_OUTPUT_HANDLE True 1
Fn
FILE OPEN file_name = c:\users\public\n3eg\uc True 1
Fn
FILE WRITE file_name = STD_OUTPUT_HANDLE, size = 20 True 1
Fn
Data
FILE OPEN file_name = STD_INPUT_HANDLE True 6
Fn
FILE OPEN file_name = STD_OUTPUT_HANDLE True 1
Fn
FILE READ file_name = STD_INPUT_HANDLE, size = 8192 False 1
Fn
Process #12: cmd.exe
(Host: 57, Network: 0)
+
Information Value
ID / OS PID #12 / 0x660
OS Parent PID 0x494 (c:\windows\system32\wscript.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\cmd.exe
Command Line "C:\Windows\System32\cmd.exe" /k shutdown -r -t 0 -f
Monitor Start Time: 00:03:49, Reason: Child Process
Unmonitor End Time: 00:03:50, Reason: Terminated
Monitor Duration 00:00:01
OS Thread IDs
# 116
0x 65C
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
pagefile_0x00000000000c0000 0x000c0000 0x000c6fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000000d0000 0x000d0000 0x000d1fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000000e0000 0x000e0000 0x000e0fff Private Memory Readable, Writable True False False
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory Readable, Writable True False False
private_0x0000000000170000 0x00170000 0x0026ffff Private Memory Readable, Writable True False False
private_0x00000000002e0000 0x002e0000 0x003dffff Private Memory Readable, Writable True False False
pagefile_0x00000000003e0000 0x003e0000 0x004a7fff Pagefile Backed Memory Readable True False False
private_0x0000000000580000 0x00580000 0x0058ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000590000 0x00590000 0x00690fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000006a0000 0x006a0000 0x0129ffff Pagefile Backed Memory Readable True False False
pagefile_0x00000000012a0000 0x012a0000 0x0152afff Pagefile Backed Memory Readable True False False
cmd.exe 0x4a810000 0x4a85bfff Memory Mapped File Readable, Writable, Executable True False False
winbrand.dll 0x6dd80000 0x6dd86fff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Threads
Thread 0x65c
(Host: 57, Network: 0)
+
Category Operation Information Success Count Logfile
MOD GET_HANDLE module_name = c:\windows\system32\cmd.exe, base_address = 0x4a810000 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address = 0x759524c2 True 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
FILE OPEN file_name = c:\users\public\n3eg\uc True 3
Fn
FILE OPEN file_name = STD_INPUT_HANDLE True 2
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data_ident_out = 0 False 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data_ident_out = 0 True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data_ident_out = 64 True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data_ident_out = 64 True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data_ident_out = 64 False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data_ident_out = 64 False 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data_ident_out = 0 True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data_ident_out = 9 True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data_ident_out = 9 True 1
Fn
REG READ_VALUE reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data_ident_out = 9 False 1
Fn
MOD GET_FILENAME file_name = C:\Windows\System32\cmd.exe True 1
Fn
PROC SET_CURDIR process_name = c:\windows\system32\cmd.exe, os_pid = 0x660, new_path_name = c:\windows\system32 True 1
Fn
FILE OPEN file_name = c:\users\public\n3eg\uc True 1
Fn
FILE OPEN file_name = STD_OUTPUT_HANDLE True 3
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x75900000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address = 0x7593ac6c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address = 0x75943ea8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address = 0x75952732 True 1
Fn
PROC CREATE process_name = C:\Windows\system32\shutdown.exe, os_tid = 0x9f0, os_pid = 0x9ec, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, current_directory = C:\Windows\system32, show_window = SW_SHOWNORMAL True 1
Fn
FILE OPEN file_name = c:\users\public\n3eg\uc True 2
Fn
FILE OPEN file_name = STD_INPUT_HANDLE True 3
Fn
FILE OPEN file_name = c:\users\public\n3eg\uc True 1
Fn
FILE OPEN file_name = STD_OUTPUT_HANDLE True 1
Fn
FILE OPEN file_name = c:\users\public\n3eg\uc True 1
Fn
FILE WRITE file_name = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
FILE OPEN file_name = c:\users\public\n3eg\uc True 1
Fn
FILE OPEN file_name = STD_OUTPUT_HANDLE True 1
Fn
FILE OPEN file_name = c:\users\public\n3eg\uc True 1
Fn
FILE WRITE file_name = STD_OUTPUT_HANDLE, size = 20 True 1
Fn
Data
FILE OPEN file_name = STD_INPUT_HANDLE True 6
Fn
FILE OPEN file_name = STD_OUTPUT_HANDLE True 1
Fn
FILE READ file_name = STD_INPUT_HANDLE, size = 8192 False 1
Fn
Process #13: shutdown.exe
+
Information Value
ID / OS PID #13 / 0x9ec
OS Parent PID 0x660 (c:\windows\system32\cmd.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\shutdown.exe
Command Line shutdown -r -t 0 -f
Monitor Start Time: 00:03:49, Reason: Child Process
Unmonitor End Time: 00:03:49, Reason: Terminated
Monitor Duration 00:00:00
OS Thread IDs
# 117
0x 9F0
# 118
0x A1C
Remarks No high level activity detected in monitored regions
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
private_0x0000000000140000 0x00140000 0x0017ffff Private Memory Readable, Writable True False False
private_0x00000000001d0000 0x001d0000 0x002cffff Private Memory Readable, Writable True False False
pagefile_0x00000000002d0000 0x002d0000 0x00397fff Pagefile Backed Memory Readable True False False
shutdown.exe 0x00410000 0x00419fff Memory Mapped File Readable, Writable, Executable False False False
private_0x00000000005b0000 0x005b0000 0x005bffff Private Memory Readable, Writable True False False
secur32.dll 0x75260000 0x75267fff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75280000 0x7529afff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75510000 0x75559fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75830000 0x758fbfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x75900000 0x759d3fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76630000 0x7664efff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76650000 0x766effff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x76a90000 0x76bebfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76bf0000 0x76c90fff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76ca0000 0x76d68fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76dd0000 0x76e1dfff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76f70000 0x7701bfff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77020000 0x770bcfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77200000 0x7733bfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77350000 0x77359fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x773d0000 0x773e8fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77440000 0x77440fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Process #14: regsvr32.exe
(Host: 90, Network: 0)
+
Information Value
ID / OS PID #14 / 0x574
OS Parent PID 0x470 (c:\windows\explorer.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\system32\regsvr32.exe
Command Line "C:\Windows\System32\regsvr32.exe" /s "C:\Users\Public\N3Eg\N3Eg2.51N3E" #96
Monitor Start Time: 00:04:12, Reason: Analysis Target
Unmonitor End Time: 00:04:23, Reason: Terminated
Monitor Duration 00:00:11
OS Thread IDs
# 120
0x 578
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00041fff Pagefile Backed Memory Readable True False False
locale.nls 0x00050000 0x000b6fff Memory Mapped File Readable False False False
pagefile_0x00000000000c0000 0x000c0000 0x000c1fff Pagefile Backed Memory Readable, Writable True False False
regsvr32.exe.mui 0x000d0000 0x000d1fff Memory Mapped File Readable, Writable False False False
private_0x00000000000e0000 0x000e0000 0x000e0fff Private Memory Readable, Writable True False False
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory Readable, Writable True False False
pagefile_0x0000000000110000 0x00110000 0x00111fff Pagefile Backed Memory Readable True False False
private_0x0000000000130000 0x00130000 0x0013ffff Private Memory Readable, Writable True False False
private_0x0000000000140000 0x00140000 0x0017ffff Private Memory Readable, Writable True False False
private_0x00000000001b0000 0x001b0000 0x002affff Private Memory Readable, Writable True False False
pagefile_0x00000000002b0000 0x002b0000 0x00377fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000380000 0x00380000 0x00480fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000490000 0x00490000 0x0056efff Pagefile Backed Memory Readable True False False
private_0x00000000005d0000 0x005d0000 0x0060ffff Private Memory Readable, Writable True False False
N3Eg2.51N3E 0x00610000 0x00764fff Memory Mapped File Readable, Writable, Executable True True False
private_0x0000000000770000 0x00770000 0x008affff Private Memory Readable, Writable True False False
SortDefault.nls 0x008b0000 0x00b7efff Memory Mapped File Readable False False False
regsvr32.exe 0x00f30000 0x00f36fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000f40000 0x00f40000 0x01b3ffff Pagefile Backed Memory Readable True False False
uxtheme.dll 0x74b10000 0x74b4ffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x74c90000 0x74e2dfff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x75c00000 0x75c0bfff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75f30000 0x75f79fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x75fb0000 0x75fcefff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76010000 0x7605dfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76110000 0x761b0fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x761c0000 0x7626bfff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76270000 0x76338fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x77130000 0x771cffff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77580000 0x7761cfff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x77620000 0x7777bfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x77780000 0x77853fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x77860000 0x778b6fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x77a00000 0x77a8efff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x77a90000 0x77b5bfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b60000 0x77c9bfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77cc0000 0x77cc9fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77ce0000 0x77cf8fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77da0000 0x77da0fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Threads
Thread 0x578
(Host: 90, Network: 0)
+
Category Operation Information Success Count Logfile
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetThreadPreferredUILanguages, address = 0x777c22d7 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetThreadPreferredUILanguages, address = 0x777be627 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetThreadUILanguage, address = 0x777bae42 True 1
Fn
SYS GET_INFO type = Hardware Information True 1
Fn
MOD GET_FILENAME file_name = C:\Users\Public\N3Eg\N3Eg2.51N3E True 1
Fn
MOD GET_FILENAME file_name = C:\Windows\System32\regsvr32.exe True 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Embarcadero\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Embarcadero\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\CodeGear\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\CodeGear\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Borland\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Borland\Delphi\Locales False 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetNativeSystemInfo, address = 0x777bbe77 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetDiskFreeSpaceExW, address = 0x777bde40 True 1
Fn
MOD GET_FILENAME file_name = C:\Windows\System32\regsvr32.exe True 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Embarcadero\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Embarcadero\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\CodeGear\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\CodeGear\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Borland\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Borland\Delphi\Locales False 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\oleaut32.dll, base_address = 0x77a00000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VariantChangeTypeEx, address = 0x77a04c28 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarNeg, address = 0x77a7c802 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarNot, address = 0x77a7ec66 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarAdd, address = 0x77a25934 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarSub, address = 0x77a7d332 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarMul, address = 0x77a7dbd4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarDiv, address = 0x77a7e405 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarIdiv, address = 0x77a7f00a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarMod, address = 0x77a7f15e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarAnd, address = 0x77a25a98 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarOr, address = 0x77a7ecfa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarXor, address = 0x77a7ee2e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarCmp, address = 0x77a1b0dc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarI4FromStr, address = 0x77a16fab True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarR4FromStr, address = 0x77a201a0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarR8FromStr, address = 0x77a1699e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarDateFromStr, address = 0x77a26ba7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarCyFromStr, address = 0x77a46c12 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBoolFromStr, address = 0x77a1dbd1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromCy, address = 0x77a27fdc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromDate, address = 0x77a17a2a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromBool, address = 0x77a20355 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = InitializeConditionVariable, address = 0x77bb9981 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WakeConditionVariable, address = 0x77c05a7b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WakeAllConditionVariable, address = 0x77b845a5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SleepConditionVariableCS, address = 0x777b18be True 1
Fn
MOD GET_FILENAME file_name = C:\Windows\System32\regsvr32.exe True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateToolhelp32Snapshot, address = 0x777bf731 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Heap32ListFirst, address = 0x778102e7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Heap32ListNext, address = 0x77810391 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Heap32First, address = 0x77810429 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Heap32Next, address = 0x77810614 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Toolhelp32ReadProcessMemory, address = 0x77810819 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32First, address = 0x777e443d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32Next, address = 0x777e4505 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32FirstW, address = 0x777bfa35 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32NextW, address = 0x777bfaca True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32FirstW, address = 0x777bfa35 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Process32NextW, address = 0x777bfaca True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Thread32First, address = 0x777e7e4c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Thread32Next, address = 0x777e7edc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32First, address = 0x77810859 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32Next, address = 0x77810942 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32FirstW, address = 0x777bc59e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32NextW, address = 0x777bc11f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32FirstW, address = 0x777bc59e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Module32NextW, address = 0x777bc11f True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualAllocEx, address = 0x777bc1b6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WriteProcessMemory, address = 0x777bc1de True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateRemoteThread, address = 0x7780f33b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = OpenProcess, address = 0x777c59d7 True 1
Fn
PROC OPEN process_name = c:\windows\explorer.exe, os_pid = 0x470, desired_access = PROCESS_ALL_ACCESS True 1
Fn
MEM ALLOC address = 0x3140000, process_name = c:\windows\explorer.exe, os_pid = 0x470, size = 66, allocation_type = MEM_COMMIT, protection = PAGE_READWRITE True 1
Fn
MEM WRITE address = 0x3140000, process_name = c:\windows\explorer.exe, os_pid = 0x470, size = 66 True 1
Fn
Data
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LoadLibraryW, address = 0x777d3c01 True 1
Fn
THREAD CREATE process_name = c:\windows\explorer.exe, os_tid = 0x628, os_pid = 0x470, proc_address = 0x777d3c01, flags = THREAD_RUNS_IMMEDIATELY True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLogicalProcessorInformation, address = 0x777b2004 True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLogicalProcessorInformation, address = 0x777b2004 True 1
Fn
Process #15: explorer.exe
(Host: 844, Network: 24)
+
Information Value
ID / OS PID #15 / 0x470
OS Parent PID 0x468 (c:\windows\system32\userinit.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\explorer.exe
Command Line C:\Windows\Explorer.EXE
Monitor Start Time: 00:04:22, Reason: Injection
Unmonitor End Time: 00:06:46, Reason: Terminated
Monitor Duration 00:02:24
OS Thread IDs
# 121
0x 5E8
# 122
0x 5C4
# 123
0x 5B4
# 124
0x 59C
# 125
0x 594
# 126
0x 568
# 127
0x 564
# 128
0x 560
# 129
0x 55C
# 130
0x 558
# 131
0x 52C
# 132
0x 528
# 133
0x 524
# 134
0x 494
# 135
0x 490
# 136
0x 48C
# 137
0x 488
# 138
0x 484
# 139
0x 480
# 140
0x 47C
# 141
0x 478
# 142
0x 474
# 143
0x 628
# 144
0x 62C
# 145
0x 66C
# 146
0x 670
# 155
0x 6A0
# 156
0x 6A8
# 157
0x 6B4
# 158
0x 6C4
# 159
0x 6C8
# 160
0x 6D0
# 161
0x 6D4
# 182
0x 7C4
# 183
0x 7C8
# 184
0x 7DC
# 185
0x 7E4
# 205
0x 918
# 210
0x 954
# 242
0x A1C
# 244
0x ACC
# 246
0x B00
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00021fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000040000 0x00040000 0x00041fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000050000 0x00050000 0x00056fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00061fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000070000 0x00070000 0x00070fff Private Memory Readable, Writable True False False
private_0x0000000000080000 0x00080000 0x000bffff Private Memory Readable, Writable True False False
locale.nls 0x000c0000 0x00126fff Memory Mapped File Readable False False False
pagefile_0x0000000000130000 0x00130000 0x001f7fff Pagefile Backed Memory Readable True False False
private_0x0000000000200000 0x00200000 0x00200fff Private Memory Readable, Writable True False False
private_0x0000000000210000 0x00210000 0x0022ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000230000 0x00230000 0x00230fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000240000 0x00240000 0x00241fff Pagefile Backed Memory Readable True False False
private_0x0000000000250000 0x00250000 0x00250fff Private Memory Readable, Writable True False False
private_0x0000000000260000 0x00260000 0x0026ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000270000 0x00270000 0x00271fff Pagefile Backed Memory Readable True False False
private_0x0000000000280000 0x00280000 0x0037ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000380000 0x00380000 0x00480fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000490000 0x00490000 0x00882fff Pagefile Backed Memory Readable True False False
private_0x0000000000890000 0x00890000 0x008cffff Private Memory Readable, Writable True False False
private_0x00000000008d0000 0x008d0000 0x009cffff Private Memory Readable, Writable True False False
private_0x00000000009d0000 0x009d0000 0x009fbfff Private Memory Readable, Writable True False False
private_0x0000000000a00000 0x00a00000 0x00a2ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000a30000 0x00a30000 0x00a30fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000a40000 0x00a40000 0x00a40fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000a50000 0x00a50000 0x00a51fff Pagefile Backed Memory Readable True False False
private_0x0000000000a60000 0x00a60000 0x00a60fff Private Memory Readable, Writable True False False
private_0x0000000000a70000 0x00a70000 0x00a70fff Private Memory Readable, Writable True False False
pagefile_0x0000000000a80000 0x00a80000 0x00a81fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000a90000 0x00a90000 0x00a91fff Pagefile Backed Memory Readable True False False
private_0x0000000000aa0000 0x00aa0000 0x00adffff Private Memory Readable, Writable True False False
pagefile_0x0000000000ae0000 0x00ae0000 0x00bbefff Pagefile Backed Memory Readable True False False
private_0x0000000000bc0000 0x00bc0000 0x00bc0fff Private Memory Readable, Writable True False False
comctl32.dll.mui 0x00bd0000 0x00bd2fff Memory Mapped File Readable, Writable False False False
private_0x0000000000be0000 0x00be0000 0x00be0fff Private Memory Readable, Writable True False False
private_0x0000000000bf0000 0x00bf0000 0x00bfffff Private Memory Readable, Writable True False False
private_0x0000000000c00000 0x00c00000 0x00c08fff Private Memory Readable, Writable True False False
private_0x0000000000c10000 0x00c10000 0x00c17fff Private Memory Readable, Writable True False False
{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000000c.db 0x00c20000 0x00c3cfff Memory Mapped File Readable True False False
pagefile_0x0000000000c40000 0x00c40000 0x00c40fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000c50000 0x00c50000 0x00c8ffff Private Memory Readable, Writable True False False
cversions.2.db 0x00c90000 0x00c93fff Memory Mapped File Readable True False False
cversions.2.db 0x00ca0000 0x00ca3fff Memory Mapped File Readable True False False
pagefile_0x0000000000cb0000 0x00cb0000 0x00cb1fff Pagefile Backed Memory Readable True False False
private_0x0000000000cc0000 0x00cc0000 0x00d3ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000d40000 0x00d40000 0x00d41fff Pagefile Backed Memory Readable True False False
private_0x0000000000d50000 0x00d50000 0x00d50fff Private Memory Readable, Writable True False False
explorer.exe 0x00d60000 0x00fe0fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000ff0000 0x00ff0000 0x01beffff Pagefile Backed Memory Readable True False False
SortDefault.nls 0x01bf0000 0x01ebefff Memory Mapped File Readable False False False
private_0x0000000001ec0000 0x01ec0000 0x01f67fff Private Memory Readable, Writable True False False
private_0x0000000001f70000 0x01f70000 0x02023fff Private Memory Readable, Writable True False False
private_0x0000000002030000 0x02030000 0x02033fff Private Memory Readable, Writable True False False
private_0x0000000002040000 0x02040000 0x0207ffff Private Memory Readable, Writable True False False
private_0x0000000002040000 0x02040000 0x02043fff Private Memory Readable, Writable True False False
thumbcache_1024.db 0x02050000 0x02050fff Memory Mapped File Readable, Writable True False False
pagefile_0x0000000002050000 0x02050000 0x02051fff Pagefile Backed Memory Readable, Writable True False False
thumbcache_sr.db 0x02060000 0x02060fff Memory Mapped File Readable, Writable True False False
pagefile_0x0000000002060000 0x02060000 0x02061fff Pagefile Backed Memory Readable True False False
thumbcache_idx.db 0x02070000 0x02071fff Memory Mapped File Readable, Writable True False False
pagefile_0x0000000002070000 0x02070000 0x02071fff Pagefile Backed Memory Readable True False False
private_0x0000000002080000 0x02080000 0x0227ffff Private Memory Readable, Writable True False False
private_0x0000000002280000 0x02280000 0x022bffff Private Memory Readable, Writable True False False
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000007.db 0x022c0000 0x022effff Memory Mapped File Readable True False False
private_0x00000000022f0000 0x022f0000 0x022f3fff Private Memory Readable, Writable True False False
private_0x0000000002300000 0x02300000 0x02300fff Private Memory Readable, Writable True False False
private_0x0000000002300000 0x02300000 0x02300fff Private Memory Readable, Writable True False False
private_0x0000000002310000 0x02310000 0x0234ffff Private Memory Readable, Writable True False False
ActionCenter.dll.mui 0x02310000 0x02314fff Memory Mapped File Readable, Writable False False False
private_0x0000000002350000 0x02350000 0x02350fff Private Memory Readable, Writable True False False
private_0x0000000002360000 0x02360000 0x0239ffff Private Memory Readable, Writable True False False
private_0x00000000023a0000 0x023a0000 0x023a0fff Private Memory Readable, Writable True False False
private_0x00000000023b0000 0x023b0000 0x023effff Private Memory Readable, Writable True False False
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db 0x023f0000 0x02455fff Memory Mapped File Readable True False False
private_0x0000000002460000 0x02460000 0x02460fff Private Memory Readable, Writable True False False
private_0x0000000002470000 0x02470000 0x02470fff Private Memory Readable, Writable True False False
private_0x0000000002480000 0x02480000 0x02480fff Private Memory Readable, Writable True False False
private_0x0000000002490000 0x02490000 0x02490fff Private Memory Readable, Writable True False False
private_0x00000000024a0000 0x024a0000 0x024a0fff Private Memory Readable, Writable True False False
private_0x00000000024b0000 0x024b0000 0x024effff Private Memory Readable, Writable True False False
StaticCache.dat 0x024f0000 0x02e1ffff Memory Mapped File Readable False False False
pagefile_0x0000000002e20000 0x02e20000 0x02e20fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000002e30000 0x02e30000 0x02e31fff Pagefile Backed Memory Readable True False False
cversions.2.db 0x02e40000 0x02e43fff Memory Mapped File Readable True False False
pagefile_0x0000000002e50000 0x02e50000 0x02e51fff Pagefile Backed Memory Readable True False False
{7CD55808-3D38-4DD5-90C9-62F0E6EE60D4}.2.ver0x0000000000000001.db 0x02e60000 0x02e60fff Memory Mapped File Readable True False False
private_0x0000000002e70000 0x02e70000 0x02e73fff Private Memory Readable, Writable True False False
private_0x0000000002e70000 0x02e70000 0x02e70fff Private Memory Readable, Writable True False False
private_0x0000000002e80000 0x02e80000 0x02e80fff Private Memory Readable, Writable True False False
private_0x0000000002e90000 0x02e90000 0x02e90fff Private Memory Readable, Writable True False False
private_0x0000000002ea0000 0x02ea0000 0x02ea0fff Private Memory Readable, Writable True False False
private_0x0000000002eb0000 0x02eb0000 0x02eeffff Private Memory Readable, Writable True False False
private_0x0000000002ef0000 0x02ef0000 0x02feffff Private Memory Readable, Writable True False False
private_0x0000000002ff0000 0x02ff0000 0x02ff0fff Private Memory Readable, Writable True False False
private_0x0000000002ff0000 0x02ff0000 0x0302ffff Private Memory Readable, Writable True False False
private_0x0000000003000000 0x03000000 0x03000fff Private Memory Readable, Writable True False False
private_0x0000000003010000 0x03010000 0x03010fff Private Memory Readable, Writable True False False
private_0x0000000003020000 0x03020000 0x03020fff Private Memory Readable, Writable True False False
private_0x0000000003020000 0x03020000 0x0305ffff Private Memory Readable, Writable True False False
thumbcache_1024.db 0x03030000 0x03030fff Memory Mapped File Readable, Writable True False False
thumbcache_sr.db 0x03040000 0x03040fff Memory Mapped File Readable, Writable True False False
thumbcache_idx.db 0x03050000 0x03051fff Memory Mapped File Readable, Writable True False False
private_0x0000000003060000 0x03060000 0x0309ffff Private Memory Readable, Writable True False False
pagefile_0x00000000030a0000 0x030a0000 0x030a0fff Pagefile Backed Memory Readable True False False
wdmaud.drv.mui 0x030b0000 0x030b0fff Memory Mapped File Readable, Writable False False False
pagefile_0x00000000030c0000 0x030c0000 0x030c1fff Pagefile Backed Memory Readable True False False
MMDevAPI.dll.mui 0x030d0000 0x030d0fff Memory Mapped File Readable, Writable False False False
private_0x00000000030e0000 0x030e0000 0x0311ffff Private Memory Readable, Writable True False False
private_0x0000000003120000 0x03120000 0x03120fff Private Memory Readable, Writable True False False
private_0x0000000003130000 0x03130000 0x03131fff Private Memory Readable, Writable True False False
private_0x0000000003140000 0x03140000 0x03140fff Private Memory Readable, Writable True False False
private_0x0000000003150000 0x03150000 0x0318ffff Private Memory Readable, Writable True False False
private_0x0000000003190000 0x03190000 0x031dffff Private Memory Readable, Writable True False False
private_0x0000000003190000 0x03190000 0x03190fff Private Memory Readable, Writable True False False
private_0x00000000031a0000 0x031a0000 0x031a0fff Private Memory Readable, Writable True False False
private_0x00000000031b0000 0x031b0000 0x031b0fff Private Memory Readable, Writable True False False
private_0x00000000031c0000 0x031c0000 0x031c0fff Private Memory Readable, Writable True False False
private_0x00000000031e0000 0x031e0000 0x03227fff Private Memory Readable, Writable True False False
pagefile_0x0000000003230000 0x03230000 0x03231fff Pagefile Backed Memory Readable, Writable True False False
oleaccrc.dll 0x03230000 0x03230fff Memory Mapped File Readable False False False
private_0x0000000003240000 0x03240000 0x03241fff Private Memory Readable, Writable True False False
private_0x0000000003250000 0x03250000 0x0328ffff Private Memory Readable, Writable True False False
pagefile_0x0000000003290000 0x03290000 0x03291fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000032a0000 0x032a0000 0x032a1fff Pagefile Backed Memory Readable True False False
cversions.2.db 0x032b0000 0x032b3fff Memory Mapped File Readable True False False
private_0x00000000032c0000 0x032c0000 0x032fffff Private Memory Readable, Writable True False False
private_0x00000000032c0000 0x032c0000 0x032fffff Private Memory Readable, Writable True False False
private_0x0000000003300000 0x03300000 0x03300fff Private Memory Readable, Writable, Executable True False False
pagefile_0x0000000003310000 0x03310000 0x03311fff Pagefile Backed Memory Readable True False False
private_0x0000000003320000 0x03320000 0x0335ffff Private Memory Readable, Writable True False False
pagefile_0x0000000003360000 0x03360000 0x03361fff Pagefile Backed Memory Readable True False False
private_0x0000000003370000 0x03370000 0x0337ffff Private Memory Readable, Writable True False False
bthprops.cpl.mui 0x03380000 0x03386fff Memory Mapped File Readable, Writable False False False
private_0x0000000003390000 0x03390000 0x033cffff Private Memory Readable, Writable True False False
private_0x00000000033d0000 0x033d0000 0x03402fff Private Memory Readable, Writable True False False
pagefile_0x0000000003410000 0x03410000 0x03411fff Pagefile Backed Memory Readable True False False
private_0x0000000003420000 0x03420000 0x0345ffff Private Memory Readable, Writable True False False
private_0x0000000003420000 0x03420000 0x03420fff Private Memory Readable, Writable, Executable True False False
private_0x0000000003430000 0x03430000 0x0343ffff Private Memory Readable, Writable True False False
index.dat 0x03440000 0x03453fff Memory Mapped File Readable, Writable True True False
private_0x0000000003460000 0x03460000 0x0349ffff Private Memory Readable, Writable True False False
thumbcache_32.db 0x034a0000 0x0359ffff Memory Mapped File Readable, Writable True False False
index.dat 0x035a0000 0x035a7fff Memory Mapped File Readable, Writable True True False
index.dat 0x035b0000 0x035bbfff Memory Mapped File Readable, Writable True True False
pagefile_0x00000000035c0000 0x035c0000 0x035c0fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x00000000035d0000 0x035d0000 0x035d0fff Pagefile Backed Memory Readable, Writable True False False
thumbcache_96.db 0x035e0000 0x036dffff Memory Mapped File Readable, Writable True False False
thumbcache_256.db 0x036e0000 0x037dffff Memory Mapped File Readable, Writable True False False
private_0x00000000037e0000 0x037e0000 0x037e2fff Private Memory Readable, Writable True False False
private_0x00000000037f0000 0x037f0000 0x0382ffff Private Memory Readable, Writable True False False
pagefile_0x0000000003830000 0x03830000 0x03831fff Pagefile Backed Memory Readable True False False
private_0x0000000003840000 0x03840000 0x0387ffff Private Memory Readable, Writable True False False
imageres.dll 0x03880000 0x04bd4fff Memory Mapped File Readable False False False
N3Eg4.51N3E 0x04be0000 0x04c54fff Memory Mapped File Readable, Writable, Executable True True False
pagefile_0x0000000004c60000 0x04c60000 0x04c61fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000004c70000 0x04c70000 0x04c71fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000004c80000 0x04c80000 0x04c81fff Pagefile Backed Memory Readable True False False
private_0x0000000004cb0000 0x04cb0000 0x04ceffff Private Memory Readable, Writable True False False
private_0x0000000004d00000 0x04d00000 0x04d3ffff Private Memory Readable, Writable True False False
private_0x0000000004d40000 0x04d40000 0x05141fff Private Memory Readable, Writable True False False
private_0x0000000005160000 0x05160000 0x0519ffff Private Memory Readable, Writable True False False
private_0x00000000051c0000 0x051c0000 0x051fffff Private Memory Readable, Writable True False False
private_0x00000000051d0000 0x051d0000 0x0520ffff Private Memory Readable, Writable True False False
private_0x0000000005210000 0x05210000 0x0530ffff Private Memory - True False False
private_0x0000000005310000 0x05310000 0x0534ffff Private Memory Readable, Writable True False False
private_0x0000000005350000 0x05350000 0x055e2fff Private Memory Readable, Writable True False False
private_0x00000000055f0000 0x055f0000 0x057effff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059aefff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059b2fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059b6fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059bafff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059befff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059c2fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059c6fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059cafff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059cefff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059d2fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059d6fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059dafff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059defff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059e2fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059e6fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059eafff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059eefff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059f2fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059f6fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059fafff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x059fefff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a02fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a06fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a0afff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a0efff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a12fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a16fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a1afff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a1efff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a22fff Private Memory Readable, Writable True False False
private_0x00000000057f0000 0x057f0000 0x05a26fff Private Memory Readable, Writable True False False
KernelBase.dll.mui 0x057f0000 0x058affff Memory Mapped File Readable, Writable False False False
thumbcache_32.db 0x058b0000 0x059affff Memory Mapped File Readable, Writable True False False
private_0x00000000058c0000 0x058c0000 0x058fffff Private Memory Readable, Writable True False False
private_0x00000000059b0000 0x059b0000 0x05b6cfff Private Memory Readable, Writable True False False
private_0x00000000059d0000 0x059d0000 0x05a0ffff Private Memory Readable, Writable True False False
private_0x0000000005a40000 0x05a40000 0x05a7ffff Private Memory Readable, Writable True False False
private_0x0000000005a90000 0x05a90000 0x05acffff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05c90fff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05c94fff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05c98fff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05c9cfff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05ca0fff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05ca4fff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05ca8fff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05cacfff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05cb0fff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05cb4fff Private Memory Readable, Writable True False False
private_0x0000000005ad0000 0x05ad0000 0x05cb8fff Private Memory Readable, Writable True False False
private_0x0000000005ae0000 0x05ae0000 0x05b1ffff Private Memory Readable, Writable True False False
private_0x0000000005b20000 0x05b20000 0x05b5ffff Private Memory Readable, Writable True False False
private_0x0000000005b90000 0x05b90000 0x05bcffff Private Memory Readable, Writable True False False
private_0x0000000005c10000 0x05c10000 0x05c1ffff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e0cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e10fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e14fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e18fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e1cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e20fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e24fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e28fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e2cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e30fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e34fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e38fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e40fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e44fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e48fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e4cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e50fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e54fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e58fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e5cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e60fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e64fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e68fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e6cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e70fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e74fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e78fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e7cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e80fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e84fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e88fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e8cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e90fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e94fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e98fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05e9cfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05ea0fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05ea4fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05ea8fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05eacfff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05eb0fff Private Memory Readable, Writable True False False
private_0x0000000005c20000 0x05c20000 0x05ebffff Private Memory - True False False
private_0x0000000005c60000 0x05c60000 0x05c9ffff Private Memory Readable, Writable True False False
private_0x0000000005ca0000 0x05ca0000 0x05ebcfff Private Memory Readable, Writable True False False
private_0x0000000005ec0000 0x05ec0000 0x05efffff Private Memory Readable, Writable True False False
private_0x0000000005f30000 0x05f30000 0x05f6ffff Private Memory Readable, Writable True False False
private_0x0000000005fb0000 0x05fb0000 0x05fbffff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x061fafff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x061fefff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06202fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06206fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0620afff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0620efff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06212fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06216fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0621afff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0621efff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06222fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06226fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0622afff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0622efff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06232fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06236fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0623afff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0623efff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06242fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06246fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0624afff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0624efff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x06252fff Private Memory Readable, Writable True False False
private_0x0000000005fc0000 0x05fc0000 0x0625bfff Private Memory Readable, Writable True False False
private_0x0000000006260000 0x06260000 0x0639ffff Private Memory Readable, Writable True False False
thumbcache_96.db 0x063a0000 0x0649ffff Memory Mapped File Readable, Writable True False False
thumbcache_256.db 0x064a0000 0x0659ffff Memory Mapped File Readable, Writable True False False
private_0x00000000065a0000 0x065a0000 0x065effff Private Memory Readable, Writable True False False
thumbcache_256.db 0x065f0000 0x0669ffff Memory Mapped File Readable, Writable True False False
private_0x0000000006720000 0x06720000 0x0675ffff Private Memory Readable, Writable True False False
private_0x00000000067f0000 0x067f0000 0x0682ffff Private Memory Readable, Writable True False False
private_0x00000000068b0000 0x068b0000 0x068effff Private Memory Readable, Writable True False False
private_0x0000000006950000 0x06950000 0x0698ffff Private Memory Readable, Writable True False False
private_0x00000000069d0000 0x069d0000 0x06a0ffff Private Memory Readable, Writable True False False
private_0x0000000006a80000 0x06a80000 0x06abffff Private Memory Readable, Writable True False False
ieproxy.dll 0x6dec0000 0x6deeafff Memory Mapped File Readable, Writable, Executable False False False
hcproviders.dll 0x6def0000 0x6def8fff Memory Mapped File Readable, Writable, Executable False False False
wercplsupport.dll 0x6df00000 0x6df11fff Memory Mapped File Readable, Writable, Executable False False False
framedynos.dll 0x6df20000 0x6df54fff Memory Mapped File Readable, Writable, Executable False False False
werconcpl.dll 0x6df60000 0x6e065fff Memory Mapped File Readable, Writable, Executable False False False
wscui.cpl 0x6e070000 0x6e189fff Memory Mapped File Readable, Writable, Executable False False False
wscapi.dll 0x6e190000 0x6e19efff Memory Mapped File Readable, Writable, Executable False False False
wscinterop.dll 0x6e1c0000 0x6e1d9fff Memory Mapped File Readable, Writable, Executable False False False
QAGENT.DLL 0x6ea40000 0x6ea6dfff Memory Mapped File Readable, Writable, Executable False False False
npmproxy.dll 0x6ed50000 0x6ed57fff Memory Mapped File Readable, Writable, Executable False False False
idndl.dll 0x6ee90000 0x6ee9afff Memory Mapped File Readable, Writable, Executable False False False
msftedit.dll 0x6f5c0000 0x6f653fff Memory Mapped File Readable, Writable, Executable False False False
netprofm.dll 0x6f6b0000 0x6f709fff Memory Mapped File Readable, Writable, Executable False False False
rasadhlp.dll 0x6f710000 0x6f715fff Memory Mapped File Readable, Writable, Executable False False False
provsvc.dll 0x6fb60000 0x6fb8afff Memory Mapped File Readable, Writable, Executable False False False
hgcpl.dll 0x6fb90000 0x6fbdefff Memory Mapped File Readable, Writable, Executable False False False
SyncCenter.dll 0x6fd30000 0x6ff3dfff Memory Mapped File Readable, Writable, Executable False False False
mlang.dll 0x6ffd0000 0x6fffdfff Memory Mapped File Readable, Writable, Executable False False False
imapi2.dll 0x6ffd0000 0x70033fff Memory Mapped File Readable, Writable, Executable False False False
webcheck.dll 0x70000000 0x70039fff Memory Mapped File Readable, Writable, Executable False False False
srchadmin.dll 0x701c0000 0x7020cfff Memory Mapped File Readable, Writable, Executable False False False
ieframe.dll 0x70d80000 0x717fffff Memory Mapped File Readable, Writable, Executable False False False
midimap.dll 0x71880000 0x71886fff Memory Mapped File Readable, Writable, Executable False False False
msacm32.dll 0x71890000 0x718a3fff Memory Mapped File Readable, Writable, Executable False False False
msacm32.drv 0x718b0000 0x718b7fff Memory Mapped File Readable, Writable, Executable False False False
AudioSes.dll 0x718c0000 0x718f5fff Memory Mapped File Readable, Writable, Executable False False False
ksuser.dll 0x71900000 0x71903fff Memory Mapped File Readable, Writable, Executable False False False
wdmaud.drv 0x71910000 0x7193ffff Memory Mapped File Readable, Writable, Executable False False False
winmm.dll 0x71940000 0x71971fff Memory Mapped File Readable, Writable, Executable False False False
networkexplorer.dll 0x71980000 0x71b17fff Memory Mapped File Readable, Writable, Executable False False False
thumbcache.dll 0x71b20000 0x71b35fff Memory Mapped File Readable, Writable, Executable False False False
tiptsf.dll 0x71d80000 0x71dd7fff Memory Mapped File Readable, Writable, Executable False False False
msls31.dll 0x71de0000 0x71e09fff Memory Mapped File Readable, Writable, Executable False False False
msftedit.dll 0x71e10000 0x71ea3fff Memory Mapped File Readable, Writable, Executable False False False
wwapi.dll 0x71e20000 0x71e29fff Memory Mapped File Readable, Writable, Executable False False False
WWanAPI.dll 0x71e30000 0x71e77fff Memory Mapped File Readable, Writable, Executable False False False
wlanutil.dll 0x71e80000 0x71e85fff Memory Mapped File Readable, Writable, Executable False False False
wlanapi.dll 0x71e90000 0x71ea5fff Memory Mapped File Readable, Writable, Executable False False False
wer.dll 0x71eb0000 0x71f10fff Memory Mapped File Readable, Writable, Executable False False False
gameux.dll 0x71f20000 0x72197fff Memory Mapped File Readable, Writable, Executable False False False
linkinfo.dll 0x721f0000 0x721f8fff Memory Mapped File Readable, Writable, Executable False False False
shdocvw.dll 0x72200000 0x7222dfff Memory Mapped File Readable, Writable, Executable False False False
actxprxy.dll 0x72310000 0x7235dfff Memory Mapped File Readable, Writable, Executable False False False
dhcpcsvc.dll 0x72430000 0x72441fff Memory Mapped File Readable, Writable, Executable False False False
dhcpcsvc6.dll 0x72450000 0x7245cfff Memory Mapped File Readable, Writable, Executable False False False
FWPUCLNT.DLL 0x72470000 0x724a7fff Memory Mapped File Readable, Writable, Executable False False False
FWPUCLNT.DLL 0x72470000 0x724a7fff Memory Mapped File Readable, Writable, Executable False False False
timedate.cpl 0x72820000 0x72897fff Memory Mapped File Readable, Writable, Executable False False False
IconCodecService.dll 0x728a0000 0x728a5fff Memory Mapped File Readable, Writable, Executable False False False
ntshrui.dll 0x728b0000 0x7291ffff Memory Mapped File Readable, Writable, Executable False False False
cscapi.dll 0x72920000 0x7292afff Memory Mapped File Readable, Writable, Executable False False False
cscdll.dll 0x72930000 0x72938fff Memory Mapped File Readable, Writable, Executable False False False
cscui.dll 0x72940000 0x729a9fff Memory Mapped File Readable, Writable, Executable False False False
EhStorShell.dll 0x729b0000 0x729e0fff Memory Mapped File Readable, Writable, Executable False False False
apphelp.dll 0x729f0000 0x72a3bfff Memory Mapped File Readable, Writable, Executable False False False
ExplorerFrame.dll 0x72a40000 0x72baefff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x72c80000 0x72c86fff Memory Mapped File Readable, Writable, Executable False False False
IPHLPAPI.DLL 0x72c90000 0x72cabfff Memory Mapped File Readable, Writable, Executable False False False
UIAnimation.dll 0x72f90000 0x72faafff Memory Mapped File Readable, Writable, Executable False False False
FXSRESM.dll 0x72fb0000 0x73092fff Memory Mapped File Readable, Writable, Executable False False False
FXSAPI.dll 0x730a0000 0x730d9fff Memory Mapped File Readable, Writable, Executable False False False
FXSST.dll 0x730e0000 0x731b1fff Memory Mapped File Readable, Writable, Executable False False False
webio.dll 0x731c0000 0x7320efff Memory Mapped File Readable, Writable, Executable False False False
winhttp.dll 0x73210000 0x73267fff Memory Mapped File Readable, Writable, Executable False False False
ncsi.dll 0x73270000 0x73297fff Memory Mapped File Readable, Writable, Executable False False False
security.dll 0x73270000 0x73272fff Memory Mapped File Readable, Writable, Executable False False False
olepro32.dll 0x73280000 0x73298fff Memory Mapped File Readable, Writable, Executable False False False
oleacc.dll 0x732a0000 0x732dbfff Memory Mapped File Readable, Writable, Executable False False False
bthprops.cpl 0x73320000 0x733cffff Memory Mapped File Readable, Writable, Executable False False False
ActionCenter.dll 0x733d0000 0x73489fff Memory Mapped File Readable, Writable, Executable False False False
cscobj.dll 0x73490000 0x734b4fff Memory Mapped File Readable, Writable, Executable False False False
QUTIL.DLL 0x73500000 0x73516fff Memory Mapped File Readable, Writable, Executable False False False
pnidui.dll 0x73520000 0x736cdfff Memory Mapped File Readable, Writable, Executable False False False
AltTab.dll 0x736d0000 0x736ddfff Memory Mapped File Readable, Writable, Executable False False False
PortableDeviceApi.dll 0x736e0000 0x73768fff Memory Mapped File Readable, Writable, Executable False False False
PortableDeviceTypes.dll 0x73770000 0x7379afff Memory Mapped File Readable, Writable, Executable False False False
WPDShServiceObj.dll 0x737a0000 0x737bcfff Memory Mapped File Readable, Writable, Executable False False False
netshell.dll 0x737d0000 0x73a34fff Memory Mapped File Readable, Writable, Executable False False False
ehSSO.dll 0x73a40000 0x73a47fff Memory Mapped File Readable, Writable, Executable False False False
DXP.dll 0x73a50000 0x73ab3fff Memory Mapped File Readable, Writable, Executable False False False
winspool.drv 0x73c90000 0x73ce0fff Memory Mapped File Readable, Writable, Executable False False False
prnfldr.dll 0x73cf0000 0x73d53fff Memory Mapped File Readable, Writable, Executable False False False
batmeter.dll 0x73d60000 0x73e16fff Memory Mapped File Readable, Writable, Executable False False False
es.dll 0x74010000 0x74056fff Memory Mapped File Readable, Writable, Executable False False False
slc.dll 0x74070000 0x74079fff Memory Mapped File Readable, Writable, Executable False False False
atl.dll 0x740a0000 0x740b3fff Memory Mapped File Readable, Writable, Executable False False False
nlaapi.dll 0x74130000 0x7413ffff Memory Mapped File Readable, Writable, Executable False False False
taskschd.dll 0x741e0000 0x7425cfff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x74320000 0x74340fff Memory Mapped File Readable, Writable, Executable False False False
avrt.dll 0x74370000 0x74376fff Memory Mapped File Readable, Writable, Executable False False False
powrprof.dll 0x74380000 0x743a4fff Memory Mapped File Readable, Writable, Executable False False False
Syncreg.dll 0x74430000 0x7443ffff Memory Mapped File Readable, Writable, Executable False False False
stobject.dll 0x74440000 0x74479fff Memory Mapped File Readable, Writable, Executable False False False
samcli.dll 0x74560000 0x7456efff Memory Mapped File Readable, Writable, Executable False False False
wkscli.dll 0x74570000 0x7457efff Memory Mapped File Readable, Writable, Executable False False False
netutils.dll 0x74580000 0x74588fff Memory Mapped File Readable, Writable, Executable False False False
wtsapi32.dll 0x74690000 0x7469cfff Memory Mapped File Readable, Writable, Executable False False False
WindowsCodecs.dll 0x746b0000 0x747aafff Memory Mapped File Readable, Writable, Executable False False False
xmllite.dll 0x747b0000 0x747defff Memory Mapped File Readable, Writable, Executable False False False
dwmapi.dll 0x747e0000 0x747f2fff Memory Mapped File Readable, Writable, Executable False False False
MMDevAPI.dll 0x74800000 0x74838fff Memory Mapped File Readable, Writable, Executable False False False
hid.dll 0x74840000 0x74848fff Memory Mapped File Readable, Writable, Executable False False False
SndVolSSO.dll 0x74850000 0x74887fff Memory Mapped File Readable, Writable, Executable False False False
duser.dll 0x74890000 0x748befff Memory Mapped File Readable, Writable, Executable False False False
dui70.dll 0x748c0000 0x74971fff Memory Mapped File Readable, Writable, Executable False False False
GdiPlus.dll 0x74980000 0x74b0ffff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x74b10000 0x74b4ffff Memory Mapped File Readable, Writable, Executable False False False
propsys.dll 0x74b50000 0x74c44fff Memory Mapped File Readable, Writable, Executable False False False
samlib.dll 0x74c50000 0x74c61fff Memory Mapped File Readable, Writable, Executable False False False
shacct.dll 0x74c70000 0x74c8dfff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x74c90000 0x74e2dfff Memory Mapped File Readable, Writable, Executable False False False
cryptui.dll 0x74e30000 0x74f27fff Memory Mapped File Readable, Writable, Executable False False False
authui.dll 0x74f30000 0x750e6fff Memory Mapped File Readable, Writable, Executable False False False
version.dll 0x75200000 0x75208fff Memory Mapped File Readable, Writable, Executable False False False
WSHTCPIP.DLL 0x75290000 0x75294fff Memory Mapped File Readable, Writable, Executable False False False
userenv.dll 0x75360000 0x75376fff Memory Mapped File Readable, Writable, Executable False False False
credssp.dll 0x75450000 0x75457fff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x75520000 0x7555afff Memory Mapped File Readable, Writable, Executable False False False
dnsapi.dll 0x75600000 0x75643fff Memory Mapped File Readable, Writable, Executable False False False
wship6.dll 0x75730000 0x75735fff Memory Mapped File Readable, Writable, Executable False False False
mswsock.dll 0x75740000 0x7577bfff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x75780000 0x75795fff Memory Mapped File Readable, Writable, Executable False False False
wevtapi.dll 0x75940000 0x75981fff Memory Mapped File Readable, Writable, Executable False False False
srvcli.dll 0x75b50000 0x75b68fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x75bc0000 0x75bc7fff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x75be0000 0x75bfafff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x75c00000 0x75c0bfff Memory Mapped File Readable, Writable, Executable False False False
sxs.dll 0x75c10000 0x75c6efff Memory Mapped File Readable, Writable, Executable False False False
winsta.dll 0x75c70000 0x75c98fff Memory Mapped File Readable, Writable, Executable False False False
RpcRtRemote.dll 0x75ca0000 0x75cadfff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x75cb0000 0x75cbafff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x75d20000 0x75d2bfff Memory Mapped File Readable, Writable, Executable False False False
devobj.dll 0x75d30000 0x75d41fff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x75d50000 0x75e6cfff Memory Mapped File Readable, Writable, Executable False False False
wintrust.dll 0x75e70000 0x75e9cfff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x75f30000 0x75f79fff Memory Mapped File Readable, Writable, Executable False False False
cfgmgr32.dll 0x75f80000 0x75fa6fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x75fb0000 0x75fcefff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x75fd0000 0x76004fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76010000 0x7605dfff Memory Mapped File Readable, Writable, Executable False False False
Wldap32.dll 0x76060000 0x760a4fff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76110000 0x761b0fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x761c0000 0x7626bfff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x76270000 0x76338fff Memory Mapped File Readable, Writable, Executable False False False
setupapi.dll 0x76340000 0x764dcfff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x764e0000 0x77129fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x77130000 0x771cffff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x771d0000 0x772c4fff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x77380000 0x7757afff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x77580000 0x7761cfff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x77620000 0x7777bfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x77780000 0x77853fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x77860000 0x778b6fff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x778c0000 0x779f5fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x77a00000 0x77a8efff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x77a90000 0x77b5bfff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b60000 0x77c9bfff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x77ca0000 0x77ca5fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x77cb0000 0x77cb4fff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x77cc0000 0x77cc9fff Memory Mapped File Readable, Writable, Executable False False False
normaliz.dll 0x77cd0000 0x77cd2fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77ce0000 0x77cf8fff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x77d00000 0x77d82fff Memory Mapped File Readable, Writable, Executable False False False
apisetschema.dll 0x77da0000 0x77da0fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory Readable True False False
private_0x000000007ff9d000 0x7ff9d000 0x7ff9dfff Private Memory Readable, Writable True False False
private_0x000000007ff9e000 0x7ff9e000 0x7ff9efff Private Memory Readable, Writable True False False
private_0x000000007ff9f000 0x7ff9f000 0x7ff9ffff Private Memory Readable, Writable True False False
private_0x000000007ffa0000 0x7ffa0000 0x7ffa0fff Private Memory Readable, Writable True False False
private_0x000000007ffa1000 0x7ffa1000 0x7ffa1fff Private Memory Readable, Writable True False False
private_0x000000007ffa2000 0x7ffa2000 0x7ffa2fff Private Memory Readable, Writable True False False
private_0x000000007ffa3000 0x7ffa3000 0x7ffa3fff Private Memory Readable, Writable True False False
private_0x000000007ffa3000 0x7ffa3000 0x7ffa3fff Private Memory Readable, Writable True False False
private_0x000000007ffa4000 0x7ffa4000 0x7ffa4fff Private Memory Readable, Writable True False False
private_0x000000007ffa5000 0x7ffa5000 0x7ffa5fff Private Memory Readable, Writable True False False
private_0x000000007ffa6000 0x7ffa6000 0x7ffa6fff Private Memory Readable, Writable True False False
private_0x000000007ffa7000 0x7ffa7000 0x7ffa7fff Private Memory Readable, Writable True False False
private_0x000000007ffa8000 0x7ffa8000 0x7ffa8fff Private Memory Readable, Writable True False False
private_0x000000007ffa8000 0x7ffa8000 0x7ffa8fff Private Memory Readable, Writable True False False
private_0x000000007ffa9000 0x7ffa9000 0x7ffa9fff Private Memory Readable, Writable True False False
private_0x000000007ffa9000 0x7ffa9000 0x7ffa9fff Private Memory Readable, Writable True False False
private_0x000000007ffaa000 0x7ffaa000 0x7ffaafff Private Memory Readable, Writable True False False
private_0x000000007ffab000 0x7ffab000 0x7ffabfff Private Memory Readable, Writable True False False
private_0x000000007ffac000 0x7ffac000 0x7ffacfff Private Memory Readable, Writable True False False
private_0x000000007ffad000 0x7ffad000 0x7ffadfff Private Memory Readable, Writable True False False
private_0x000000007ffae000 0x7ffae000 0x7ffaefff Private Memory Readable, Writable True False False
private_0x000000007ffaf000 0x7ffaf000 0x7ffaffff Private Memory Readable, Writable True False False
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory Readable True False False
private_0x000000007ffd3000 0x7ffd3000 0x7ffd3fff Private Memory Readable, Writable True False False
private_0x000000007ffd4000 0x7ffd4000 0x7ffd4fff Private Memory Readable, Writable True False False
private_0x000000007ffd5000 0x7ffd5000 0x7ffd5fff Private Memory Readable, Writable True False False
private_0x000000007ffd6000 0x7ffd6000 0x7ffd6fff Private Memory Readable, Writable True False False
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory Readable, Writable True False False
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory Readable, Writable True False False
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory Readable, Writable True False False
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory Readable, Writable True False False
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory Readable, Writable True False False
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory Readable, Writable True False False
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory Readable, Writable True False False
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory Readable, Writable True False False
Injection Information
+
Injection Type Source Process Source Os Thread ID Injection Info Success Count Logfile
Modify Memory c:\windows\system32\regsvr32.exe 0x578 address = 0x3140000, size = 66 True 1
Fn
Data
Create Remote Thread c:\windows\system32\regsvr32.exe 0x578 os_thread_id = 0x628, address = 0x777d3c01, flags = THREAD_RUNS_IMMEDIATELY True 1
Fn
Threads
Thread 0x628
(Host: 33, Network: 0)
+
Category Operation Information Success Count Logfile
KEYBOARD GET_INFO type = 0, result_out = 4 True 1
Fn
MOD GET_FILENAME file_name = C:\Users\Public\N3Eg\N3Eg4.51N3E True 1
Fn
MOD GET_FILENAME file_name = C:\Windows\Explorer.EXE True 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Borland\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Borland\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Borland\Delphi\Locales False 1
Fn
MOD LOAD module_name = C:\Users\Public\N3Eg\N3Eg4.ENU, base_address = 0x0 False 1
Fn
MOD LOAD module_name = C:\Users\Public\N3Eg\N3Eg4.EN, base_address = 0x0 False 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetDiskFreeSpaceExA, address = 0x7780f46f True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\oleaut32.dll, base_address = 0x77a00000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VariantChangeTypeEx, address = 0x77a04c28 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarNeg, address = 0x77a7c802 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarNot, address = 0x77a7ec66 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarAdd, address = 0x77a25934 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarSub, address = 0x77a7d332 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarMul, address = 0x77a7dbd4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarDiv, address = 0x77a7e405 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarIdiv, address = 0x77a7f00a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarMod, address = 0x77a7f15e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarAnd, address = 0x77a25a98 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarOr, address = 0x77a7ecfa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarXor, address = 0x77a7ee2e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarCmp, address = 0x77a1b0dc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarI4FromStr, address = 0x77a16fab True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarR4FromStr, address = 0x77a201a0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarR8FromStr, address = 0x77a1699e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarDateFromStr, address = 0x77a26ba7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarCyFromStr, address = 0x77a46c12 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBoolFromStr, address = 0x77a1dbd1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromCy, address = 0x77a27fdc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromDate, address = 0x77a17a2a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromBool, address = 0x77a20355 True 1
Fn
Thread 0x62c
(Host: 811, Network: 24)
+
Category Operation Information Success Count Logfile
FILE CREATE file_name = c:\users\public\n3eg\n3eg1.51n3e, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE READ file_name = c:\users\public\n3eg\n3eg1.51n3e, size = 2689537 True 1
Fn
MOD LOAD module_name = oleaut32.dll, base_address = 0x77a00000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = SysFreeString, address = 0x77a03e59 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = SysReAllocStringLen, address = 0x77a07810 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = SysAllocStringLen, address = 0x77a045d2 True 1
Fn
MOD LOAD module_name = advapi32.dll, base_address = 0x77130000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegQueryValueExW, address = 0x771446ad True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegOpenKeyExW, address = 0x7714468d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegCloseKey, address = 0x7714469d True 1
Fn
MOD LOAD module_name = user32.dll, base_address = 0x76270000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MessageBoxA, address = 0x762cea11 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CharNextW, address = 0x76280be6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = LoadStringW, address = 0x7627dfba True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Sleep, address = 0x777cba46 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualFree, address = 0x777d1da4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualAlloc, address = 0x777d2fb6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = lstrlenW, address = 0x777cd9e8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualQuery, address = 0x777d76d6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = QueryPerformanceCounter, address = 0x777cbb9f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetTickCount, address = 0x777cba60 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetSystemInfo, address = 0x777d3728 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetVersion, address = 0x777c154e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CompareStringW, address = 0x777c9bee True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = IsValidLocale, address = 0x777c3de4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetThreadLocale, address = 0x777e88e6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetSystemDefaultUILanguage, address = 0x777b731d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetUserDefaultUILanguage, address = 0x777c22ef True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLocaleInfoW, address = 0x777d6596 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WideCharToMultiByte, address = 0x777d450e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = MultiByteToWideChar, address = 0x777d452b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetACP, address = 0x777d39aa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LoadLibraryExW, address = 0x777c4775 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetStartupInfoW, address = 0x777d3891 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetProcAddress, address = 0x777d33d3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetModuleHandleW, address = 0x777d374d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetModuleFileNameW, address = 0x777d3c26 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetCommandLineW, address = 0x777d679e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FreeLibrary, address = 0x777cd9d0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLastError, address = 0x777cbf00 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = UnhandledExceptionFilter, address = 0x777ded38 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = RtlUnwind, address = 0x777b7f70 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = RaiseException, address = 0x777beb60 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = ExitProcess, address = 0x777d214f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = ExitThread, address = 0x77b8f611 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SwitchToThread, address = 0x777beb24 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetCurrentThreadId, address = 0x777cbb80 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateThread, address = 0x777d375d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = DeleteCriticalSection, address = 0x77bb9ac5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LeaveCriticalSection, address = 0x77ba7760 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = EnterCriticalSection, address = 0x77ba77a0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = InitializeCriticalSection, address = 0x77bba149 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FindFirstFileW, address = 0x777d53b2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FindClose, address = 0x777d0e62 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WriteFile, address = 0x777d1400 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetStdHandle, address = 0x777d1e46 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CloseHandle, address = 0x777cca7c True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetProcAddress, address = 0x777d33d3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = RaiseException, address = 0x777beb60 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LoadLibraryA, address = 0x777d395c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLastError, address = 0x777cbf00 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = TlsSetValue, address = 0x777cda88 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = TlsGetValue, address = 0x777cda70 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = TlsFree, address = 0x777d13b8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = TlsAlloc, address = 0x777d35a1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LocalFree, address = 0x777cca64 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LocalAlloc, address = 0x777d3363 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FreeLibrary, address = 0x777cd9d0 True 1
Fn
MOD LOAD module_name = user32.dll, base_address = 0x76270000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetClassLongW, address = 0x7627658b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetClassLongW, address = 0x76283860 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetWindowLongW, address = 0x76284449 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetWindowLongW, address = 0x762861b8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CreateWindowExW, address = 0x7627ec7c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = keybd_event, address = 0x762cec3b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = WindowFromPoint, address = 0x762a6be9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = WaitMessage, address = 0x762866bd True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = WaitForInputIdle, address = 0x762a0397 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = UpdateWindow, address = 0x7627ffa8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = UnregisterClassW, address = 0x7627b9ae True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = UnhookWindowsHookEx, address = 0x7627adf9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = TranslateMessage, address = 0x762864c7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = TranslateMDISysAccel, address = 0x762a1a5a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = TrackPopupMenu, address = 0x76292228 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SystemParametersInfoW, address = 0x7627e09a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SwitchDesktop, address = 0x7627476b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ShowWindow, address = 0x7627f2a9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ShowScrollBar, address = 0x762a3c89 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ShowOwnedPopups, address = 0x762a28ca True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ShowCaret, address = 0x76279334 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetWindowRgn, address = 0x762799ec True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetWindowsHookExW, address = 0x7627e30c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetWindowTextW, address = 0x7628612b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetWindowPos, address = 0x76281bc4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetWindowPlacement, address = 0x76277f78 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetTimer, address = 0x762852ef True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetScrollRange, address = 0x76278ec5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetScrollPos, address = 0x762a04be True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetScrollInfo, address = 0x762848da True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetRect, address = 0x7628498b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetPropW, address = 0x76285dc5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetParent, address = 0x76278314 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetMenuItemInfoW, address = 0x76281799 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetMenu, address = 0x762a6b0e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetKeyboardState, address = 0x762a695a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetForegroundWindow, address = 0x7627b225 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetFocus, address = 0x7627abad True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetCursorPos, address = 0x762bc1b0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetCursor, address = 0x76283075 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetCapture, address = 0x762a6932 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetActiveWindow, address = 0x7628333a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SendMessageTimeoutW, address = 0x7627e459 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SendMessageA, address = 0x7627ad60 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SendMessageW, address = 0x76285539 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ScrollWindow, address = 0x7629fc1d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ScreenToClient, address = 0x7627a506 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = RemovePropW, address = 0x76285fe1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = RemoveMenu, address = 0x762786e8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ReleaseDC, address = 0x76285421 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ReleaseCapture, address = 0x762a69f2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = RegisterWindowMessageW, address = 0x7627df8d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = RegisterClipboardFormatW, address = 0x7627df8d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = RegisterClassW, address = 0x7627ed4a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = RedrawWindow, address = 0x762829bc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = PostQuitMessage, address = 0x7627b308 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = PostMessageW, address = 0x7628447b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = PeekMessageA, address = 0x762819a5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = PeekMessageW, address = 0x7628634a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = OpenDesktopW, address = 0x7627c669 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MsgWaitForMultipleObjectsEx, address = 0x7627e369 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MsgWaitForMultipleObjects, address = 0x762837d8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MoveWindow, address = 0x76278d29 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MessageBoxW, address = 0x762cea5f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MessageBeep, address = 0x762a2939 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MapWindowPoints, address = 0x76285caa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MapVirtualKeyW, address = 0x762a6a7c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = LoadStringW, address = 0x7627dfba True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = LoadKeyboardLayoutW, address = 0x762bc874 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = LoadIconW, address = 0x7627f142 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = LoadCursorW, address = 0x7627ed90 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = LoadBitmapW, address = 0x76276460 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = KillTimer, address = 0x762864f7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsZoomed, address = 0x76284ce9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsWindowVisible, address = 0x76284d69 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsWindowUnicode, address = 0x76282f55 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsWindowEnabled, address = 0x7627a9b9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsWindow, address = 0x762853ba True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsIconic, address = 0x76284c8e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsDialogMessageA, address = 0x76292019 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsDialogMessageW, address = 0x76284104 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsChild, address = 0x76283a83 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = InvalidateRect, address = 0x7628566d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = InsertMenuItemW, address = 0x7627aac5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = InsertMenuW, address = 0x7627869a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = HideCaret, address = 0x76279348 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetWindowThreadProcessId, address = 0x7627ee32 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetWindowTextW, address = 0x7627b8c5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetWindowRect, address = 0x7628558c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetWindowPlacement, address = 0x762a69de True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetWindowDC, address = 0x76284ab7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetTopWindow, address = 0x762a24d9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetSystemMetrics, address = 0x762867cf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetSystemMenu, address = 0x7627fd8b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetSysColorBrush, address = 0x7627f1ed True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetSysColor, address = 0x7628db7a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetSubMenu, address = 0x76279c19 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetScrollRange, address = 0x762a045a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetScrollPos, address = 0x762a0e43 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetScrollInfo, address = 0x76282da3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetPropW, address = 0x76285bbe True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetParent, address = 0x76286029 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetWindow, address = 0x76282780 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMessageTime, address = 0x762a4231 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMessagePos, address = 0x762a6703 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMessageExtraInfo, address = 0x7627b705 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMenuStringW, address = 0x762a6528 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMenuState, address = 0x762a67d2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMenuItemInfoW, address = 0x7627aefa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMenuItemID, address = 0x76279cd4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMenuItemCount, address = 0x7627ae39 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMenu, address = 0x762a6b68 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetLastActivePopup, address = 0x762a6894 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetKeyboardState, address = 0x762a6946 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetKeyboardLayoutNameW, address = 0x762bfa13 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetKeyboardLayoutList, address = 0x7627935c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetKeyboardLayout, address = 0x76283800 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetKeyState, address = 0x76282b4d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetKeyNameTextW, address = 0x762bfa03 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetIconInfo, address = 0x76282989 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetGUIThreadInfo, address = 0x7628237e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetForegroundWindow, address = 0x7628335d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetFocus, address = 0x76283a34 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetDlgCtrlID, address = 0x7627b4e8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetDesktopWindow, address = 0x762801a9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetDCEx, address = 0x76282d57 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetDC, address = 0x7628544c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetCursorPos, address = 0x7627a4b3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetCursor, address = 0x762a6408 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetClipboardData, address = 0x76292ba7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetClientRect, address = 0x762854dd True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetClassNameW, address = 0x76282a29 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetClassInfoExW, address = 0x7628095e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetClassInfoW, address = 0x76280ac2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetCapture, address = 0x76279dc7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetActiveWindow, address = 0x762a3b33 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = FrameRect, address = 0x762a0eb0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = FindWindowExW, address = 0x762a712b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = FindWindowW, address = 0x7627ae0d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = FillRect, address = 0x76285d56 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EnumWindows, address = 0x7628375b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EnumThreadWindows, address = 0x7627b712 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EnumChildWindows, address = 0x76282948 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EndPaint, address = 0x76285d42 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EndMenu, address = 0x76278302 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EnableWindow, address = 0x76278d02 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EnableScrollBar, address = 0x762a19ce True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EnableMenuItem, address = 0x762a43bc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DrawTextExW, address = 0x76285894 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DrawTextW, address = 0x76285b6a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DrawMenuBar, address = 0x762a15ae True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DrawIconEx, address = 0x76282c32 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DrawIcon, address = 0x76276427 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DrawFrameControl, address = 0x7629b4f9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DrawFocusRect, address = 0x762a3091 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DrawEdge, address = 0x7628311a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DispatchMessageA, address = 0x76282e32 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DispatchMessageW, address = 0x7628cc61 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DestroyWindow, address = 0x7627b2f4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DestroyMenu, address = 0x762787f7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DestroyIcon, address = 0x7627a77f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DestroyCursor, address = 0x7627a77f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DeleteMenu, address = 0x762783c2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DefWindowProcW, address = 0x7628507d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DefMDIChildProcW, address = 0x762a150a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = DefFrameProcW, address = 0x762a152b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CreatePopupMenu, address = 0x7627867c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CreateMenu, address = 0x762a6aed True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CreateIcon, address = 0x76297510 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CreateDesktopW, address = 0x762740cf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CopyImage, address = 0x762787a6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CloseDesktop, address = 0x7627c4ce True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ClientToScreen, address = 0x76281316 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CheckMenuItem, address = 0x7629ee7c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CharUpperBuffW, address = 0x7628ebd5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CharUpperW, address = 0x7628e981 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CharNextW, address = 0x76280be6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CharLowerBuffW, address = 0x76283afe True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CharLowerW, address = 0x7627ba8a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CallWindowProcW, address = 0x76281b3c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = CallNextHookEx, address = 0x7627abe1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = BeginPaint, address = 0x76285d14 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = AdjustWindowRectEx, address = 0x762848ba True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = ActivateKeyboardLayout, address = 0x76278203 True 1
Fn
MOD LOAD module_name = gdi32.dll, base_address = 0x76010000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = UnrealizeObject, address = 0x7601fb63 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = StretchBlt, address = 0x7601f467 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetWindowOrgEx, address = 0x76018546 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetWinMetaFileBits, address = 0x7604d957 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetViewportOrgEx, address = 0x7601834f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetTextColor, address = 0x76016906 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetStretchBltMode, address = 0x76017705 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetROP2, address = 0x7601f9e0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetPixel, address = 0x760314f3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetMapMode, address = 0x7601efbf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetEnhMetaFileBits, address = 0x7602b380 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetDIBits, address = 0x7601a995 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetDIBColorTable, address = 0x76031492 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetBrushOrgEx, address = 0x7601c4c5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetBkMode, address = 0x760169b1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SetBkColor, address = 0x76016a3c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SelectPalette, address = 0x7601a1f6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SelectObject, address = 0x76016640 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = SaveDC, address = 0x7601a74b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = RoundRect, address = 0x7603016d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = RestoreDC, address = 0x7601a67b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = Rectangle, address = 0x7601f1ff True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = RectVisible, address = 0x76018f13 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = RealizePalette, address = 0x7601ef91 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = Polyline, address = 0x760205cf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = Polygon, address = 0x7601fb87 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = PolyBezierTo, address = 0x76046c25 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = PolyBezier, address = 0x76046b03 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = PlayEnhMetaFile, address = 0x7602990d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = Pie, address = 0x7604569f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = PatBlt, address = 0x760162af True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = MoveToEx, address = 0x76018c21 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = MaskBlt, address = 0x7601c7ad True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = LineTo, address = 0x7601f59b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = LPtoDP, address = 0x76018484 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = IntersectClipRect, address = 0x76017dfe True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetWindowOrgEx, address = 0x7601d1bf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetWinMetaFileBits, address = 0x7604d7cb True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetTextMetricsW, address = 0x76017b8f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetTextExtentPointW, address = 0x7601b358 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetTextExtentPoint32W, address = 0x7601b4b5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetSystemPaletteEntries, address = 0x7601c2e1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetStockObject, address = 0x76015ddf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetRgnBox, address = 0x7601621f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetPixel, address = 0x7601c3d5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetPaletteEntries, address = 0x7601c2aa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetObjectW, address = 0x76017568 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetEnhMetaFilePaletteEntries, address = 0x7604d1ac True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetEnhMetaFileHeader, address = 0x7602cd3a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetEnhMetaFileDescriptionW, address = 0x7604dc6b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetEnhMetaFileBits, address = 0x7602cdc8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetDeviceCaps, address = 0x76016f7f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetDIBits, address = 0x7601a23b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetDIBColorTable, address = 0x7601a149 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetCurrentPositionEx, address = 0x76018d78 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetClipBox, address = 0x76018525 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetBrushOrgEx, address = 0x7601c943 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GetBitmapBits, address = 0x7601c1ba True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = GdiFlush, address = 0x76015fe4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = FrameRgn, address = 0x76045ae2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = ExtTextOutW, address = 0x76018192 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = ExtFloodFill, address = 0x7602fd94 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = ExcludeClipRect, address = 0x76019218 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = EnumFontFamiliesExW, address = 0x7601ce94 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = Ellipse, address = 0x760455e3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = DeleteObject, address = 0x76015f14 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = DeleteEnhMetaFile, address = 0x7602bda2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = DeleteDC, address = 0x76016eaa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateSolidBrush, address = 0x76016b49 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateRectRgn, address = 0x7601633b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreatePenIndirect, address = 0x7602744d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreatePalette, address = 0x7601b1b0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateHalftonePalette, address = 0x7601c2cd True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateFontIndirectW, address = 0x7601abfc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateEnhMetaFileW, address = 0x7602cc1f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateDIBitmap, address = 0x7601a379 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateDIBSection, address = 0x76018850 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateCompatibleDC, address = 0x76016888 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateCompatibleBitmap, address = 0x760173ad True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateBrushIndirect, address = 0x7601993c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CreateBitmap, address = 0x76016b79 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CopyEnhMetaFileW, address = 0x7604d651 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CombineRgn, address = 0x7601651e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = CloseEnhMetaFile, address = 0x7602c3fe True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = Chord, address = 0x760454fa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = BitBlt, address = 0x760172c0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = ArcTo, address = 0x76045436 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = Arc, address = 0x7604534e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\gdi32.dll, function = AngleArc, address = 0x76045299 True 1
Fn
MOD LOAD module_name = version.dll, base_address = 0x75200000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\version.dll, function = VerQueryValueW, address = 0x75201b51 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\version.dll, function = GetFileVersionInfoSizeW, address = 0x752019d9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\version.dll, function = GetFileVersionInfoW, address = 0x752019f4 True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WriteFile, address = 0x777d1400 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WinExec, address = 0x7780e5fd True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WideCharToMultiByte, address = 0x777d450e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WaitForSingleObject, address = 0x777cba90 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WaitForMultipleObjectsEx, address = 0x777cbc00 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualQueryEx, address = 0x777b4e42 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualQuery, address = 0x777d76d6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualProtect, address = 0x777c2341 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualFree, address = 0x777d1da4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = VirtualAlloc, address = 0x777d2fb6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SwitchToThread, address = 0x777beb24 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SuspendThread, address = 0x777e0ca9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Sleep, address = 0x777cba46 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SizeofResource, address = 0x777c3e7f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetThreadPriority, address = 0x777c4815 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetThreadLocale, address = 0x777e88e6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetLastError, address = 0x777cbb08 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetFilePointer, address = 0x777cdb36 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetEvent, address = 0x777cbccc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetErrorMode, address = 0x777d4a51 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetEndOfFile, address = 0x777c2319 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = ResumeThread, address = 0x777c0f1c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = ResetEvent, address = 0x777cbcb4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = RemoveDirectoryW, address = 0x777b586a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = ReadFile, address = 0x777c96fb True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = RaiseException, address = 0x777beb60 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address = 0x777c3ea8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = OpenProcess, address = 0x777c59d7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = MulDiv, address = 0x777cb7a0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LockResource, address = 0x777bfd29 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LocalFree, address = 0x777cca64 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LoadResource, address = 0x777c984d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LoadLibraryW, address = 0x777d3c01 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = LeaveCriticalSection, address = 0x77ba7760 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = IsValidLocale, address = 0x777c3de4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = InitializeCriticalSection, address = 0x77bba149 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = HeapFree, address = 0x777cbbd0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = HeapDestroy, address = 0x777c2301 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = HeapCreate, address = 0x777d3ea2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = HeapAlloc, address = 0x77bb2dd6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GlobalUnlock, address = 0x777c9d50 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GlobalSize, address = 0x777beb78 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GlobalLock, address = 0x777c9e05 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GlobalFree, address = 0x777c9cf9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GlobalFindAtomW, address = 0x777c912d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GlobalDeleteAtom, address = 0x777bf16c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GlobalAlloc, address = 0x777c9ce1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GlobalAddAtomW, address = 0x777c70f9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetVolumeInformationW, address = 0x777d7598 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetVersionExW, address = 0x777c3b1a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetVersion, address = 0x777c154e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetUserDefaultLCID, address = 0x777d6584 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetTimeZoneInformation, address = 0x777b8a3b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetTickCount, address = 0x777cba60 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetThreadPriority, address = 0x777c9147 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetThreadLocale, address = 0x777c153c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetTempPathW, address = 0x777b8b33 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetStdHandle, address = 0x777d1e46 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetProcAddress, address = 0x777d33d3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetModuleHandleW, address = 0x777d374d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetModuleFileNameW, address = 0x777d3c26 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLocaleInfoW, address = 0x777d6596 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLocalTime, address = 0x777ca90e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLastError, address = 0x777cbf00 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetFullPathNameW, address = 0x777d4543 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetFileSize, address = 0x777c0273 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetFileAttributesW, address = 0x777d64ff True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetExitCodeThread, address = 0x777b6ddd True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetEnvironmentVariableW, address = 0x777d65c4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetDiskFreeSpaceW, address = 0x777b3530 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetDateFormatW, address = 0x777cafab True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetCurrentThreadId, address = 0x777cbb80 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetCurrentThread, address = 0x777d3351 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetCurrentProcessId, address = 0x777ccac4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetCurrentProcess, address = 0x777ccdcf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetComputerNameW, address = 0x777c03ff True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetCPInfoExW, address = 0x777b8b1b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetCPInfo, address = 0x777d1e2e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetACP, address = 0x777d39aa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FreeResource, address = 0x777bf1bd True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = InterlockedExchange, address = 0x777cbf0a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = InterlockedCompareExchange, address = 0x777cbb92 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FreeLibrary, address = 0x777cd9d0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FormatMessageW, address = 0x777c54a3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FindResourceW, address = 0x777c3e61 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FindNextFileW, address = 0x777c963a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FindFirstFileW, address = 0x777d53b2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FindClose, address = 0x777d0e62 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FileTimeToLocalFileTime, address = 0x777d2004 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = FileTimeToDosDateTime, address = 0x777c2ce1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = EnumSystemLocalesW, address = 0x7780f3df True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = EnumCalendarInfoW, address = 0x7780f38f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = EnterCriticalSection, address = 0x77ba77a0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = DeleteFileW, address = 0x777c0f62 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = DeleteCriticalSection, address = 0x77bb9ac5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateThread, address = 0x777d375d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateProcessW, address = 0x7778204d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateFileW, address = 0x777ccc56 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateEventW, address = 0x777d3386 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CreateDirectoryW, address = 0x777c3925 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CompareStringW, address = 0x777c9bee True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = CloseHandle, address = 0x777cca7c True 1
Fn
MOD LOAD module_name = advapi32.dll, base_address = 0x77130000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegSetValueExW, address = 0x771414d6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegQueryValueExW, address = 0x771446ad True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegQueryInfoKeyW, address = 0x771446e7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegOpenKeyExW, address = 0x7714468d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegFlushKey, address = 0x7715773f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegEnumKeyExW, address = 0x771446c8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegCreateKeyExW, address = 0x771440fe True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = RegCloseKey, address = 0x7714469d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\advapi32.dll, function = GetUserNameW, address = 0x7714157a True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = Sleep, address = 0x777cba46 True 1
Fn
MOD LOAD module_name = oleaut32.dll, base_address = 0x77a00000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = SafeArrayPtrOfIndex, address = 0x77a1e1ce True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = SafeArrayGetUBound, address = 0x77a1e127 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = SafeArrayGetLBound, address = 0x77a1e173 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = SafeArrayCreate, address = 0x77a1e263 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VariantChangeType, address = 0x77a05dee True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VariantCopyInd, address = 0x77a1e86c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VariantCopy, address = 0x77a048f1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VariantClear, address = 0x77a03eae True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VariantInit, address = 0x77a03ed5 True 1
Fn
MOD LOAD module_name = oleaut32.dll, base_address = 0x77a00000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = GetErrorInfo, address = 0x77a03f21 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = GetActiveObject, address = 0x77a48f58 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = SysFreeString, address = 0x77a03e59 True 1
Fn
MOD LOAD module_name = ole32.dll, base_address = 0x77620000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CreateStreamOnHGlobal, address = 0x7764363b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = IsAccelerator, address = 0x776e043e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = OleDraw, address = 0x776a0286 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = OleSetMenuDescriptor, address = 0x7767dc53 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = OleUninitialize, address = 0x7763eba1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = OleInitialize, address = 0x7763efd7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoTaskMemFree, address = 0x77676f41 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoTaskMemAlloc, address = 0x7766ea4c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = ProgIDFromCLSID, address = 0x776aef82 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = StringFromCLSID, address = 0x7763eb17 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoCreateInstance, address = 0x77669d0b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoGetClassObject, address = 0x776554ad True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoUninitialize, address = 0x776686d3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoInitialize, address = 0x7763b636 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = IsEqualGUID, address = 0x776e041c True 1
Fn
MOD LOAD module_name = comctl32.dll, base_address = 0x74c90000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = InitializeFlatSB, address = 0x74d6f803 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_SetScrollProp, address = 0x74d107d0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_SetScrollPos, address = 0x74d10894 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_SetScrollInfo, address = 0x74d108c7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_GetScrollPos, address = 0x74d6f80e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_GetScrollInfo, address = 0x74d108b6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = _TrackMouseEvent, address = 0x74d122d1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_SetIconSize, address = 0x74d7b44e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_GetIconSize, address = 0x74ca50df True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_Write, address = 0x74cd8b97 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_Read, address = 0x74c93eae True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_GetDragImage, address = 0x74d7afbb True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_DragShowNolock, address = 0x74d7b161 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_DragMove, address = 0x74d7b0f0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_DragLeave, address = 0x74d7b12a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_DragEnter, address = 0x74d7b0b3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_EndDrag, address = 0x74d7a177 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_BeginDrag, address = 0x74d7b021 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_GetIcon, address = 0x74cbaf2e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_Remove, address = 0x74cbe333 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_DrawEx, address = 0x74ca10fd True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_Draw, address = 0x74d2c687 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_GetBkColor, address = 0x74cae8d2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_SetBkColor, address = 0x74d10183 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_Add, address = 0x74ce8fa1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_SetImageCount, address = 0x74ce5249 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_GetImageCount, address = 0x74c9a8b9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_Destroy, address = 0x74ca6471 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = ImageList_Create, address = 0x74ca3c75 True 1
Fn
MOD LOAD module_name = user32.dll, base_address = 0x76270000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = EnumDisplayMonitors, address = 0x762834a3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetMonitorInfoW, address = 0x762833e7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MonitorFromPoint, address = 0x762794c9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = MonitorFromWindow, address = 0x76283622 True 1
Fn
MOD LOAD module_name = msvcrt.dll, base_address = 0x761c0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\msvcrt.dll, function = memset, address = 0x761c9790 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\msvcrt.dll, function = memcpy, address = 0x761c9910 True 1
Fn
MOD LOAD module_name = shell32.dll, base_address = 0x764e0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\shell32.dll, function = ShellExecuteW, address = 0x764f3c71 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\shell32.dll, function = Shell_NotifyIconW, address = 0x765001c1 True 1
Fn
MOD LOAD module_name = wininet.dll, base_address = 0x771d0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\wininet.dll, function = FindNextUrlCacheEntryW, address = 0x7720989c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\wininet.dll, function = FindFirstUrlCacheEntryW, address = 0x7720978a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\wininet.dll, function = FindCloseUrlCache, address = 0x77218409 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\wininet.dll, function = DeleteUrlCacheEntryW, address = 0x77229573 True 1
Fn
MOD LOAD module_name = user32.dll, base_address = 0x76270000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GetRawInputData, address = 0x762d4c21 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = RegisterRawInputDevices, address = 0x76275b52 True 1
Fn
MOD LOAD module_name = oleacc.dll, base_address = 0x732a0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleacc.dll, function = AccessibleObjectFromWindow, address = 0x732a2480 True 1
Fn
MOD LOAD module_name = OLEACC.DLL, base_address = 0x732a0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleacc.dll, function = AccessibleChildren, address = 0x732a5d25 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetThreadPreferredUILanguages, address = 0x777c22d7 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SetThreadPreferredUILanguages, address = 0x777be627 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetThreadUILanguage, address = 0x777bae42 True 1
Fn
SYS GET_INFO type = Hardware Information True 1
Fn
MOD GET_FILENAME file_name = False 1
Fn
MOD GET_FILENAME file_name = C:\Windows\Explorer.EXE True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetNativeSystemInfo, address = 0x777bbe77 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetDiskFreeSpaceExW, address = 0x777bde40 True 1
Fn
MOD GET_FILENAME file_name = C:\Windows\Explorer.EXE True 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Embarcadero\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\Embarcadero\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\CodeGear\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\Software\CodeGear\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Borland\Locales False 1
Fn
REG OPEN_KEY reg_name = HKEY_CURRENT_USER\Software\Borland\Delphi\Locales False 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\oleaut32.dll, base_address = 0x77a00000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VariantChangeTypeEx, address = 0x77a04c28 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarNeg, address = 0x77a7c802 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarNot, address = 0x77a7ec66 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarAdd, address = 0x77a25934 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarSub, address = 0x77a7d332 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarMul, address = 0x77a7dbd4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarDiv, address = 0x77a7e405 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarIdiv, address = 0x77a7f00a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarMod, address = 0x77a7f15e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarAnd, address = 0x77a25a98 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarOr, address = 0x77a7ecfa True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarXor, address = 0x77a7ee2e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarCmp, address = 0x77a1b0dc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarI4FromStr, address = 0x77a16fab True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarR4FromStr, address = 0x77a201a0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarR8FromStr, address = 0x77a1699e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarDateFromStr, address = 0x77a26ba7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarCyFromStr, address = 0x77a46c12 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBoolFromStr, address = 0x77a1dbd1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromCy, address = 0x77a27fdc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromDate, address = 0x77a17a2a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\oleaut32.dll, function = VarBstrFromBool, address = 0x77a20355 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = InitializeConditionVariable, address = 0x77bb9981 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WakeConditionVariable, address = 0x77c05a7b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = WakeAllConditionVariable, address = 0x77b845a5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = SleepConditionVariableCS, address = 0x777b18be True 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes, value_name = MS Shell Dlg 2, data_ident_out = 0 True 1
Fn
REG READ_VALUE reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes, value_name = MS Shell Dlg 2, data_ident_out = Tahoma True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLogicalProcessorInformation, address = 0x777b2004 True 1
Fn
MOD LOAD module_name = kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetLogicalProcessorInformation, address = 0x777b2004 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\ole32.dll, base_address = 0x77620000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoCreateInstanceEx, address = 0x77669d4e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoInitializeEx, address = 0x776609ad True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoAddRefServerProcess, address = 0x77683cf3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoReleaseServerProcess, address = 0x77684314 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoResumeClassObjects, address = 0x7762ea02 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ole32.dll, function = CoSuspendClassObjects, address = 0x7768bb02 True 1
Fn
MOD LOAD module_name = imm32.dll, base_address = 0x75fb0000 True 1
Fn
KEYBOARD GET_INFO type = KB_LOCALE_ID, os_tid = 0, result_out = 67699721 True 1
Fn
MOD GET_FILENAME file_name = C:\Windows\Explorer.EXE True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
KEYBOARD GET_INFO type = KB_LOCALE_ID True 1
Fn
MOD LOAD module_name = imm32.dll, base_address = 0x75fb0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\imm32.dll, function = ImmIsIME, address = 0x75fb2ceb True 1
Fn
REG OPEN_KEY reg_name = HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04090409 False 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\user32.dll, base_address = 0x76270000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = AnimateWindow, address = 0x762a0620 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, base_address = 0x74c90000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = InitializeFlatSB, address = 0x74d6f803 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = UninitializeFlatSB, address = 0x74c9d1ea True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_GetScrollProp, address = 0x74d6f81f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_SetScrollProp, address = 0x74d107d0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_EnableScrollBar, address = 0x74d6f84b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_ShowScrollBar, address = 0x74d6f83a True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_GetScrollRange, address = 0x74d6f829 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_GetScrollInfo, address = 0x74d108b6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_GetScrollPos, address = 0x74d6f80e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_SetScrollPos, address = 0x74d10894 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_SetScrollInfo, address = 0x74d108c7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = FlatSB_SetScrollRange, address = 0x74d108a5 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\user32.dll, base_address = 0x76270000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = SetLayeredWindowAttributes, address = 0x7627a6dc True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\user32.dll, base_address = 0x76270000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = IsHungAppWindow, address = 0x762a7195 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = HungWindowFromGhostWindow, address = 0x762961f5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\user32.dll, function = GhostWindowFromHungWindow, address = 0x7627a561 True 1
Fn
MOD LOAD module_name = olepro32.dll, base_address = 0x73280000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ncsi.dll, function = OleCreatePropertyFrame, address = 0x732820ea True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ncsi.dll, function = OleCreateFontIndirect, address = 0x732820b7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ncsi.dll, function = OleCreatePictureIndirect, address = 0x732820c8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ncsi.dll, function = OleLoadPicture, address = 0x732820d9 True 1
Fn
MOD GET_HANDLE module_name = c:\windows\system32\kernel32.dll, base_address = 0x77780000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\kernel32.dll, function = GetFileSizeEx, address = 0x777c59ef True 1
Fn
MOD LOAD module_name = security.dll, base_address = 0x73270000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ncsi.dll, function = InitSecurityInterfaceW, address = 0x75be5b53 True 1
Fn
WND CREATE window_name = Explorer, class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0, window_parameter = 0 True 1
Fn
MOD LOAD module_name = wtsapi32.dll, base_address = 0x74690000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\wtsapi32.dll, function = WTSRegisterSessionNotification, address = 0x74691cbc True 1
Fn
MOD LOAD module_name = uxtheme.dll, base_address = 0x74b10000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = BufferedPaintInit, address = 0x74b1940e True 1
Fn
WND SET_ATTRIBUTE window_name = Explorer, class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0 True 1
Fn
MOD LOAD module_name = uxtheme.dll, base_address = 0x74b10000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = OpenThemeData, address = 0x74b173d2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = CloseThemeData, address = 0x74b16a18 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = DrawThemeBackground, address = 0x74b13982 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = DrawThemeText, address = 0x74b14ea1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeBackgroundContentRect, address = 0x74b1cd2e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeBackgroundExtent, address = 0x74b1f8bf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemePartSize, address = 0x74b1cdb1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeTextExtent, address = 0x74b12d57 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeTextMetrics, address = 0x74b1f992 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeBackgroundRegion, address = 0x74b2165d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = HitTestThemeBackground, address = 0x74b23ce3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = DrawThemeEdge, address = 0x74b33b52 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = DrawThemeIcon, address = 0x74b435e7 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = IsThemePartDefined, address = 0x74b185b4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = IsThemeBackgroundPartiallyTransparent, address = 0x74b160ab True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeColor, address = 0x74b1616c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeMetric, address = 0x74b206e2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeString, address = 0x74b422e4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeBool, address = 0x74b17c1f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeInt, address = 0x74b1616c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeEnumValue, address = 0x74b1616c True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemePosition, address = 0x74b42350 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeFont, address = 0x74b1ff21 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeRect, address = 0x74b23611 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeMargins, address = 0x74b186e9 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeIntList, address = 0x74b423b1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemePropertyOrigin, address = 0x74b33fbb True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = SetWindowTheme, address = 0x74b20134 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeFilename, address = 0x74b42412 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeSysColor, address = 0x74b33274 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeSysColorBrush, address = 0x74b4301e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeSysBool, address = 0x74b43172 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeSysSize, address = 0x74b4320b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeSysFont, address = 0x74b429c4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeSysString, address = 0x74b42b3f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeSysInt, address = 0x74b42bd3 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = IsThemeActive, address = 0x74b1f785 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = IsAppThemed, address = 0x74b1f869 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetWindowTheme, address = 0x74b1df46 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = EnableThemeDialogTexture, address = 0x74b1fcaf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = IsThemeDialogTextureEnabled, address = 0x74b4312b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeAppProperties, address = 0x74b20fb1 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = SetThemeAppProperties, address = 0x74b43296 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetCurrentThemeName, address = 0x74b205dd True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = GetThemeDocumentationProperty, address = 0x74b42932 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = DrawThemeParentBackground, address = 0x74b153e5 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = EnableTheming, address = 0x74b42feb True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\uxtheme.dll, function = DrawThemeTextEx, address = 0x74b163e6 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SYS SLEEP duration = 1500 milliseconds (1.500 seconds) True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SYS SLEEP duration = 1000 milliseconds (1.000 seconds) True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SYS SLEEP duration = 60000 milliseconds (60.000 seconds) True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SYS SLEEP duration = 1000 milliseconds (1.000 seconds) True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
WND CREATE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = , class_name = TPUtilWindow, x_coordinate = 0, y_coordinate = 0, width = 0, height = 0 True 1
Fn
SYS SLEEP duration = 60000 milliseconds (60.000 seconds) True 1
Fn
WND SET_ATTRIBUTE window_name = Explorer, class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0 True 1
Fn
WND CREATE window_name = Explorer, window_name = FrmMwM41n, class_name = TFrmMwM41n, x_coordinate = 18446744073709551164, y_coordinate = 18446744073709551164, width = 320, height = 240, class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0, window_parameter = 0 True 1
Fn
WND SET_ATTRIBUTE window_name = FrmMwM41n, class_name = TFrmMwM41n, x_coordinate = 18446744073709551164, y_coordinate = 18446744073709551164, width = 320, height = 240 True 1
Fn
WND SET_ATTRIBUTE window_name = FrmMwM41n, class_name = TFrmMwM41n, x_coordinate = 18446744073709551164, y_coordinate = 18446744073709551164, width = 320, height = 240 True 1
Fn
WND FIND window_name = k8w0 False 1
Fn
FILE DELETE file_name = c:\users\public\n3eg\n3e.vbs True 1
Fn
FILE DELETE file_name = c:\users\public\n3eg\n3e.vbs False 1
Fn
FILE CREATE file_name = c:\users\public\n3eg\wvs, desired_access = GENERIC_WRITE, GENERIC_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
FILE WRITE file_name = c:\users\public\n3eg\wvs, size = 4 True 1
Fn
Data
WND SET_ATTRIBUTE window_name = Explorer, class_name = TApplication, x_coordinate = 720, y_coordinate = 450, width = 0, height = 0 True 1
Fn
SYS GET_CURSOR x_out = 1428, y_out = 797 True 17
Fn
SYS GET_CURSOR x_out = 814, y_out = 22 True 4
Fn
SYS SLEEP duration = 600000 milliseconds (600.000 seconds) True 1
Fn
MOD LOAD module_name = WS2_32.DLL, base_address = 0x75fd0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = WSAStartup, address = 0x75fd3ab2 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = GetAddrInfoW, address = 0x75fd4889 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = GetNameInfoW, address = 0x75fd66af True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = FreeAddrInfoW, address = 0x75fd4b1b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = InetPtonW, address = 0x75fe39dc True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = InetNtopW, address = 0x75fe3abf True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = GetAddrInfoExW, address = 0x75fdd1ea True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = SetAddrInfoExW, address = 0x75fdf4f6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = FreeAddrInfoExW, address = 0x75fde14d True 1
Fn
MOD LOAD module_name = Fwpuclnt.dll, base_address = 0x72470000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\fwpuclnt.dll, function = WSASetSocketPeerTargetName, address = 0x7248bb1e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\fwpuclnt.dll, function = WSADeleteSocketPeerTargetName, address = 0x7248bb4e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\fwpuclnt.dll, function = WSAImpersonateSocketPeer, address = 0x7248bb7e True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\fwpuclnt.dll, function = WSAQuerySocketSecurity, address = 0x7248baed True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\fwpuclnt.dll, function = WSARevertImpersonation, address = 0x7248bcfd True 1
Fn
MOD LOAD module_name = IdnDL.dll, base_address = 0x6ee90000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\idndl.dll, function = DownlevelGetLocaleScripts, address = 0x6ee92a5b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\idndl.dll, function = DownlevelGetStringScripts, address = 0x6ee92b2f True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\idndl.dll, function = DownlevelVerifyScripts, address = 0x6ee92dad True 1
Fn
MOD LOAD module_name = Normaliz.dll, base_address = 0x77cd0000 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\normaliz.dll, function = IdnToUnicode, address = 0x7781f707 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\normaliz.dll, function = IdnToNameprepUnicode, address = 0x7781f6b4 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\normaliz.dll, function = IdnToAscii, address = 0x777b8bb8 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\normaliz.dll, function = IsNormalizedString, address = 0x7781f662 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\normaliz.dll, function = NormalizeString, address = 0x7781f5ea True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = socket, address = 0x75fd3eb8 True 1
Fn
SCK CREATE address_family = AF_INET, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = getsockopt, address = 0x75fd737d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = setsockopt, address = 0x75fd41b6 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = htons, address = 0x75fd2d8b True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = bind, address = 0x75fd4582 True 1
Fn
SCK BIND local_address = 0.0.0.0, local_port = 0 True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = getsockname, address = 0x75fd30af True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = ntohs, address = 0x75fd2d8b True 1
Fn
DNS RESOLVE_NAME host = carvas32ltda.com True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = connect, address = 0x75fd6bdd True 1
Fn
SCK CONNECT remote_address = 187.191.100.112, remote_port = 80 False 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = WSAGetLastError, address = 0x75fd37ad True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = shutdown, address = 0x75fd449d True 1
Fn
MOD GET_PROC_ADDRESS module_name = c:\windows\system32\ws2_32.dll, function = closesocket, address = 0x75fd3918 True 1
Fn
SCK CREATE address_family = AF_INET, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
SCK BIND local_address = 0.0.0.0, local_port = 0 True 1
Fn
DNS RESOLVE_NAME host = carva32ssa.com True 1
Fn
SCK CONNECT remote_address = 187.191.100.112, remote_port = 80 False 1
Fn
SCK CREATE address_family = AF_INET, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
SCK BIND local_address = 0.0.0.0, local_port = 0 True 1
Fn
DNS RESOLVE_NAME host = bandeivacomercial.com True 1
Fn
SCK CONNECT remote_address = 187.191.100.112, remote_port = 80 False 1
Fn
SCK CREATE address_family = AF_INET, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
SCK BIND local_address = 0.0.0.0, local_port = 0 True 1
Fn
DNS RESOLVE_NAME host = bandeivacomercio.com True 1
Fn
SCK CONNECT remote_address = 187.191.100.112, remote_port = 80 False 1
Fn
SCK CREATE address_family = AF_INET, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
SCK BIND local_address = 0.0.0.0, local_port = 0 True 1
Fn
DNS RESOLVE_NAME host = carvas32ltda.com True 1
Fn
SCK CONNECT remote_address = 187.191.100.112, remote_port = 80 False 1
Fn
SCK CREATE address_family = AF_INET, type = SOCK_STREAM, protocol = IPPROTO_IP True 1
Fn
SCK BIND local_address = 0.0.0.0, local_port = 0 True 1
Fn
DNS RESOLVE_NAME host = carva32ssa.com True 1
Fn
SCK CONNECT remote_address = 187.191.100.112, remote_port = 80 False 1
Fn
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefox with deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image