Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0053445A GetFileAttributesW,FindFirstFileW,FindClose, | 0_2_0053445A |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0053C6D1 FindFirstFileW,FindClose, | 0_2_0053C6D1 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0053C75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 0_2_0053C75C |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0053EF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_0053EF95 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0053F0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_0053F0F2 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0053F3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_0053F3F3 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_005337EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_005337EF |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_00533B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_00533B12 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0053BCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_0053BCBC |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_0042445A GetFileAttributesW,FindFirstFileW,FindClose, | 2_2_0042445A |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_0042C6D1 FindFirstFileW,FindClose, | 2_2_0042C6D1 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_0042C75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 2_2_0042C75C |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_0042EF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 2_2_0042EF95 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_0042F0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 2_2_0042F0F2 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_0042F3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 2_2_0042F3F3 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_004237EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 2_2_004237EF |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_00423B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 2_2_00423B12 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_0042BCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 2_2_0042BCBC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 01489731h | 3_2_01489480 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 01489E5Ah | 3_2_01489A40 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 01489E5Ah | 3_2_01489A30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 01489E5Ah | 3_2_01489D87 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 024A9731h | 9_2_024A9480 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 024A9E5Ah | 9_2_024A9A40 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 024A9E5Ah | 9_2_024A9A30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 024A9E5Ah | 9_2_024A9D87 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D05E15h | 9_2_04D05AD8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D0F700h | 9_2_04D0F458 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D076D0h | 9_2_04D07428 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D08830h | 9_2_04D08588 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D047C9h | 9_2_04D04520 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D05929h | 9_2_04D05680 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D0E9F8h | 9_2_04D0E750 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D0F2A8h | 9_2_04D0F000 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D083D8h | 9_2_04D08130 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D0E5A0h | 9_2_04D0E2F8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D054D1h | 9_2_04D05228 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D07F80h | 9_2_04D07CD8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D05079h | 9_2_04D04DD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D07278h | 9_2_04D06FD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D07B28h | 9_2_04D07880 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D0FB58h | 9_2_04D0F8B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D04C21h | 9_2_04D04978 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 04D0EE50h | 9_2_04D0EBA8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C62B5h | 9_2_052C60D8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C6C3Fh | 9_2_052C60D8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C3840h | 9_2_052C3598 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C18A0h | 9_2_052C15F8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C26E0h | 9_2_052C2438 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C0740h | 9_2_052C0498 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C49A0h | 9_2_052C46F8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C33E8h | 9_2_052C3140 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C1448h | 9_2_052C11A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then mov dword ptr [ebp-14h], 00000000h | 9_2_052C51E8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C02E8h | 9_2_052C0040 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then mov esp, ebp | 9_2_052C93F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C4548h | 9_2_052C42A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C0FF0h | 9_2_052C0D48 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C2F90h | 9_2_052C2CE8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C40F0h | 9_2_052C3E48 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C2152h | 9_2_052C1EA8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then mov dword ptr [ebp-14h], 00000000h | 9_2_052C59FB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C3C98h | 9_2_052C39F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then mov dword ptr [ebp-14h], 00000000h | 9_2_052C581B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C2B38h | 9_2_052C2890 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C0B98h | 9_2_052C08F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C4DF8h | 9_2_052C4B50 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 4x nop then jmp 052C1CF8h | 9_2_052C1A50 |
Source: RegSvcs.exe, 00000003.00000002.3376122410.0000000002EB0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000009.00000002.3376008303.0000000002770000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.com |
Source: RegSvcs.exe, 00000003.00000002.3376122410.0000000002EB0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000009.00000002.3376008303.0000000002770000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.comd |
Source: RegSvcs.exe, 00000003.00000002.3376122410.0000000002E9E000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.3376122410.0000000002EB0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000009.00000002.3376008303.0000000002770000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000009.00000002.3376008303.000000000275E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org |
Source: RegSvcs.exe, 00000003.00000002.3376122410.0000000002E83000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.3376122410.0000000002E31000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000009.00000002.3376008303.00000000026F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/ |
Source: RegSvcs.exe, 00000003.00000002.3376122410.0000000002EB0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000009.00000002.3376008303.0000000002770000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/d |
Source: juvenile.exe, 00000002.00000002.2191566788.0000000000510000.00000004.00001000.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.3374747417.0000000000402000.00000040.80000000.00040000.00000000.sdmp, juvenile.exe, 00000006.00000002.2340015646.0000000001390000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/q |
Source: RegSvcs.exe, 00000003.00000002.3376122410.0000000002EB0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000009.00000002.3376008303.0000000002770000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.orgd |
Source: RegSvcs.exe, 00000003.00000002.3376122410.0000000002ECD000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000009.00000002.3376008303.000000000278D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://reallyfreegeoip.org |
Source: RegSvcs.exe, 00000003.00000002.3376122410.0000000002ECD000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000009.00000002.3376008303.000000000278D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://reallyfreegeoip.orgd |
Source: RegSvcs.exe, 00000003.00000002.3376122410.0000000002E83000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000009.00000002.3376008303.00000000026F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: juvenile.exe, 00000002.00000002.2191566788.0000000000510000.00000004.00001000.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.3374747417.0000000000402000.00000040.80000000.00040000.00000000.sdmp, juvenile.exe, 00000006.00000002.2340015646.0000000001390000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot-/sendDocument?chat_id= |
Source: RegSvcs.exe, 00000003.00000002.3376122410.0000000002EB0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000009.00000002.3376008303.0000000002770000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org |
Source: juvenile.exe, 00000002.00000002.2191566788.0000000000510000.00000004.00001000.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.3374747417.0000000000402000.00000040.80000000.00040000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.3376122410.0000000002EB0000.00000004.00000800.00020000.00000000.sdmp, juvenile.exe, 00000006.00000002.2340015646.0000000001390000.00000004.00001000.00020000.00000000.sdmp, RegSvcs.exe, 00000009.00000002.3376008303.0000000002770000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/ |
Source: RegSvcs.exe, 00000003.00000002.3376122410.0000000002EB0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000009.00000002.3376008303.0000000002770000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.175d |
Source: RegSvcs.exe, 00000003.00000002.3376122410.0000000002EB0000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000009.00000002.3376008303.0000000002770000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.175l |
Source: 2.2.juvenile.exe.510000.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 2.2.juvenile.exe.510000.1.raw.unpack, type: UNPACKEDPE | Matched rule: Detects Encrial credential stealer malware Author: Florian Roth |
Source: 3.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 3.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Detects Encrial credential stealer malware Author: Florian Roth |
Source: 6.2.juvenile.exe.1390000.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 6.2.juvenile.exe.1390000.1.raw.unpack, type: UNPACKEDPE | Matched rule: Detects Encrial credential stealer malware Author: Florian Roth |
Source: 2.2.juvenile.exe.510000.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 2.2.juvenile.exe.510000.1.unpack, type: UNPACKEDPE | Matched rule: Detects Encrial credential stealer malware Author: Florian Roth |
Source: 6.2.juvenile.exe.1390000.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 6.2.juvenile.exe.1390000.1.unpack, type: UNPACKEDPE | Matched rule: Detects Encrial credential stealer malware Author: Florian Roth |
Source: 00000006.00000002.2340015646.0000000001390000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 00000006.00000002.2340015646.0000000001390000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects Encrial credential stealer malware Author: Florian Roth |
Source: 00000002.00000002.2191566788.0000000000510000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: 00000002.00000002.2191566788.0000000000510000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects Encrial credential stealer malware Author: Florian Roth |
Source: 00000003.00000002.3374747417.0000000000402000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: Process Memory Space: juvenile.exe PID: 6552, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: Process Memory Space: RegSvcs.exe PID: 4328, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: Process Memory Space: juvenile.exe PID: 4196, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004DE6A0 | 0_2_004DE6A0 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004FD975 | 0_2_004FD975 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004DFCE0 | 0_2_004DFCE0 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004F21C5 | 0_2_004F21C5 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_005062D2 | 0_2_005062D2 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_005503DA | 0_2_005503DA |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0050242E | 0_2_0050242E |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004F25FA | 0_2_004F25FA |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0052E616 | 0_2_0052E616 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004E66E1 | 0_2_004E66E1 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0050878F | 0_2_0050878F |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_00550857 | 0_2_00550857 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_00506844 | 0_2_00506844 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004E8808 | 0_2_004E8808 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_00538889 | 0_2_00538889 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004FCB21 | 0_2_004FCB21 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_00506DB6 | 0_2_00506DB6 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004E6F9E | 0_2_004E6F9E |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004E3030 | 0_2_004E3030 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004FF1D9 | 0_2_004FF1D9 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004F3187 | 0_2_004F3187 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004D1287 | 0_2_004D1287 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004F1484 | 0_2_004F1484 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004E5520 | 0_2_004E5520 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004F7696 | 0_2_004F7696 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004E5760 | 0_2_004E5760 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004F1978 | 0_2_004F1978 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_00509AB5 | 0_2_00509AB5 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_00557DDB | 0_2_00557DDB |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004F1D90 | 0_2_004F1D90 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004FBDA6 | 0_2_004FBDA6 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004DDF00 | 0_2_004DDF00 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_004E3FE0 | 0_2_004E3FE0 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_017EE6B8 | 0_2_017EE6B8 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003CE6A0 | 2_2_003CE6A0 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003ED975 | 2_2_003ED975 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003CFCE0 | 2_2_003CFCE0 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003E21C5 | 2_2_003E21C5 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003F62D2 | 2_2_003F62D2 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_004403DA | 2_2_004403DA |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003F242E | 2_2_003F242E |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003E25FA | 2_2_003E25FA |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_0041E616 | 2_2_0041E616 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003D66E1 | 2_2_003D66E1 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003F878F | 2_2_003F878F |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_00440857 | 2_2_00440857 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003D8808 | 2_2_003D8808 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003F6844 | 2_2_003F6844 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_00428889 | 2_2_00428889 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003ECB21 | 2_2_003ECB21 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003F6DB6 | 2_2_003F6DB6 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003D6F9E | 2_2_003D6F9E |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003D3030 | 2_2_003D3030 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003E3187 | 2_2_003E3187 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003EF1D9 | 2_2_003EF1D9 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003C1287 | 2_2_003C1287 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003E1484 | 2_2_003E1484 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003D5520 | 2_2_003D5520 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003E7696 | 2_2_003E7696 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003D5760 | 2_2_003D5760 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003E1978 | 2_2_003E1978 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003F9AB5 | 2_2_003F9AB5 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003EBDA6 | 2_2_003EBDA6 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_00447DDB | 2_2_00447DDB |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003E1D90 | 2_2_003E1D90 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003CDF00 | 2_2_003CDF00 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_003D3FE0 | 2_2_003D3FE0 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_00E2BA98 | 2_2_00E2BA98 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_0148C530 | 3_2_0148C530 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_01489480 | 3_2_01489480 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_01481A4B | 3_2_01481A4B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_0148C521 | 3_2_0148C521 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_01482DD1 | 3_2_01482DD1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_0148946F | 3_2_0148946F |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 6_2_015EBB38 | 6_2_015EBB38 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_024AC530 | 9_2_024AC530 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_024A2DD1 | 9_2_024A2DD1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_024A9480 | 9_2_024A9480 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_024A19B8 | 9_2_024A19B8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_024AC521 | 9_2_024AC521 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_024A946F | 9_2_024A946F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D01400 | 9_2_04D01400 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0B678 | 9_2_04D0B678 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D06138 | 9_2_04D06138 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0BC60 | 9_2_04D0BC60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0AF00 | 9_2_04D0AF00 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D089E0 | 9_2_04D089E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D05AD8 | 9_2_04D05AD8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D00AB8 | 9_2_04D00AB8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0F458 | 9_2_04D0F458 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0F44F | 9_2_04D0F44F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D07423 | 9_2_04D07423 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D07428 | 9_2_04D07428 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D08583 | 9_2_04D08583 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D08588 | 9_2_04D08588 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0451B | 9_2_04D0451B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D04520 | 9_2_04D04520 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D05680 | 9_2_04D05680 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0E750 | 9_2_04D0E750 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0E743 | 9_2_04D0E743 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0F000 | 9_2_04D0F000 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0602A | 9_2_04D0602A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D08130 | 9_2_04D08130 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D08123 | 9_2_04D08123 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0E2F8 | 9_2_04D0E2F8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0E2EB | 9_2_04D0E2EB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D05228 | 9_2_04D05228 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D013FB | 9_2_04D013FB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D00330 | 9_2_04D00330 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0032B | 9_2_04D0032B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D00CD3 | 9_2_04D00CD3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D07CD3 | 9_2_04D07CD3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D00CD8 | 9_2_04D00CD8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D07CD8 | 9_2_04D07CD8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D04DD0 | 9_2_04D04DD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D04DCB | 9_2_04D04DCB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D06FD0 | 9_2_04D06FD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D06FCD | 9_2_04D06FCD |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0EFF7 | 9_2_04D0EFF7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D07880 | 9_2_04D07880 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0F8B0 | 9_2_04D0F8B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0F8A4 | 9_2_04D0F8A4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0787B | 9_2_04D0787B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D04978 | 9_2_04D04978 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0496F | 9_2_04D0496F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D03BC3 | 9_2_04D03BC3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0EB9F | 9_2_04D0EB9F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_04D0EBA8 | 9_2_04D0EBA8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C9118 | 9_2_052C9118 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C8030 | 9_2_052C8030 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C60D8 | 9_2_052C60D8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C7390 | 9_2_052C7390 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C6D48 | 9_2_052C6D48 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C79E0 | 9_2_052C79E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C358B | 9_2_052C358B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C3598 | 9_2_052C3598 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C15EB | 9_2_052C15EB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C15F8 | 9_2_052C15F8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C2427 | 9_2_052C2427 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C2438 | 9_2_052C2438 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C048F | 9_2_052C048F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C0498 | 9_2_052C0498 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C8668 | 9_2_052C8668 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C8678 | 9_2_052C8678 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C46ED | 9_2_052C46ED |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C46F8 | 9_2_052C46F8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C3133 | 9_2_052C3133 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C9108 | 9_2_052C9108 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C3140 | 9_2_052C3140 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C11A0 | 9_2_052C11A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C1195 | 9_2_052C1195 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C51E8 | 9_2_052C51E8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C51DF | 9_2_052C51DF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C8024 | 9_2_052C8024 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C0037 | 9_2_052C0037 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C0040 | 9_2_052C0040 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C60CF | 9_2_052C60CF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C7380 | 9_2_052C7380 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C42A0 | 9_2_052C42A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C4290 | 9_2_052C4290 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C0D3F | 9_2_052C0D3F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C6D37 | 9_2_052C6D37 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C0D48 | 9_2_052C0D48 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C2CE8 | 9_2_052C2CE8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C2CDB | 9_2_052C2CDB |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C3E39 | 9_2_052C3E39 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C3E48 | 9_2_052C3E48 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C1EA8 | 9_2_052C1EA8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C1E9B | 9_2_052C1E9B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C39E1 | 9_2_052C39E1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C39F0 | 9_2_052C39F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C79D0 | 9_2_052C79D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C2880 | 9_2_052C2880 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C2890 | 9_2_052C2890 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C08E7 | 9_2_052C08E7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C08F0 | 9_2_052C08F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C4B41 | 9_2_052C4B41 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C4B50 | 9_2_052C4B50 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C1A40 | 9_2_052C1A40 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 9_2_052C1A50 | 9_2_052C1A50 |
Source: 2.2.juvenile.exe.510000.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 2.2.juvenile.exe.510000.1.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 3.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 3.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 6.2.juvenile.exe.1390000.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 6.2.juvenile.exe.1390000.1.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 2.2.juvenile.exe.510000.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 2.2.juvenile.exe.510000.1.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 6.2.juvenile.exe.1390000.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 6.2.juvenile.exe.1390000.1.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 00000006.00000002.2340015646.0000000001390000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000006.00000002.2340015646.0000000001390000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 00000002.00000002.2191566788.0000000000510000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000002.00000002.2191566788.0000000000510000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 00000003.00000002.3374747417.0000000000402000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: juvenile.exe PID: 6552, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: RegSvcs.exe PID: 4328, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: juvenile.exe PID: 4196, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0053445A GetFileAttributesW,FindFirstFileW,FindClose, | 0_2_0053445A |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0053C6D1 FindFirstFileW,FindClose, | 0_2_0053C6D1 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0053C75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 0_2_0053C75C |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0053EF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_0053EF95 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0053F0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_0053F0F2 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0053F3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_0053F3F3 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_005337EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_005337EF |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_00533B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_00533B12 |
Source: C:\Users\user\Desktop\41570002689_20220814_05352297_HesapOzeti.exe | Code function: 0_2_0053BCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_0053BCBC |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_0042445A GetFileAttributesW,FindFirstFileW,FindClose, | 2_2_0042445A |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_0042C6D1 FindFirstFileW,FindClose, | 2_2_0042C6D1 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_0042C75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 2_2_0042C75C |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_0042EF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 2_2_0042EF95 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_0042F0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 2_2_0042F0F2 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_0042F3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 2_2_0042F3F3 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_004237EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 2_2_004237EF |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_00423B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 2_2_00423B12 |
Source: C:\Users\user\AppData\Local\nonplacental\juvenile.exe | Code function: 2_2_0042BCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 2_2_0042BCBC |