Source: PO# 81136575.exe, 00000000.00000002.1263148906.00000000703F1000.00000020.00000001.01000000.00000009.sdmp | String found in binary or memory: http://beta.visualstudio.net/net/sdk/feedback.asp |
Source: sages.exe, 00000016.00000002.5956179976.00000000008FA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://go.microsoft.c |
Source: sage.exe, 0000000E.00000002.6029462311.000000000F382000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.0000000006FF2000.00000004.10000000.00040000.00000000.sdmp | String found in binary or memory: http://homebizsuccess.blog/sn35/?VX=2Ljw85fE62irHv4CO6sOxtyqmKbvzO49yiJy4Znj95Je |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/fonts/montserrat-bold/montserrat-bold.eot |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/fonts/montserrat-bold/montserrat-bold.eot?#iefix |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/fonts/montserrat-bold/montserrat-bold.otf |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/fonts/montserrat-bold/montserrat-bold.svg#montserrat-bold |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/fonts/montserrat-bold/montserrat-bold.ttf |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/fonts/montserrat-bold/montserrat-bold.woff |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/fonts/montserrat-bold/montserrat-bold.woff2 |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/fonts/montserrat-regular/montserrat-regular.eot |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/fonts/montserrat-regular/montserrat-regular.eot?#iefix |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/fonts/montserrat-regular/montserrat-regular.otf |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/fonts/montserrat-regular/montserrat-regular.svg#montserrat-regular |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/fonts/montserrat-regular/montserrat-regular.ttf |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/fonts/montserrat-regular/montserrat-regular.woff |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/fonts/montserrat-regular/montserrat-regular.woff2 |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/js/min.js?v2.3 |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/pics/10667/netsol-logos-2020-165-50.jpg |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/pics/28903/search.png) |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/pics/28905/arrrow.png) |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/pics/29590/bg1.png) |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://i2.cdn-image.com/__media__/pics/468/netsol-favicon-2020.jpg |
Source: PO# 81136575.exe, 00000000.00000002.1257906767.0000000005F32000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://purl.oen |
Source: sage.exe, 00000011.00000002.6049294447.00000000058A1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://purl.oen=9 |
Source: sage.exe, 0000000E.00000002.6012035049.00000000058E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://purl.oenS5 |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.Slwmarketing.online |
Source: sage.exe, 0000000E.00000002.6031342259.000000000FCED000.00000040.80000000.00040000.00000000.sdmp | String found in binary or memory: http://www.homebizsuccess.blog |
Source: sage.exe, 0000000E.00000002.6031342259.000000000FCED000.00000040.80000000.00040000.00000000.sdmp | String found in binary or memory: http://www.homebizsuccess.blog/sn35/ |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.slwmarketing.online/Exchange.cfm?fp=j4IJ8dhE9wDFyDIIjviqztKLPQy021ALH0tYM6%2FRantCn63Wcie |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.slwmarketing.online/Internet_Search_Engines.cfm?fp=j4IJ8dhE9wDFyDIIjviqztKLPQy021ALH0tYM6 |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.slwmarketing.online/Marketing_Online_Strategy.cfm?fp=j4IJ8dhE9wDFyDIIjviqztKLPQy021ALH0tY |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.slwmarketing.online/Small_Business_Financing.cfm?fp=j4IJ8dhE9wDFyDIIjviqztKLPQy021ALH0tYM |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.slwmarketing.online/Trade.cfm?fp=j4IJ8dhE9wDFyDIIjviqztKLPQy021ALH0tYM6%2FRantCn63Wciee8E |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.slwmarketing.online/__media__/design/underconstructionnotice.php?d=slwmarketing.online |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5960102666.0000000007E80000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.slwmarketing.online/__media__/js/trademark.php?d=slwmarketing.online&type=ns |
Source: clip.exe, 00000018.00000002.5959043483.0000000005D1A000.00000004.10000000.00040000.00000000.sdmp | String found in binary or memory: https://aa57601869.xn--tnqx81c85gn1o9ud.com/download/57601869/57601869a1.html |
Source: clip.exe, 00000018.00000002.5959043483.0000000005D1A000.00000004.10000000.00040000.00000000.sdmp | String found in binary or memory: https://aa57601869.xn--tnqx81c85gn1o9ud.com/download/57601869/57601869a2.html |
Source: sage.exe, 0000000E.00000002.6029462311.000000000E0AA000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.0000000005D1A000.00000004.10000000.00040000.00000000.sdmp | String found in binary or memory: https://aa57601869.xn--tnqx81c85gn1o9ud.com/download/57601869/57601869a5.html |
Source: sage.exe, 0000000E.00000002.6029462311.000000000E0AA000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.0000000005D1A000.00000004.10000000.00040000.00000000.sdmp | String found in binary or memory: https://aa57601869.xn--tnqx81c85gn1o9ud.com/download/57601869/57601869a6.html |
Source: sage.exe, 0000000E.00000002.6029462311.000000000E0AA000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.0000000005D1A000.00000004.10000000.00040000.00000000.sdmp | String found in binary or memory: https://aa57601869.xn--tnqx81c85gn1o9ud.com/download/57601869/57601869a8.html |
Source: sage.exe, 0000000E.00000002.6029462311.000000000E0AA000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.0000000005D1A000.00000004.10000000.00040000.00000000.sdmp | String found in binary or memory: https://aa57601869.xn--tnqx81c85gn1o9ud.com/download/57601869/57601869a9.html |
Source: clip.exe, 00000018.00000002.5960241652.000000000814F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp | String found in binary or memory: https://cdn.consentmanager.net |
Source: clip.exe, 00000018.00000002.5960241652.000000000814F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: sage.exe, 0000000E.00000002.6029462311.000000000ED3A000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp | String found in binary or memory: https://delivery.consentmanager.net |
Source: clip.exe, 00000018.00000002.5959043483.00000000069AA000.00000004.10000000.00040000.00000000.sdmp | String found in binary or memory: https://dts.gnpge.com |
Source: clip.exe, 00000018.00000003.2916902307.00000000081BA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: clip.exe, 00000018.00000002.5960241652.000000000814F000.00000004.00000020.00020000.00000000.sdmp, clip.exe, 00000018.00000003.2916902307.00000000081BA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: clip.exe, 00000018.00000003.2916902307.00000000081BA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: clip.exe, 00000018.00000002.5960241652.000000000814F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://gemini.google.com/app?q= |
Source: sage.exe, 0000000E.00000002.6029462311.000000000E0AA000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.0000000005D1A000.00000004.10000000.00040000.00000000.sdmp | String found in binary or memory: https://js.users.51.la/21851687.js |
Source: clip.exe, 00000018.00000002.5955950229.00000000030EC000.00000004.00000020.00020000.00000000.sdmp, clip.exe, 00000018.00000003.2908988913.0000000003108000.00000004.00000020.00020000.00000000.sdmp, clip.exe, 00000018.00000002.5955950229.0000000003108000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/ |
Source: clip.exe, 00000018.00000002.5955950229.00000000030EC000.00000004.00000020.00020000.00000000.sdmp, clip.exe, 00000018.00000003.2908988913.0000000003108000.00000004.00000020.00020000.00000000.sdmp, clip.exe, 00000018.00000002.5955950229.0000000003108000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com// |
Source: clip.exe, 00000018.00000002.5955950229.00000000030EC000.00000004.00000020.00020000.00000000.sdmp, clip.exe, 00000018.00000003.2908988913.0000000003108000.00000004.00000020.00020000.00000000.sdmp, clip.exe, 00000018.00000002.5955950229.0000000003108000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/v104 |
Source: clip.exe, 00000018.00000002.5955950229.00000000030CC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://odc.officeapps.live.com/odc/v2.1/hrd?lcid=1033&syslcid=2057&uilcid=1033&app=1&ver=16&build=1 |
Source: clip.exe, 00000018.00000002.5955950229.00000000030A5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://odc.officeapps.live.com/odc/v2.1/hrdlcid=1033&syslcid=2057&uilcid=1033&app=1&ver=16&build=16 |
Source: clip.exe, 00000018.00000003.2907985166.000000000813D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://odc.officeapps.live.com/odc/v2.1/hrdres://C: |
Source: clip.exe, 00000018.00000002.5960241652.000000000814F000.00000004.00000020.00020000.00000000.sdmp, clip.exe, 00000018.00000003.2916902307.00000000081BA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://uk.search.yahoo.com/favicon.icohttps://uk.search.yahoo.com/search |
Source: clip.exe, 00000018.00000003.2916902307.00000000081BA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://uk.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: sage.exe, 0000000E.00000002.6029462311.000000000DD86000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000059F6000.00000004.10000000.00040000.00000000.sdmp | String found in binary or memory: https://whois.gandi.net/en/results?search=akravchenko.dev |
Source: clip.exe, 00000018.00000002.5960241652.000000000814F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: sage.exe, 0000000E.00000002.6029462311.000000000DD86000.00000004.80000000.00040000.00000000.sdmp, clip.exe, 00000018.00000002.5959043483.00000000059F6000.00000004.10000000.00040000.00000000.sdmp | String found in binary or memory: https://www.gandi.net/en/domain |
Source: clip.exe, 00000018.00000003.2916902307.00000000081BA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Code function: 0_2_03137058 | 0_2_03137058 |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Code function: 0_2_03136588 | 0_2_03136588 |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Code function: 0_2_031328B8 | 0_2_031328B8 |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Code function: 0_2_07271408 | 0_2_07271408 |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Code function: 0_2_072E0040 | 0_2_072E0040 |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Code function: 0_2_072E0006 | 0_2_072E0006 |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Code function: 0_2_072EF2B0 | 0_2_072EF2B0 |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Code function: 0_2_072E68F0 | 0_2_072E68F0 |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Code function: 0_2_072EF2C0 | 0_2_072EF2C0 |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Code function: 0_2_077BA780 | 0_2_077BA780 |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Code function: 0_2_077B0040 | 0_2_077B0040 |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Code function: 0_2_077BCA9A | 0_2_077BCA9A |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Code function: 0_2_077BA6BD | 0_2_077BA6BD |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Code function: 0_2_077B001F | 0_2_077B001F |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Code function: 0_2_07271398 | 0_2_07271398 |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Code function: 0_2_072713F8 | 0_2_072713F8 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_02A47058 | 14_2_02A47058 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_02A46588 | 14_2_02A46588 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_02A428B8 | 14_2_02A428B8 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_02A46A70 | 14_2_02A46A70 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06C068F0 | 14_2_06C068F0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06C00040 | 14_2_06C00040 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06C0C530 | 14_2_06C0C530 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06C00007 | 14_2_06C00007 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06C0C522 | 14_2_06C0C522 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F152C8 | 14_2_06F152C8 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F1DA38 | 14_2_06F1DA38 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F123D0 | 14_2_06F123D0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F1BB60 | 14_2_06F1BB60 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F14078 | 14_2_06F14078 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F13468 | 14_2_06F13468 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F10040 | 14_2_06F10040 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F18830 | 14_2_06F18830 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F1E198 | 14_2_06F1E198 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F16168 | 14_2_06F16168 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F14900 | 14_2_06F14900 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F152B8 | 14_2_06F152B8 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F18688 | 14_2_06F18688 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F18678 | 14_2_06F18678 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F17E30 | 14_2_06F17E30 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F17E20 | 14_2_06F17E20 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F193E0 | 14_2_06F193E0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F123C0 | 14_2_06F123C0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F13FBF | 14_2_06F13FBF |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F19372 | 14_2_06F19372 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F1CB78 | 14_2_06F1CB78 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F17E30 | 14_2_06F17E30 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F17B30 | 14_2_06F17B30 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F17B21 | 14_2_06F17B21 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F148F0 | 14_2_06F148F0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F16088 | 14_2_06F16088 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F14870 | 14_2_06F14870 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F17050 | 14_2_06F17050 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F13459 | 14_2_06F13459 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F17040 | 14_2_06F17040 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F18820 | 14_2_06F18820 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F18410 | 14_2_06F18410 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F18400 | 14_2_06F18400 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F181D8 | 14_2_06F181D8 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F181C9 | 14_2_06F181C9 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F1612D | 14_2_06F1612D |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F63660 | 14_2_06F63660 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F61FE0 | 14_2_06F61FE0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F66718 | 14_2_06F66718 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F63968 | 14_2_06F63968 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F63652 | 14_2_06F63652 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F61238 | 14_2_06F61238 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F6122A | 14_2_06F6122A |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F63FF1 | 14_2_06F63FF1 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F61FA1 | 14_2_06F61FA1 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F60040 | 14_2_06F60040 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F61417 | 14_2_06F61417 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F60007 | 14_2_06F60007 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F64000 | 14_2_06F64000 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F619A0 | 14_2_06F619A0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F61990 | 14_2_06F61990 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_06F63958 | 14_2_06F63958 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_070D0040 | 14_2_070D0040 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_070DEB1A | 14_2_070DEB1A |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_070DEB20 | 14_2_070DEB20 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_0FCC8D80 | 14_2_0FCC8D80 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_0FCA8558 | 14_2_0FCA8558 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_0FCA8380 | 14_2_0FCA8380 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_0FCAA300 | 14_2_0FCAA300 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_0FC9EA8C | 14_2_0FC9EA8C |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_0FCB0A10 | 14_2_0FCB0A10 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_0FCAF180 | 14_2_0FCAF180 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_0FCAA0E0 | 14_2_0FCAA0E0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 14_2_0FCB2830 | 14_2_0FCB2830 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_012E7058 | 17_2_012E7058 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_012E6588 | 17_2_012E6588 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_012E28B8 | 17_2_012E28B8 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_012E6A70 | 17_2_012E6A70 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07100040 | 17_2_07100040 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0710EB1A | 17_2_0710EB1A |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0743C530 | 17_2_0743C530 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07430040 | 17_2_07430040 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0743C522 | 17_2_0743C522 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07430006 | 17_2_07430006 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_074368F0 | 17_2_074368F0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_075423C0 | 17_2_075423C0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_075452B8 | 17_2_075452B8 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0754D578 | 17_2_0754D578 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07546168 | 17_2_07546168 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07543459 | 17_2_07543459 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07540040 | 17_2_07540040 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07544870 | 17_2_07544870 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07544078 | 17_2_07544078 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07548820 | 17_2_07548820 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07549372 | 17_2_07549372 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0754CB78 | 17_2_0754CB78 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07547B30 | 17_2_07547B30 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07547B22 | 17_2_07547B22 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07543FBF | 17_2_07543FBF |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07546E78 | 17_2_07546E78 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07547E20 | 17_2_07547E20 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07548686 | 17_2_07548686 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07548688 | 17_2_07548688 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07546910 | 17_2_07546910 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0754612D | 17_2_0754612D |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_075481D8 | 17_2_075481D8 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_075481C9 | 17_2_075481C9 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07547050 | 17_2_07547050 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07547040 | 17_2_07547040 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07548410 | 17_2_07548410 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07548400 | 17_2_07548400 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_075448F0 | 17_2_075448F0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07546088 | 17_2_07546088 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0CDE3958 | 17_2_0CDE3958 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0CDE3660 | 17_2_0CDE3660 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0CDE1FA1 | 17_2_0CDE1FA1 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0CDE6718 | 17_2_0CDE6718 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0CDE0040 | 17_2_0CDE0040 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0CDE1417 | 17_2_0CDE1417 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0CDE0007 | 17_2_0CDE0007 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0CDE11DA | 17_2_0CDE11DA |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0CDE1990 | 17_2_0CDE1990 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0CDE19A0 | 17_2_0CDE19A0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0CDE3652 | 17_2_0CDE3652 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0CDE1238 | 17_2_0CDE1238 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_0CDE3FF1 | 17_2_0CDE3FF1 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Code function: 17_2_07100007 | 17_2_07100007 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_00418203 | 18_2_00418203 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_004010D7 | 18_2_004010D7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_004010E0 | 18_2_004010E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_00403190 | 18_2_00403190 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0040FAB3 | 18_2_0040FAB3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_004163E3 | 18_2_004163E3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0040445F | 18_2_0040445F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0040FCD3 | 18_2_0040FCD3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0040DD53 | 18_2_0040DD53 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_004026D0 | 18_2_004026D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0042E753 | 18_2_0042E753 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0040DF2B | 18_2_0040DF2B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015E010E | 18_2_015E010E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015CE076 | 18_2_015CE076 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015100A0 | 18_2_015100A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152E310 | 18_2_0152E310 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_014E2245 | 18_2_014E2245 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015EA526 | 18_2_015EA526 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520445 | 18_2_01520445 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D6757 | 18_2_015D6757 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01522760 | 18_2_01522760 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152A760 | 18_2_0152A760 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01544670 | 18_2_01544670 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153C600 | 18_2_0153C600 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DA6C0 | 18_2_015DA6C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151C6E0 | 18_2_0151C6E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520680 | 18_2_01520680 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151E9A0 | 18_2_0151E9A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DE9A6 | 18_2_015DE9A6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01506868 | 18_2_01506868 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154E810 | 18_2_0154E810 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0835 | 18_2_015C0835 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015228C0 | 18_2_015228C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01536882 | 18_2_01536882 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520B10 | 18_2_01520B10 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01594BC0 | 18_2_01594BC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DEA5B | 18_2_015DEA5B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DCA13 | 18_2_015DCA13 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520D69 | 18_2_01520D69 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151AD00 | 18_2_0151AD00 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01532DB0 | 18_2_01532DB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015CEC4C | 18_2_015CEC4C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D6C69 | 18_2_015D6C69 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DEC60 | 18_2_015DEC60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01510C12 | 18_2_01510C12 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152AC20 | 18_2_0152AC20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159EC20 | 18_2_0159EC20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01538CDF | 18_2_01538CDF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015EACEB | 18_2_015EACEB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152CF00 | 18_2_0152CF00 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01526FE0 | 18_2_01526FE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DEFBF | 18_2_015DEFBF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01540E50 | 18_2_01540E50 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01562E48 | 18_2_01562E48 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0E6D | 18_2_015C0E6D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01512EE8 | 18_2_01512EE8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D0EAD | 18_2_015D0EAD |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0156717A | 18_2_0156717A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150F113 | 18_2_0150F113 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015BD130 | 18_2_015BD130 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015251C0 | 18_2_015251C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153B1E0 | 18_2_0153B1E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152B0D0 | 18_2_0152B0D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D70F1 | 18_2_015D70F1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0155508C | 18_2_0155508C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DF330 | 18_2_015DF330 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01511380 | 18_2_01511380 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D124C | 18_2_015D124C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150D2EC | 18_2_0150D2EC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DF5C9 | 18_2_015DF5C9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D75C6 | 18_2_015D75C6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B5490 | 18_2_015B5490 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158D480 | 18_2_0158D480 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015CD646 | 18_2_015CD646 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015BD62C | 18_2_015BD62C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DF6F6 | 18_2_015DF6F6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015936EC | 18_2_015936EC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015659C0 | 18_2_015659C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_014E99E8 | 18_2_014E99E8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01529870 | 18_2_01529870 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153B870 | 18_2_0153B870 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01595870 | 18_2_01595870 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DF872 | 18_2_015DF872 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01523800 | 18_2_01523800 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D18DA | 18_2_015D18DA |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D78F3 | 18_2_015D78F3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015998B2 | 18_2_015998B2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0155DB19 | 18_2_0155DB19 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DFB2E | 18_2_015DFB2E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B1B80 | 18_2_015B1B80 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DFA89 | 18_2_015DFA89 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153FAA0 | 18_2_0153FAA0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D7D4C | 18_2_015D7D4C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DFD27 | 18_2_015DFD27 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01529DD0 | 18_2_01529DD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015BFDF4 | 18_2_015BFDF4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01523C60 | 18_2_01523C60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015A7CE8 | 18_2_015A7CE8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153FCE0 | 18_2_0153FCE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B9C98 | 18_2_015B9C98 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159FF40 | 18_2_0159FF40 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DFF63 | 18_2_015DFF63 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D1FC6 | 18_2_015D1FC6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D9ED2 | 18_2_015D9ED2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01521EB2 | 18_2_01521EB2 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DE0445 | 24_2_04DE0445 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04EAA526 | 24_2_04EAA526 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E9A6C0 | 24_2_04E9A6C0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DDC6E0 | 24_2_04DDC6E0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DE0680 | 24_2_04DE0680 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E04670 | 24_2_04E04670 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DFC600 | 24_2_04DFC600 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E96757 | 24_2_04E96757 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DEA760 | 24_2_04DEA760 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DE2760 | 24_2_04DE2760 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DD00A0 | 24_2_04DD00A0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E8E076 | 24_2_04E8E076 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04EA010E | 24_2_04EA010E |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DEE310 | 24_2_04DEE310 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DF8CDF | 24_2_04DF8CDF |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04EAACEB | 24_2_04EAACEB |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E96C69 | 24_2_04E96C69 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E9EC60 | 24_2_04E9EC60 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E8EC4C | 24_2_04E8EC4C |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E5EC20 | 24_2_04E5EC20 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DD0C12 | 24_2_04DD0C12 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DEAC20 | 24_2_04DEAC20 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DF2DB0 | 24_2_04DF2DB0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DE0D69 | 24_2_04DE0D69 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DDAD00 | 24_2_04DDAD00 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DD2EE8 | 24_2_04DD2EE8 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E90EAD | 24_2_04E90EAD |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E80E6D | 24_2_04E80E6D |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E22E48 | 24_2_04E22E48 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E00E50 | 24_2_04E00E50 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DE6FE0 | 24_2_04DE6FE0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E9EFBF | 24_2_04E9EFBF |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DECF00 | 24_2_04DECF00 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DE28C0 | 24_2_04DE28C0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DF6882 | 24_2_04DF6882 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E7C89F | 24_2_04E7C89F |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DC6868 | 24_2_04DC6868 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E80835 | 24_2_04E80835 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E0E810 | 24_2_04E0E810 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E9E9A6 | 24_2_04E9E9A6 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DDE9A0 | 24_2_04DDE9A0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E9EA5B | 24_2_04E9EA5B |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E9CA13 | 24_2_04E9CA13 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E54BC0 | 24_2_04E54BC0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DE0B10 | 24_2_04DE0B10 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E4D480 | 24_2_04E4D480 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E75490 | 24_2_04E75490 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E9F5C9 | 24_2_04E9F5C9 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E975C6 | 24_2_04E975C6 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E536EC | 24_2_04E536EC |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E9F6F6 | 24_2_04E9F6F6 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E8D646 | 24_2_04E8D646 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E7D62C | 24_2_04E7D62C |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E81623 | 24_2_04E81623 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DEB0D0 | 24_2_04DEB0D0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E970F1 | 24_2_04E970F1 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E1508C | 24_2_04E1508C |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DE51C0 | 24_2_04DE51C0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DFB1E0 | 24_2_04DFB1E0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E2717A | 24_2_04E2717A |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DCF113 | 24_2_04DCF113 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E7D130 | 24_2_04E7D130 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DCD2EC | 24_2_04DCD2EC |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E9124C | 24_2_04E9124C |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DD1380 | 24_2_04DD1380 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E9F330 | 24_2_04E9F330 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E67CE8 | 24_2_04E67CE8 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DFFCE0 | 24_2_04DFFCE0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E79C98 | 24_2_04E79C98 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DE3C60 | 24_2_04DE3C60 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DE9DD0 | 24_2_04DE9DD0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E7FDF4 | 24_2_04E7FDF4 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E97D4C | 24_2_04E97D4C |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E9FD27 | 24_2_04E9FD27 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E99ED2 | 24_2_04E99ED2 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DE1EB2 | 24_2_04DE1EB2 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E91FC6 | 24_2_04E91FC6 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E9FF63 | 24_2_04E9FF63 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E5FF40 | 24_2_04E5FF40 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E978F3 | 24_2_04E978F3 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E918DA | 24_2_04E918DA |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E598B2 | 24_2_04E598B2 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E55870 | 24_2_04E55870 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E9F872 | 24_2_04E9F872 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DE9870 | 24_2_04DE9870 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DFB870 | 24_2_04DFB870 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DE3800 | 24_2_04DE3800 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E259C0 | 24_2_04E259C0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E9FA89 | 24_2_04E9FA89 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04DFFAA0 | 24_2_04DFFAA0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E71B80 | 24_2_04E71B80 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E9FB2E | 24_2_04E9FB2E |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_04E1DB19 | 24_2_04E1DB19 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_02E11740 | 24_2_02E11740 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_02E2B340 | 24_2_02E2B340 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_02E0104C | 24_2_02E0104C |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_02E0C6A0 | 24_2_02E0C6A0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_02E0AB18 | 24_2_02E0AB18 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_02E0C8C0 | 24_2_02E0C8C0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_02E0A940 | 24_2_02E0A940 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_02E12FD0 | 24_2_02E12FD0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_02E14DF0 | 24_2_02E14DF0 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_050FE64C | 24_2_050FE64C |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_050FD6B8 | 24_2_050FD6B8 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_050FE194 | 24_2_050FE194 |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_050FE2BB | 24_2_050FE2BB |
Source: C:\Windows\SysWOW64\clip.exe | Code function: 24_2_050FC988 | 24_2_050FC988 |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: msvcp140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: edgegdi.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: dwrite.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: msvcp140_clr0400.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: edgegdi.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: wininet.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: ieframe.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: netapi32.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: secur32.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: mlang.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: propsys.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: winsqlite3.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: vaultcli.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\SysWOW64\clip.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: edgegdi.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: dwrite.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: msvcp140_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: edputil.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: urlmon.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: iertutil.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: srvcli.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: appresolver.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: bcp47langs.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: slc.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: sppc.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: edgegdi.dll | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PO# 81136575.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sage.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\clip.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\clip.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\clip.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\clip.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\clip.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\sages.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154415F mov eax, dword ptr fs:[00000030h] | 18_2_0154415F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150A147 mov eax, dword ptr fs:[00000030h] | 18_2_0150A147 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150A147 mov eax, dword ptr fs:[00000030h] | 18_2_0150A147 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150A147 mov eax, dword ptr fs:[00000030h] | 18_2_0150A147 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01516179 mov eax, dword ptr fs:[00000030h] | 18_2_01516179 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01540118 mov eax, dword ptr fs:[00000030h] | 18_2_01540118 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159A130 mov eax, dword ptr fs:[00000030h] | 18_2_0159A130 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015201C0 mov eax, dword ptr fs:[00000030h] | 18_2_015201C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015201C0 mov eax, dword ptr fs:[00000030h] | 18_2_015201C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015201F1 mov eax, dword ptr fs:[00000030h] | 18_2_015201F1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015201F1 mov eax, dword ptr fs:[00000030h] | 18_2_015201F1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015201F1 mov eax, dword ptr fs:[00000030h] | 18_2_015201F1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A1E3 mov eax, dword ptr fs:[00000030h] | 18_2_0151A1E3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A1E3 mov eax, dword ptr fs:[00000030h] | 18_2_0151A1E3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A1E3 mov eax, dword ptr fs:[00000030h] | 18_2_0151A1E3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A1E3 mov eax, dword ptr fs:[00000030h] | 18_2_0151A1E3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A1E3 mov eax, dword ptr fs:[00000030h] | 18_2_0151A1E3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D81EE mov eax, dword ptr fs:[00000030h] | 18_2_015D81EE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D81EE mov eax, dword ptr fs:[00000030h] | 18_2_015D81EE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015081EB mov eax, dword ptr fs:[00000030h] | 18_2_015081EB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01514180 mov eax, dword ptr fs:[00000030h] | 18_2_01514180 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01514180 mov eax, dword ptr fs:[00000030h] | 18_2_01514180 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01514180 mov eax, dword ptr fs:[00000030h] | 18_2_01514180 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015441BB mov ecx, dword ptr fs:[00000030h] | 18_2_015441BB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015441BB mov eax, dword ptr fs:[00000030h] | 18_2_015441BB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015441BB mov eax, dword ptr fs:[00000030h] | 18_2_015441BB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154E1A4 mov eax, dword ptr fs:[00000030h] | 18_2_0154E1A4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154E1A4 mov eax, dword ptr fs:[00000030h] | 18_2_0154E1A4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01540044 mov eax, dword ptr fs:[00000030h] | 18_2_01540044 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01596040 mov eax, dword ptr fs:[00000030h] | 18_2_01596040 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01516074 mov eax, dword ptr fs:[00000030h] | 18_2_01516074 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01516074 mov eax, dword ptr fs:[00000030h] | 18_2_01516074 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01552010 mov ecx, dword ptr fs:[00000030h] | 18_2_01552010 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01518009 mov eax, dword ptr fs:[00000030h] | 18_2_01518009 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150C0F6 mov eax, dword ptr fs:[00000030h] | 18_2_0150C0F6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159C0E0 mov ecx, dword ptr fs:[00000030h] | 18_2_0159C0E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150C090 mov eax, dword ptr fs:[00000030h] | 18_2_0150C090 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150A093 mov ecx, dword ptr fs:[00000030h] | 18_2_0150A093 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015A6090 mov eax, dword ptr fs:[00000030h] | 18_2_015A6090 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015E4080 mov eax, dword ptr fs:[00000030h] | 18_2_015E4080 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015E4080 mov eax, dword ptr fs:[00000030h] | 18_2_015E4080 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015E4080 mov eax, dword ptr fs:[00000030h] | 18_2_015E4080 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015E4080 mov eax, dword ptr fs:[00000030h] | 18_2_015E4080 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015E4080 mov eax, dword ptr fs:[00000030h] | 18_2_015E4080 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015E4080 mov eax, dword ptr fs:[00000030h] | 18_2_015E4080 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015E4080 mov eax, dword ptr fs:[00000030h] | 18_2_015E4080 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015500A5 mov eax, dword ptr fs:[00000030h] | 18_2_015500A5 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015960A0 mov eax, dword ptr fs:[00000030h] | 18_2_015960A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015960A0 mov eax, dword ptr fs:[00000030h] | 18_2_015960A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015960A0 mov eax, dword ptr fs:[00000030h] | 18_2_015960A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015960A0 mov eax, dword ptr fs:[00000030h] | 18_2_015960A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015960A0 mov eax, dword ptr fs:[00000030h] | 18_2_015960A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015960A0 mov eax, dword ptr fs:[00000030h] | 18_2_015960A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015960A0 mov eax, dword ptr fs:[00000030h] | 18_2_015960A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154A350 mov eax, dword ptr fs:[00000030h] | 18_2_0154A350 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01508347 mov eax, dword ptr fs:[00000030h] | 18_2_01508347 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01508347 mov eax, dword ptr fs:[00000030h] | 18_2_01508347 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01508347 mov eax, dword ptr fs:[00000030h] | 18_2_01508347 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01590371 mov eax, dword ptr fs:[00000030h] | 18_2_01590371 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01590371 mov eax, dword ptr fs:[00000030h] | 18_2_01590371 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153237A mov eax, dword ptr fs:[00000030h] | 18_2_0153237A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158E372 mov eax, dword ptr fs:[00000030h] | 18_2_0158E372 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158E372 mov eax, dword ptr fs:[00000030h] | 18_2_0158E372 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158E372 mov eax, dword ptr fs:[00000030h] | 18_2_0158E372 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158E372 mov eax, dword ptr fs:[00000030h] | 18_2_0158E372 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154E363 mov eax, dword ptr fs:[00000030h] | 18_2_0154E363 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154E363 mov eax, dword ptr fs:[00000030h] | 18_2_0154E363 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154E363 mov eax, dword ptr fs:[00000030h] | 18_2_0154E363 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154E363 mov eax, dword ptr fs:[00000030h] | 18_2_0154E363 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154E363 mov eax, dword ptr fs:[00000030h] | 18_2_0154E363 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154E363 mov eax, dword ptr fs:[00000030h] | 18_2_0154E363 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154E363 mov eax, dword ptr fs:[00000030h] | 18_2_0154E363 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154E363 mov eax, dword ptr fs:[00000030h] | 18_2_0154E363 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152E310 mov eax, dword ptr fs:[00000030h] | 18_2_0152E310 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152E310 mov eax, dword ptr fs:[00000030h] | 18_2_0152E310 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152E310 mov eax, dword ptr fs:[00000030h] | 18_2_0152E310 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154631F mov eax, dword ptr fs:[00000030h] | 18_2_0154631F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B630E mov eax, dword ptr fs:[00000030h] | 18_2_015B630E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01548322 mov eax, dword ptr fs:[00000030h] | 18_2_01548322 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01548322 mov eax, dword ptr fs:[00000030h] | 18_2_01548322 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01548322 mov eax, dword ptr fs:[00000030h] | 18_2_01548322 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150E328 mov eax, dword ptr fs:[00000030h] | 18_2_0150E328 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150E328 mov eax, dword ptr fs:[00000030h] | 18_2_0150E328 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150E328 mov eax, dword ptr fs:[00000030h] | 18_2_0150E328 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015443D0 mov ecx, dword ptr fs:[00000030h] | 18_2_015443D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159E3DD mov eax, dword ptr fs:[00000030h] | 18_2_0159E3DD |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015943D5 mov eax, dword ptr fs:[00000030h] | 18_2_015943D5 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150E3C0 mov eax, dword ptr fs:[00000030h] | 18_2_0150E3C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150E3C0 mov eax, dword ptr fs:[00000030h] | 18_2_0150E3C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150E3C0 mov eax, dword ptr fs:[00000030h] | 18_2_0150E3C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150C3C7 mov eax, dword ptr fs:[00000030h] | 18_2_0150C3C7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015163CB mov eax, dword ptr fs:[00000030h] | 18_2_015163CB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153A390 mov eax, dword ptr fs:[00000030h] | 18_2_0153A390 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153A390 mov eax, dword ptr fs:[00000030h] | 18_2_0153A390 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153A390 mov eax, dword ptr fs:[00000030h] | 18_2_0153A390 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B43BA mov eax, dword ptr fs:[00000030h] | 18_2_015B43BA |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B43BA mov eax, dword ptr fs:[00000030h] | 18_2_015B43BA |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158C3B0 mov eax, dword ptr fs:[00000030h] | 18_2_0158C3B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150821B mov eax, dword ptr fs:[00000030h] | 18_2_0150821B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150A200 mov eax, dword ptr fs:[00000030h] | 18_2_0150A200 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01530230 mov ecx, dword ptr fs:[00000030h] | 18_2_01530230 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01590227 mov eax, dword ptr fs:[00000030h] | 18_2_01590227 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01590227 mov eax, dword ptr fs:[00000030h] | 18_2_01590227 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01590227 mov eax, dword ptr fs:[00000030h] | 18_2_01590227 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154A22B mov eax, dword ptr fs:[00000030h] | 18_2_0154A22B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154A22B mov eax, dword ptr fs:[00000030h] | 18_2_0154A22B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154A22B mov eax, dword ptr fs:[00000030h] | 18_2_0154A22B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015202F9 mov eax, dword ptr fs:[00000030h] | 18_2_015202F9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015202F9 mov eax, dword ptr fs:[00000030h] | 18_2_015202F9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015202F9 mov eax, dword ptr fs:[00000030h] | 18_2_015202F9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015202F9 mov eax, dword ptr fs:[00000030h] | 18_2_015202F9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015202F9 mov eax, dword ptr fs:[00000030h] | 18_2_015202F9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015202F9 mov eax, dword ptr fs:[00000030h] | 18_2_015202F9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015202F9 mov eax, dword ptr fs:[00000030h] | 18_2_015202F9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015202F9 mov eax, dword ptr fs:[00000030h] | 18_2_015202F9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A2E0 mov eax, dword ptr fs:[00000030h] | 18_2_0151A2E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A2E0 mov eax, dword ptr fs:[00000030h] | 18_2_0151A2E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A2E0 mov eax, dword ptr fs:[00000030h] | 18_2_0151A2E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A2E0 mov eax, dword ptr fs:[00000030h] | 18_2_0151A2E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A2E0 mov eax, dword ptr fs:[00000030h] | 18_2_0151A2E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A2E0 mov eax, dword ptr fs:[00000030h] | 18_2_0151A2E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015182E0 mov eax, dword ptr fs:[00000030h] | 18_2_015182E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015182E0 mov eax, dword ptr fs:[00000030h] | 18_2_015182E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015182E0 mov eax, dword ptr fs:[00000030h] | 18_2_015182E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015182E0 mov eax, dword ptr fs:[00000030h] | 18_2_015182E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158E289 mov eax, dword ptr fs:[00000030h] | 18_2_0158E289 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150C2B0 mov ecx, dword ptr fs:[00000030h] | 18_2_0150C2B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015342AF mov eax, dword ptr fs:[00000030h] | 18_2_015342AF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015342AF mov eax, dword ptr fs:[00000030h] | 18_2_015342AF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015A6550 mov eax, dword ptr fs:[00000030h] | 18_2_015A6550 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DA553 mov eax, dword ptr fs:[00000030h] | 18_2_015DA553 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01546540 mov eax, dword ptr fs:[00000030h] | 18_2_01546540 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01548540 mov eax, dword ptr fs:[00000030h] | 18_2_01548540 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152E547 mov eax, dword ptr fs:[00000030h] | 18_2_0152E547 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151254C mov eax, dword ptr fs:[00000030h] | 18_2_0151254C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152C560 mov eax, dword ptr fs:[00000030h] | 18_2_0152C560 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159C51D mov eax, dword ptr fs:[00000030h] | 18_2_0159C51D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01512500 mov eax, dword ptr fs:[00000030h] | 18_2_01512500 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153E507 mov eax, dword ptr fs:[00000030h] | 18_2_0153E507 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153E507 mov eax, dword ptr fs:[00000030h] | 18_2_0153E507 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153E507 mov eax, dword ptr fs:[00000030h] | 18_2_0153E507 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153E507 mov eax, dword ptr fs:[00000030h] | 18_2_0153E507 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153E507 mov eax, dword ptr fs:[00000030h] | 18_2_0153E507 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153E507 mov eax, dword ptr fs:[00000030h] | 18_2_0153E507 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153E507 mov eax, dword ptr fs:[00000030h] | 18_2_0153E507 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153E507 mov eax, dword ptr fs:[00000030h] | 18_2_0153E507 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154C50D mov eax, dword ptr fs:[00000030h] | 18_2_0154C50D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154C50D mov eax, dword ptr fs:[00000030h] | 18_2_0154C50D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01552539 mov eax, dword ptr fs:[00000030h] | 18_2_01552539 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152252B mov eax, dword ptr fs:[00000030h] | 18_2_0152252B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152252B mov eax, dword ptr fs:[00000030h] | 18_2_0152252B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152252B mov eax, dword ptr fs:[00000030h] | 18_2_0152252B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152252B mov eax, dword ptr fs:[00000030h] | 18_2_0152252B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152252B mov eax, dword ptr fs:[00000030h] | 18_2_0152252B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152252B mov eax, dword ptr fs:[00000030h] | 18_2_0152252B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152252B mov eax, dword ptr fs:[00000030h] | 18_2_0152252B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015465D0 mov eax, dword ptr fs:[00000030h] | 18_2_015465D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154C5C6 mov eax, dword ptr fs:[00000030h] | 18_2_0154C5C6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015905C6 mov eax, dword ptr fs:[00000030h] | 18_2_015905C6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159C5FC mov eax, dword ptr fs:[00000030h] | 18_2_0159C5FC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154A5E7 mov ebx, dword ptr fs:[00000030h] | 18_2_0154A5E7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154A5E7 mov eax, dword ptr fs:[00000030h] | 18_2_0154A5E7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01542594 mov eax, dword ptr fs:[00000030h] | 18_2_01542594 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159C592 mov eax, dword ptr fs:[00000030h] | 18_2_0159C592 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158E588 mov eax, dword ptr fs:[00000030h] | 18_2_0158E588 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158E588 mov eax, dword ptr fs:[00000030h] | 18_2_0158E588 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154A580 mov eax, dword ptr fs:[00000030h] | 18_2_0154A580 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154A580 mov eax, dword ptr fs:[00000030h] | 18_2_0154A580 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015145B0 mov eax, dword ptr fs:[00000030h] | 18_2_015145B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015145B0 mov eax, dword ptr fs:[00000030h] | 18_2_015145B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015985AA mov eax, dword ptr fs:[00000030h] | 18_2_015985AA |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153E45E mov eax, dword ptr fs:[00000030h] | 18_2_0153E45E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153E45E mov eax, dword ptr fs:[00000030h] | 18_2_0153E45E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153E45E mov eax, dword ptr fs:[00000030h] | 18_2_0153E45E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153E45E mov eax, dword ptr fs:[00000030h] | 18_2_0153E45E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153E45E mov eax, dword ptr fs:[00000030h] | 18_2_0153E45E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520445 mov eax, dword ptr fs:[00000030h] | 18_2_01520445 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520445 mov eax, dword ptr fs:[00000030h] | 18_2_01520445 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520445 mov eax, dword ptr fs:[00000030h] | 18_2_01520445 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520445 mov eax, dword ptr fs:[00000030h] | 18_2_01520445 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520445 mov eax, dword ptr fs:[00000030h] | 18_2_01520445 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520445 mov eax, dword ptr fs:[00000030h] | 18_2_01520445 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01590443 mov eax, dword ptr fs:[00000030h] | 18_2_01590443 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01518470 mov eax, dword ptr fs:[00000030h] | 18_2_01518470 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01518470 mov eax, dword ptr fs:[00000030h] | 18_2_01518470 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159E461 mov eax, dword ptr fs:[00000030h] | 18_2_0159E461 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DA464 mov eax, dword ptr fs:[00000030h] | 18_2_015DA464 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015A6400 mov eax, dword ptr fs:[00000030h] | 18_2_015A6400 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015A6400 mov eax, dword ptr fs:[00000030h] | 18_2_015A6400 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150640D mov eax, dword ptr fs:[00000030h] | 18_2_0150640D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015344D1 mov eax, dword ptr fs:[00000030h] | 18_2_015344D1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015344D1 mov eax, dword ptr fs:[00000030h] | 18_2_015344D1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015164F0 mov eax, dword ptr fs:[00000030h] | 18_2_015164F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B44F8 mov eax, dword ptr fs:[00000030h] | 18_2_015B44F8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B44F8 mov eax, dword ptr fs:[00000030h] | 18_2_015B44F8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154A4F0 mov eax, dword ptr fs:[00000030h] | 18_2_0154A4F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154A4F0 mov eax, dword ptr fs:[00000030h] | 18_2_0154A4F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159E4F2 mov eax, dword ptr fs:[00000030h] | 18_2_0159E4F2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159E4F2 mov eax, dword ptr fs:[00000030h] | 18_2_0159E4F2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154E4EF mov eax, dword ptr fs:[00000030h] | 18_2_0154E4EF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154E4EF mov eax, dword ptr fs:[00000030h] | 18_2_0154E4EF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159C490 mov eax, dword ptr fs:[00000030h] | 18_2_0159C490 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01510485 mov ecx, dword ptr fs:[00000030h] | 18_2_01510485 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154648A mov eax, dword ptr fs:[00000030h] | 18_2_0154648A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154648A mov eax, dword ptr fs:[00000030h] | 18_2_0154648A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154648A mov eax, dword ptr fs:[00000030h] | 18_2_0154648A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015A84BB mov eax, dword ptr fs:[00000030h] | 18_2_015A84BB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154E4BC mov eax, dword ptr fs:[00000030h] | 18_2_0154E4BC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015124A2 mov eax, dword ptr fs:[00000030h] | 18_2_015124A2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015124A2 mov ecx, dword ptr fs:[00000030h] | 18_2_015124A2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015444A8 mov eax, dword ptr fs:[00000030h] | 18_2_015444A8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154A750 mov eax, dword ptr fs:[00000030h] | 18_2_0154A750 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01532755 mov eax, dword ptr fs:[00000030h] | 18_2_01532755 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01532755 mov eax, dword ptr fs:[00000030h] | 18_2_01532755 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01532755 mov eax, dword ptr fs:[00000030h] | 18_2_01532755 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01532755 mov ecx, dword ptr fs:[00000030h] | 18_2_01532755 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01532755 mov eax, dword ptr fs:[00000030h] | 18_2_01532755 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01532755 mov eax, dword ptr fs:[00000030h] | 18_2_01532755 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015BE750 mov eax, dword ptr fs:[00000030h] | 18_2_015BE750 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01540774 mov eax, dword ptr fs:[00000030h] | 18_2_01540774 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01514779 mov eax, dword ptr fs:[00000030h] | 18_2_01514779 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01514779 mov eax, dword ptr fs:[00000030h] | 18_2_01514779 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01522760 mov ecx, dword ptr fs:[00000030h] | 18_2_01522760 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151471B mov eax, dword ptr fs:[00000030h] | 18_2_0151471B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151471B mov eax, dword ptr fs:[00000030h] | 18_2_0151471B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153270D mov eax, dword ptr fs:[00000030h] | 18_2_0153270D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153270D mov eax, dword ptr fs:[00000030h] | 18_2_0153270D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153270D mov eax, dword ptr fs:[00000030h] | 18_2_0153270D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153E7E0 mov eax, dword ptr fs:[00000030h] | 18_2_0153E7E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158E79D mov eax, dword ptr fs:[00000030h] | 18_2_0158E79D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158E79D mov eax, dword ptr fs:[00000030h] | 18_2_0158E79D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158E79D mov eax, dword ptr fs:[00000030h] | 18_2_0158E79D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158E79D mov eax, dword ptr fs:[00000030h] | 18_2_0158E79D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158E79D mov eax, dword ptr fs:[00000030h] | 18_2_0158E79D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158E79D mov eax, dword ptr fs:[00000030h] | 18_2_0158E79D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158E79D mov eax, dword ptr fs:[00000030h] | 18_2_0158E79D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158E79D mov eax, dword ptr fs:[00000030h] | 18_2_0158E79D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158E79D mov eax, dword ptr fs:[00000030h] | 18_2_0158E79D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015AC7B0 mov eax, dword ptr fs:[00000030h] | 18_2_015AC7B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015AC7B0 mov eax, dword ptr fs:[00000030h] | 18_2_015AC7B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B47B4 mov eax, dword ptr fs:[00000030h] | 18_2_015B47B4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B47B4 mov eax, dword ptr fs:[00000030h] | 18_2_015B47B4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B47B4 mov eax, dword ptr fs:[00000030h] | 18_2_015B47B4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B47B4 mov eax, dword ptr fs:[00000030h] | 18_2_015B47B4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B47B4 mov eax, dword ptr fs:[00000030h] | 18_2_015B47B4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B47B4 mov eax, dword ptr fs:[00000030h] | 18_2_015B47B4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B47B4 mov ecx, dword ptr fs:[00000030h] | 18_2_015B47B4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015107A7 mov eax, dword ptr fs:[00000030h] | 18_2_015107A7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154265C mov eax, dword ptr fs:[00000030h] | 18_2_0154265C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154265C mov ecx, dword ptr fs:[00000030h] | 18_2_0154265C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154265C mov eax, dword ptr fs:[00000030h] | 18_2_0154265C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154C640 mov eax, dword ptr fs:[00000030h] | 18_2_0154C640 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154C640 mov eax, dword ptr fs:[00000030h] | 18_2_0154C640 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01510670 mov eax, dword ptr fs:[00000030h] | 18_2_01510670 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01552670 mov eax, dword ptr fs:[00000030h] | 18_2_01552670 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01552670 mov eax, dword ptr fs:[00000030h] | 18_2_01552670 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154666D mov esi, dword ptr fs:[00000030h] | 18_2_0154666D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154666D mov eax, dword ptr fs:[00000030h] | 18_2_0154666D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154666D mov eax, dword ptr fs:[00000030h] | 18_2_0154666D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159E660 mov eax, dword ptr fs:[00000030h] | 18_2_0159E660 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015E4600 mov eax, dword ptr fs:[00000030h] | 18_2_015E4600 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01510630 mov eax, dword ptr fs:[00000030h] | 18_2_01510630 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01540630 mov eax, dword ptr fs:[00000030h] | 18_2_01540630 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01598633 mov esi, dword ptr fs:[00000030h] | 18_2_01598633 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01598633 mov eax, dword ptr fs:[00000030h] | 18_2_01598633 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01598633 mov eax, dword ptr fs:[00000030h] | 18_2_01598633 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154C620 mov eax, dword ptr fs:[00000030h] | 18_2_0154C620 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015A66D0 mov eax, dword ptr fs:[00000030h] | 18_2_015A66D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015A66D0 mov eax, dword ptr fs:[00000030h] | 18_2_015A66D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B86C2 mov eax, dword ptr fs:[00000030h] | 18_2_015B86C2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DA6C0 mov eax, dword ptr fs:[00000030h] | 18_2_015DA6C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015106CF mov eax, dword ptr fs:[00000030h] | 18_2_015106CF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158C6F2 mov eax, dword ptr fs:[00000030h] | 18_2_0158C6F2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158C6F2 mov eax, dword ptr fs:[00000030h] | 18_2_0158C6F2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151C6E0 mov eax, dword ptr fs:[00000030h] | 18_2_0151C6E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015366E0 mov eax, dword ptr fs:[00000030h] | 18_2_015366E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015366E0 mov eax, dword ptr fs:[00000030h] | 18_2_015366E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01518690 mov eax, dword ptr fs:[00000030h] | 18_2_01518690 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159C691 mov eax, dword ptr fs:[00000030h] | 18_2_0159C691 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520680 mov eax, dword ptr fs:[00000030h] | 18_2_01520680 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520680 mov eax, dword ptr fs:[00000030h] | 18_2_01520680 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520680 mov eax, dword ptr fs:[00000030h] | 18_2_01520680 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520680 mov eax, dword ptr fs:[00000030h] | 18_2_01520680 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520680 mov eax, dword ptr fs:[00000030h] | 18_2_01520680 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520680 mov eax, dword ptr fs:[00000030h] | 18_2_01520680 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520680 mov eax, dword ptr fs:[00000030h] | 18_2_01520680 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520680 mov eax, dword ptr fs:[00000030h] | 18_2_01520680 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520680 mov eax, dword ptr fs:[00000030h] | 18_2_01520680 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520680 mov eax, dword ptr fs:[00000030h] | 18_2_01520680 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520680 mov eax, dword ptr fs:[00000030h] | 18_2_01520680 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520680 mov eax, dword ptr fs:[00000030h] | 18_2_01520680 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D86A8 mov eax, dword ptr fs:[00000030h] | 18_2_015D86A8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D86A8 mov eax, dword ptr fs:[00000030h] | 18_2_015D86A8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01534955 mov eax, dword ptr fs:[00000030h] | 18_2_01534955 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01534955 mov eax, dword ptr fs:[00000030h] | 18_2_01534955 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154C958 mov eax, dword ptr fs:[00000030h] | 18_2_0154C958 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154C944 mov eax, dword ptr fs:[00000030h] | 18_2_0154C944 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153E94E mov eax, dword ptr fs:[00000030h] | 18_2_0153E94E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01516970 mov eax, dword ptr fs:[00000030h] | 18_2_01516970 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01516970 mov eax, dword ptr fs:[00000030h] | 18_2_01516970 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01516970 mov eax, dword ptr fs:[00000030h] | 18_2_01516970 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01516970 mov eax, dword ptr fs:[00000030h] | 18_2_01516970 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01516970 mov eax, dword ptr fs:[00000030h] | 18_2_01516970 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01516970 mov eax, dword ptr fs:[00000030h] | 18_2_01516970 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01516970 mov eax, dword ptr fs:[00000030h] | 18_2_01516970 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152096B mov eax, dword ptr fs:[00000030h] | 18_2_0152096B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0152096B mov eax, dword ptr fs:[00000030h] | 18_2_0152096B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01566912 mov eax, dword ptr fs:[00000030h] | 18_2_01566912 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01542919 mov eax, dword ptr fs:[00000030h] | 18_2_01542919 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01542919 mov eax, dword ptr fs:[00000030h] | 18_2_01542919 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0156693A mov eax, dword ptr fs:[00000030h] | 18_2_0156693A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0156693A mov eax, dword ptr fs:[00000030h] | 18_2_0156693A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0156693A mov eax, dword ptr fs:[00000030h] | 18_2_0156693A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D892E mov eax, dword ptr fs:[00000030h] | 18_2_015D892E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D892E mov eax, dword ptr fs:[00000030h] | 18_2_015D892E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015E492D mov eax, dword ptr fs:[00000030h] | 18_2_015E492D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158C920 mov ecx, dword ptr fs:[00000030h] | 18_2_0158C920 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158C920 mov eax, dword ptr fs:[00000030h] | 18_2_0158C920 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158C920 mov eax, dword ptr fs:[00000030h] | 18_2_0158C920 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158C920 mov eax, dword ptr fs:[00000030h] | 18_2_0158C920 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015E29CF mov eax, dword ptr fs:[00000030h] | 18_2_015E29CF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015E29CF mov eax, dword ptr fs:[00000030h] | 18_2_015E29CF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015189C0 mov eax, dword ptr fs:[00000030h] | 18_2_015189C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015189C0 mov eax, dword ptr fs:[00000030h] | 18_2_015189C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015109F0 mov eax, dword ptr fs:[00000030h] | 18_2_015109F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015449F0 mov eax, dword ptr fs:[00000030h] | 18_2_015449F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015449F0 mov eax, dword ptr fs:[00000030h] | 18_2_015449F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154C98F mov eax, dword ptr fs:[00000030h] | 18_2_0154C98F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154C98F mov eax, dword ptr fs:[00000030h] | 18_2_0154C98F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154C98F mov eax, dword ptr fs:[00000030h] | 18_2_0154C98F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B0980 mov eax, dword ptr fs:[00000030h] | 18_2_015B0980 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B0980 mov eax, dword ptr fs:[00000030h] | 18_2_015B0980 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015489B0 mov edx, dword ptr fs:[00000030h] | 18_2_015489B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015A69B0 mov eax, dword ptr fs:[00000030h] | 18_2_015A69B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015A69B0 mov eax, dword ptr fs:[00000030h] | 18_2_015A69B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015A69B0 mov ecx, dword ptr fs:[00000030h] | 18_2_015A69B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151E9A0 mov eax, dword ptr fs:[00000030h] | 18_2_0151E9A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151E9A0 mov eax, dword ptr fs:[00000030h] | 18_2_0151E9A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151E9A0 mov eax, dword ptr fs:[00000030h] | 18_2_0151E9A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151E9A0 mov eax, dword ptr fs:[00000030h] | 18_2_0151E9A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151E9A0 mov eax, dword ptr fs:[00000030h] | 18_2_0151E9A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151E9A0 mov eax, dword ptr fs:[00000030h] | 18_2_0151E9A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151E9A0 mov eax, dword ptr fs:[00000030h] | 18_2_0151E9A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151E9A0 mov eax, dword ptr fs:[00000030h] | 18_2_0151E9A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151E9A0 mov eax, dword ptr fs:[00000030h] | 18_2_0151E9A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015989A0 mov eax, dword ptr fs:[00000030h] | 18_2_015989A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159C870 mov eax, dword ptr fs:[00000030h] | 18_2_0159C870 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154C819 mov eax, dword ptr fs:[00000030h] | 18_2_0154C819 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154C819 mov eax, dword ptr fs:[00000030h] | 18_2_0154C819 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0835 mov eax, dword ptr fs:[00000030h] | 18_2_015C0835 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0835 mov eax, dword ptr fs:[00000030h] | 18_2_015C0835 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0835 mov eax, dword ptr fs:[00000030h] | 18_2_015C0835 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0835 mov eax, dword ptr fs:[00000030h] | 18_2_015C0835 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0835 mov eax, dword ptr fs:[00000030h] | 18_2_015C0835 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0835 mov eax, dword ptr fs:[00000030h] | 18_2_015C0835 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0835 mov eax, dword ptr fs:[00000030h] | 18_2_015C0835 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0835 mov eax, dword ptr fs:[00000030h] | 18_2_015C0835 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0835 mov eax, dword ptr fs:[00000030h] | 18_2_015C0835 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0835 mov eax, dword ptr fs:[00000030h] | 18_2_015C0835 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0835 mov eax, dword ptr fs:[00000030h] | 18_2_015C0835 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0835 mov eax, dword ptr fs:[00000030h] | 18_2_015C0835 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0835 mov eax, dword ptr fs:[00000030h] | 18_2_015C0835 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015228C0 mov eax, dword ptr fs:[00000030h] | 18_2_015228C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015228C0 mov eax, dword ptr fs:[00000030h] | 18_2_015228C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015228C0 mov eax, dword ptr fs:[00000030h] | 18_2_015228C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015228C0 mov eax, dword ptr fs:[00000030h] | 18_2_015228C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015228C0 mov eax, dword ptr fs:[00000030h] | 18_2_015228C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015228C0 mov eax, dword ptr fs:[00000030h] | 18_2_015228C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015228C0 mov eax, dword ptr fs:[00000030h] | 18_2_015228C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015228C0 mov eax, dword ptr fs:[00000030h] | 18_2_015228C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015228C0 mov eax, dword ptr fs:[00000030h] | 18_2_015228C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015228C0 mov eax, dword ptr fs:[00000030h] | 18_2_015228C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015228C0 mov eax, dword ptr fs:[00000030h] | 18_2_015228C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015228C0 mov eax, dword ptr fs:[00000030h] | 18_2_015228C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015228C0 mov eax, dword ptr fs:[00000030h] | 18_2_015228C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015088C8 mov eax, dword ptr fs:[00000030h] | 18_2_015088C8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015088C8 mov eax, dword ptr fs:[00000030h] | 18_2_015088C8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015108CD mov eax, dword ptr fs:[00000030h] | 18_2_015108CD |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015108CD mov eax, dword ptr fs:[00000030h] | 18_2_015108CD |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015A88FB mov eax, dword ptr fs:[00000030h] | 18_2_015A88FB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A8F0 mov eax, dword ptr fs:[00000030h] | 18_2_0151A8F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A8F0 mov eax, dword ptr fs:[00000030h] | 18_2_0151A8F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A8F0 mov eax, dword ptr fs:[00000030h] | 18_2_0151A8F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A8F0 mov eax, dword ptr fs:[00000030h] | 18_2_0151A8F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A8F0 mov eax, dword ptr fs:[00000030h] | 18_2_0151A8F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151A8F0 mov eax, dword ptr fs:[00000030h] | 18_2_0151A8F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015448F0 mov eax, dword ptr fs:[00000030h] | 18_2_015448F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C8890 mov eax, dword ptr fs:[00000030h] | 18_2_015C8890 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C8890 mov eax, dword ptr fs:[00000030h] | 18_2_015C8890 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01536882 mov eax, dword ptr fs:[00000030h] | 18_2_01536882 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01536882 mov eax, dword ptr fs:[00000030h] | 18_2_01536882 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01536882 mov eax, dword ptr fs:[00000030h] | 18_2_01536882 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159488F mov eax, dword ptr fs:[00000030h] | 18_2_0159488F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0155088E mov eax, dword ptr fs:[00000030h] | 18_2_0155088E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0155088E mov edx, dword ptr fs:[00000030h] | 18_2_0155088E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0155088E mov eax, dword ptr fs:[00000030h] | 18_2_0155088E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151AB70 mov eax, dword ptr fs:[00000030h] | 18_2_0151AB70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151AB70 mov eax, dword ptr fs:[00000030h] | 18_2_0151AB70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151AB70 mov eax, dword ptr fs:[00000030h] | 18_2_0151AB70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151AB70 mov eax, dword ptr fs:[00000030h] | 18_2_0151AB70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151AB70 mov eax, dword ptr fs:[00000030h] | 18_2_0151AB70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151AB70 mov eax, dword ptr fs:[00000030h] | 18_2_0151AB70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01516B70 mov eax, dword ptr fs:[00000030h] | 18_2_01516B70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01516B70 mov eax, dword ptr fs:[00000030h] | 18_2_01516B70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01516B70 mov eax, dword ptr fs:[00000030h] | 18_2_01516B70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C6B77 mov eax, dword ptr fs:[00000030h] | 18_2_015C6B77 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01544B79 mov eax, dword ptr fs:[00000030h] | 18_2_01544B79 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015E4B67 mov eax, dword ptr fs:[00000030h] | 18_2_015E4B67 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01518B10 mov eax, dword ptr fs:[00000030h] | 18_2_01518B10 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01518B10 mov eax, dword ptr fs:[00000030h] | 18_2_01518B10 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01518B10 mov eax, dword ptr fs:[00000030h] | 18_2_01518B10 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520B10 mov eax, dword ptr fs:[00000030h] | 18_2_01520B10 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520B10 mov eax, dword ptr fs:[00000030h] | 18_2_01520B10 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520B10 mov eax, dword ptr fs:[00000030h] | 18_2_01520B10 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520B10 mov eax, dword ptr fs:[00000030h] | 18_2_01520B10 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150CB1E mov eax, dword ptr fs:[00000030h] | 18_2_0150CB1E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153EB1C mov eax, dword ptr fs:[00000030h] | 18_2_0153EB1C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154CB20 mov eax, dword ptr fs:[00000030h] | 18_2_0154CB20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159CB20 mov eax, dword ptr fs:[00000030h] | 18_2_0159CB20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159CB20 mov eax, dword ptr fs:[00000030h] | 18_2_0159CB20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159CB20 mov eax, dword ptr fs:[00000030h] | 18_2_0159CB20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01538BD1 mov eax, dword ptr fs:[00000030h] | 18_2_01538BD1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01538BD1 mov eax, dword ptr fs:[00000030h] | 18_2_01538BD1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B6BDE mov ebx, dword ptr fs:[00000030h] | 18_2_015B6BDE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B6BDE mov eax, dword ptr fs:[00000030h] | 18_2_015B6BDE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150EBC0 mov eax, dword ptr fs:[00000030h] | 18_2_0150EBC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01594BC0 mov eax, dword ptr fs:[00000030h] | 18_2_01594BC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01594BC0 mov eax, dword ptr fs:[00000030h] | 18_2_01594BC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01594BC0 mov eax, dword ptr fs:[00000030h] | 18_2_01594BC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01594BC0 mov eax, dword ptr fs:[00000030h] | 18_2_01594BC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015E4BE0 mov eax, dword ptr fs:[00000030h] | 18_2_015E4BE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D8BBE mov eax, dword ptr fs:[00000030h] | 18_2_015D8BBE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D8BBE mov eax, dword ptr fs:[00000030h] | 18_2_015D8BBE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D8BBE mov eax, dword ptr fs:[00000030h] | 18_2_015D8BBE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015D8BBE mov eax, dword ptr fs:[00000030h] | 18_2_015D8BBE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01594A57 mov eax, dword ptr fs:[00000030h] | 18_2_01594A57 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01594A57 mov eax, dword ptr fs:[00000030h] | 18_2_01594A57 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153EA40 mov eax, dword ptr fs:[00000030h] | 18_2_0153EA40 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153EA40 mov eax, dword ptr fs:[00000030h] | 18_2_0153EA40 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015AAA40 mov eax, dword ptr fs:[00000030h] | 18_2_015AAA40 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015AAA40 mov eax, dword ptr fs:[00000030h] | 18_2_015AAA40 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154AA0E mov eax, dword ptr fs:[00000030h] | 18_2_0154AA0E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0154AA0E mov eax, dword ptr fs:[00000030h] | 18_2_0154AA0E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B4AC2 mov eax, dword ptr fs:[00000030h] | 18_2_015B4AC2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520ACE mov eax, dword ptr fs:[00000030h] | 18_2_01520ACE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01520ACE mov eax, dword ptr fs:[00000030h] | 18_2_01520ACE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01590AFF mov eax, dword ptr fs:[00000030h] | 18_2_01590AFF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01590AFF mov eax, dword ptr fs:[00000030h] | 18_2_01590AFF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01590AFF mov eax, dword ptr fs:[00000030h] | 18_2_01590AFF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015E4AE8 mov eax, dword ptr fs:[00000030h] | 18_2_015E4AE8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01530AEB mov eax, dword ptr fs:[00000030h] | 18_2_01530AEB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01530AEB mov eax, dword ptr fs:[00000030h] | 18_2_01530AEB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01530AEB mov eax, dword ptr fs:[00000030h] | 18_2_01530AEB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B0AE0 mov eax, dword ptr fs:[00000030h] | 18_2_015B0AE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B2AE0 mov eax, dword ptr fs:[00000030h] | 18_2_015B2AE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B2AE0 mov eax, dword ptr fs:[00000030h] | 18_2_015B2AE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01510AED mov eax, dword ptr fs:[00000030h] | 18_2_01510AED |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01510AED mov eax, dword ptr fs:[00000030h] | 18_2_01510AED |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01510AED mov eax, dword ptr fs:[00000030h] | 18_2_01510AED |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C6A80 mov eax, dword ptr fs:[00000030h] | 18_2_015C6A80 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015E4D4B mov eax, dword ptr fs:[00000030h] | 18_2_015E4D4B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158CD40 mov eax, dword ptr fs:[00000030h] | 18_2_0158CD40 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0158CD40 mov eax, dword ptr fs:[00000030h] | 18_2_0158CD40 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015B6D79 mov esi, dword ptr fs:[00000030h] | 18_2_015B6D79 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153CD10 mov eax, dword ptr fs:[00000030h] | 18_2_0153CD10 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153CD10 mov ecx, dword ptr fs:[00000030h] | 18_2_0153CD10 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015A8D0A mov eax, dword ptr fs:[00000030h] | 18_2_015A8D0A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151AD00 mov eax, dword ptr fs:[00000030h] | 18_2_0151AD00 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151AD00 mov eax, dword ptr fs:[00000030h] | 18_2_0151AD00 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151AD00 mov eax, dword ptr fs:[00000030h] | 18_2_0151AD00 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151AD00 mov eax, dword ptr fs:[00000030h] | 18_2_0151AD00 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151AD00 mov eax, dword ptr fs:[00000030h] | 18_2_0151AD00 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0151AD00 mov eax, dword ptr fs:[00000030h] | 18_2_0151AD00 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01530D01 mov eax, dword ptr fs:[00000030h] | 18_2_01530D01 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159CD00 mov eax, dword ptr fs:[00000030h] | 18_2_0159CD00 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0159CD00 mov eax, dword ptr fs:[00000030h] | 18_2_0159CD00 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153AD20 mov eax, dword ptr fs:[00000030h] | 18_2_0153AD20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153AD20 mov eax, dword ptr fs:[00000030h] | 18_2_0153AD20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153AD20 mov eax, dword ptr fs:[00000030h] | 18_2_0153AD20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153AD20 mov ecx, dword ptr fs:[00000030h] | 18_2_0153AD20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153AD20 mov eax, dword ptr fs:[00000030h] | 18_2_0153AD20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153AD20 mov eax, dword ptr fs:[00000030h] | 18_2_0153AD20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153AD20 mov eax, dword ptr fs:[00000030h] | 18_2_0153AD20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153AD20 mov eax, dword ptr fs:[00000030h] | 18_2_0153AD20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153AD20 mov eax, dword ptr fs:[00000030h] | 18_2_0153AD20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0153AD20 mov eax, dword ptr fs:[00000030h] | 18_2_0153AD20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0D24 mov eax, dword ptr fs:[00000030h] | 18_2_015C0D24 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0D24 mov eax, dword ptr fs:[00000030h] | 18_2_015C0D24 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0D24 mov eax, dword ptr fs:[00000030h] | 18_2_015C0D24 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015C0D24 mov eax, dword ptr fs:[00000030h] | 18_2_015C0D24 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015CADD6 mov eax, dword ptr fs:[00000030h] | 18_2_015CADD6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015CADD6 mov eax, dword ptr fs:[00000030h] | 18_2_015CADD6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01508DCD mov eax, dword ptr fs:[00000030h] | 18_2_01508DCD |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150EDFA mov eax, dword ptr fs:[00000030h] | 18_2_0150EDFA |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DCDEB mov eax, dword ptr fs:[00000030h] | 18_2_015DCDEB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_015DCDEB mov eax, dword ptr fs:[00000030h] | 18_2_015DCDEB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01516D91 mov eax, dword ptr fs:[00000030h] | 18_2_01516D91 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150CD8A mov eax, dword ptr fs:[00000030h] | 18_2_0150CD8A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_0150CD8A mov eax, dword ptr fs:[00000030h] | 18_2_0150CD8A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | Code function: 18_2_01542DBC mov eax, dword ptr fs:[00000030h] | 18_2_01542DBC |