Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://127.0.0.1:27060 |
Source: GHXsFkoroU.exe, 00000000.00000003.2121400725.0000000001449000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://store.steampowered.com/account/cookiepreferences/ |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121400725.0000000001449000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://store.steampowered.com/privacy_agreement/ |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121400725.0000000001449000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://store.steampowered.com/subscriber_agreement/ |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.valvesoftware.com/legal.htm |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://api.steampowered.c |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://api.steampowered.com/ |
Source: GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://avatars.fastly.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://cdn.fastly.steam |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://checkout.steampowered. |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steams |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamst |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/ |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/css/ |
Source: GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/css/applications/community/main.css?v=Lj6X7NKU |
Source: GHXsFkoroU.exe, 00000000.00000003.2121400725.0000000001449000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/css/applications/community/main.css?v=Lj6X7NKUMfzk&a |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/css/globalv2.css?v=hzEgqbtRcI5V&l=english&_c |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/css/promo/summer2017/stickers.css?v=Ncr6N09yZIap& |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/css/skin_1/header.css?v=EM4kCu67DNda&l=english&a |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/css/skin_1/modalContent.css?v=WXAusLHclDIt&l=eng |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/css/skin_1/profilev2.css?v=fe66ET2uI50l&l=englis |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121400725.0000000001449000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/images/skin_1/arrowDn9x5.gif |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121400725.0000000001449000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1 |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121400725.0000000001449000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6 |
Source: GHXsFkoroU.exe, 00000000.00000003.2121400725.0000000001449000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/javascript/applications/community/main.js?v=_92TWn81 |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121400725.0000000001449000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/javascript/applications/community/manifest.js?v=FRRi |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/javascript/global.js?v=jWc2JLWHx5Kn&l=english&am |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=gQHVlrK4-jX-&l |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/javascript/modalContent.js?v=uqf5ttWTRe7l&l=engl |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/javascript/modalv2.js?v=zBXEuexVQ0FZ&l=english&a |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/javascript/profile.js?v=GeQ6v03mWpAc&l=english&a |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/javascript/promo/stickers.js?v=CcLRHsa04otQ&l=en |
Source: GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/javascript/prototype-1.7.js?v=npJElBnrEO6W&l=eng |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/javascript/reportedcontent.js?v=-lZqrarogJr8&l=e |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=pbdAKOcDIgbC |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/javascript/webui/clientcom.js?v=oOCAGrkRfpQ6&l=e |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/shared/css/buttons.css?v=qhQgyjWi6LgJ&l=english& |
Source: GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/shared/css/motiva_sans.css?v=-yZgCk0Nu7kH&l=engl |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/shared/css/shared_global.css?v=wuA4X_n5-mo0&l=en |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/shared/css/shared_responsive.css?v=JL1e4uQSrVGe& |
Source: GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016 |
Source: GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/shared/images/responsive/header_logo.png |
Source: GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png |
Source: GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/shared/jav |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/shared/javascript/auth_refresh.js?v=w6QbwI-5-j2S& |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/shared/javascript/shared_global.js?v=Gr6TbGRvDtNE&am |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=tvQ |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.fastly.steamstatic.com/public/shared/javascript/tooltip.js?v=QYkT4eS5mbTN&l=en |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://help.steampo |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://help.steampowered.com/en/ |
Source: GHXsFkoroU.exe, 00000000.00000003.2121400725.0000000001455000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lev-tolstoi.com/ |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lev-tolstoi.com/.valvea |
Source: GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001452000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001451000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lev-tolstoi.com/api |
Source: GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lev-tolstoi.com/api- |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lev-tolstoi.com/f |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lev-tolstoi.com/l1 |
Source: GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001432000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2135887360.0000000001432000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lev-tolstoi.com/pi |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.steampowereV |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lv.queniujq.cn |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://player.vi |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://s.ytimg.com; |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://sketchfab.com |
Source: GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steamcommunity.com/ |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steamcommunity.com/?subsection=broadcasts |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steamcommunity.com/discussions/ |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steamcommunity.com/l |
Source: GHXsFkoroU.exe, 00000000.00000003.2121400725.0000000001449000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org |
Source: GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900 |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steamcommunity.com/market/ |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steamcommunity.com/my/wishlist/ |
Source: GHXsFkoroU.exe, 00000000.00000003.2121400725.0000000001449000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steamcommunity.com/profiles/76561199724331900/badges |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001446000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2135887360.0000000001446000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steamcommunity.com/profiles/76561199724331900/inventory/ |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steamcommunity.com/workshop/ |
Source: GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://store.steampowered.com/ |
Source: GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://store.steampowered.com/about/ |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://store.steampowered.com/explore/ |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121400725.0000000001449000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://store.steampowered.com/legal/ |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://store.steampowered.com/mobile |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://store.steampowered.com/news/ |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://store.steampowered.com/points/shop/ |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://store.steampowered.com/privacy_agreement/ |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://store.steampowered.com/stats/ |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://store.steampowered.com/steam_refunds/ |
Source: GHXsFkoroU.exe, 00000000.00000002.2136201793.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130555729.00000000014BA000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://store.steampowered.com/subscriber_agreement/ |
Source: GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/recaptcha/ |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.gstatic.com/recaptcha/ |
Source: GHXsFkoroU.exe, 00000000.00000003.2130332071.00000000014BD000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121349074.00000000014B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback |
Source: GHXsFkoroU.exe, 00000000.00000003.2130625918.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2121466598.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000002.2136088469.0000000001469000.00000004.00000020.00020000.00000000.sdmp, GHXsFkoroU.exe, 00000000.00000003.2130362992.0000000001469000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.youtube.com |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00718600 | 0_2_00718600 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0071B100 | 0_2_0071B100 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0088E09C | 0_2_0088E09C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0078E063 | 0_2_0078E063 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007FA058 | 0_2_007FA058 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00798053 | 0_2_00798053 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008780AA | 0_2_008780AA |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008620A8 | 0_2_008620A8 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0086E0B2 | 0_2_0086E0B2 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00772033 | 0_2_00772033 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F403A | 0_2_007F403A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007E8033 | 0_2_007E8033 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008480D1 | 0_2_008480D1 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0080A0FB | 0_2_0080A0FB |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0073C0E6 | 0_2_0073C0E6 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007260E9 | 0_2_007260E9 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0082C019 | 0_2_0082C019 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00884016 | 0_2_00884016 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007860DD | 0_2_007860DD |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A00D3 | 0_2_007A00D3 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F00D5 | 0_2_007F00D5 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00840036 | 0_2_00840036 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0073A0CA | 0_2_0073A0CA |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00826039 | 0_2_00826039 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0081A03E | 0_2_0081A03E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007AE0B2 | 0_2_007AE0B2 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0087004F | 0_2_0087004F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0077E0A7 | 0_2_0077E0A7 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0073C09E | 0_2_0073C09E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007CE08D | 0_2_007CE08D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0079C17E | 0_2_0079C17E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007E4173 | 0_2_007E4173 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00774179 | 0_2_00774179 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00868196 | 0_2_00868196 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00716160 | 0_2_00716160 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00728169 | 0_2_00728169 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0073C09E | 0_2_0073C09E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0081E1E5 | 0_2_0081E1E5 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008561E0 | 0_2_008561E0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0079A10C | 0_2_0079A10C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008221F5 | 0_2_008221F5 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0084C106 | 0_2_0084C106 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007C01FF | 0_2_007C01FF |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007B41ED | 0_2_007B41ED |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007941E2 | 0_2_007941E2 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F41E2 | 0_2_007F41E2 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007921D2 | 0_2_007921D2 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00804138 | 0_2_00804138 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007C41C6 | 0_2_007C41C6 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00886133 | 0_2_00886133 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007381CC | 0_2_007381CC |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0083A141 | 0_2_0083A141 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0077C1B0 | 0_2_0077C1B0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0084E14D | 0_2_0084E14D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0084A14F | 0_2_0084A14F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00888159 | 0_2_00888159 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0087215B | 0_2_0087215B |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0078418B | 0_2_0078418B |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0073E180 | 0_2_0073E180 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00714270 | 0_2_00714270 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0082028C | 0_2_0082028C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00816293 | 0_2_00816293 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00806298 | 0_2_00806298 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0086629E | 0_2_0086629E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00880291 | 0_2_00880291 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008842A8 | 0_2_008842A8 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008022B0 | 0_2_008022B0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008342BD | 0_2_008342BD |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007AC233 | 0_2_007AC233 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007EE237 | 0_2_007EE237 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A0236 | 0_2_007A0236 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0072E220 | 0_2_0072E220 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008102D9 | 0_2_008102D9 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008182DA | 0_2_008182DA |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008542E5 | 0_2_008542E5 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00778210 | 0_2_00778210 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008462EA | 0_2_008462EA |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007EC208 | 0_2_007EC208 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A6200 | 0_2_007A6200 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008382F9 | 0_2_008382F9 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007B02D9 | 0_2_007B02D9 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007342D0 | 0_2_007342D0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007E22DD | 0_2_007E22DD |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00858256 | 0_2_00858256 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00844252 | 0_2_00844252 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0086E279 | 0_2_0086E279 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00782379 | 0_2_00782379 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A8377 | 0_2_007A8377 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0082E38D | 0_2_0082E38D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F236C | 0_2_007F236C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007CA356 | 0_2_007CA356 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00796355 | 0_2_00796355 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0085A3B9 | 0_2_0085A3B9 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A233B | 0_2_007A233B |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007B6339 | 0_2_007B6339 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A6339 | 0_2_007A6339 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0083C3C0 | 0_2_0083C3C0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00788330 | 0_2_00788330 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F6337 | 0_2_007F6337 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008823C5 | 0_2_008823C5 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0079032E | 0_2_0079032E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A4326 | 0_2_007A4326 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00792327 | 0_2_00792327 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008643D8 | 0_2_008643D8 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0079E30D | 0_2_0079E30D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008323F7 | 0_2_008323F7 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0085C3F3 | 0_2_0085C3F3 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007863FA | 0_2_007863FA |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0087A30F | 0_2_0087A30F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00808317 | 0_2_00808317 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0077A3EF | 0_2_0077A3EF |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007BA3E3 | 0_2_007BA3E3 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007383D8 | 0_2_007383D8 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007FE3D2 | 0_2_007FE3D2 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00836342 | 0_2_00836342 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007DA3BA | 0_2_007DA3BA |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0087E34A | 0_2_0087E34A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00840350 | 0_2_00840350 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0080C35F | 0_2_0080C35F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0087637D | 0_2_0087637D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00772471 | 0_2_00772471 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00750460 | 0_2_00750460 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0078E46D | 0_2_0078E46D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008CA494 | 0_2_008CA494 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0084C49E | 0_2_0084C49E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0081449A | 0_2_0081449A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007EC463 | 0_2_007EC463 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0078C466 | 0_2_0078C466 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007AE45E | 0_2_007AE45E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008624AB | 0_2_008624AB |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0074A440 | 0_2_0074A440 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007D0443 | 0_2_007D0443 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0086A4D6 | 0_2_0086A4D6 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008784DC | 0_2_008784DC |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007B241F | 0_2_007B241F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0081E4EB | 0_2_0081E4EB |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007B4416 | 0_2_007B4416 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A6414 | 0_2_007A6414 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007E840F | 0_2_007E840F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00776409 | 0_2_00776409 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007BE4FC | 0_2_007BE4FC |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007E44F6 | 0_2_007E44F6 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00872415 | 0_2_00872415 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007324E0 | 0_2_007324E0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007C04E2 | 0_2_007C04E2 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0077E4E8 | 0_2_0077E4E8 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0081C421 | 0_2_0081C421 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007D24DB | 0_2_007D24DB |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007804CC | 0_2_007804CC |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007304C6 | 0_2_007304C6 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00860443 | 0_2_00860443 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008AE44C | 0_2_008AE44C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0088E45F | 0_2_0088E45F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0085246A | 0_2_0085246A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0079E48B | 0_2_0079E48B |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0083458E | 0_2_0083458E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F8570 | 0_2_007F8570 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0078656A | 0_2_0078656A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00734560 | 0_2_00734560 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007C256A | 0_2_007C256A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0084A5AC | 0_2_0084A5AC |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008565AE | 0_2_008565AE |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008CC5A2 | 0_2_008CC5A2 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0079A54B | 0_2_0079A54B |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007AA541 | 0_2_007AA541 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007BC531 | 0_2_007BC531 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0073C53C | 0_2_0073C53C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008705D4 | 0_2_008705D4 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008005D4 | 0_2_008005D4 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007D6528 | 0_2_007D6528 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007DE518 | 0_2_007DE518 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A651C | 0_2_007A651C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008425E8 | 0_2_008425E8 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0078450C | 0_2_0078450C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007D45FD | 0_2_007D45FD |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007165F0 | 0_2_007165F0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007985F1 | 0_2_007985F1 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007C65F5 | 0_2_007C65F5 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007AC5E2 | 0_2_007AC5E2 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0085851D | 0_2_0085851D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0074A5D4 | 0_2_0074A5D4 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0082E521 | 0_2_0082E521 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007C85D7 | 0_2_007C85D7 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0078C5D6 | 0_2_0078C5D6 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0083A52D | 0_2_0083A52D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007EC5CC | 0_2_007EC5CC |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00822535 | 0_2_00822535 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008DE541 | 0_2_008DE541 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00866548 | 0_2_00866548 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0074C5A0 | 0_2_0074C5A0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007DC59B | 0_2_007DC59B |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008D4564 | 0_2_008D4564 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F467D | 0_2_007F467D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A4679 | 0_2_007A4679 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00850694 | 0_2_00850694 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00782664 | 0_2_00782664 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0081869D | 0_2_0081869D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0086C6A7 | 0_2_0086C6A7 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00748650 | 0_2_00748650 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008406A2 | 0_2_008406A2 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0077C65E | 0_2_0077C65E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00796657 | 0_2_00796657 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007C2648 | 0_2_007C2648 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0087C6C6 | 0_2_0087C6C6 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0072E630 | 0_2_0072E630 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0085A6C1 | 0_2_0085A6C1 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008106D2 | 0_2_008106D2 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0083E6DA | 0_2_0083E6DA |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00794624 | 0_2_00794624 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008546E9 | 0_2_008546E9 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008086ED | 0_2_008086ED |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007EA603 | 0_2_007EA603 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0081A602 | 0_2_0081A602 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007506F0 | 0_2_007506F0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00888629 | 0_2_00888629 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007346D0 | 0_2_007346D0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0080462D | 0_2_0080462D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A06C3 | 0_2_007A06C3 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0085E66D | 0_2_0085E66D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0088467A | 0_2_0088467A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0071E687 | 0_2_0071E687 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00824788 | 0_2_00824788 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00722750 | 0_2_00722750 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008747AE | 0_2_008747AE |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008207B3 | 0_2_008207B3 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007C874E | 0_2_007C874E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008C87C1 | 0_2_008C87C1 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007FA732 | 0_2_007FA732 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007D8721 | 0_2_007D8721 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008467D8 | 0_2_008467D8 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0081C7DF | 0_2_0081C7DF |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007EE70B | 0_2_007EE70B |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008527FC | 0_2_008527FC |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007887FD | 0_2_007887FD |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A67E8 | 0_2_007A67E8 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0082A711 | 0_2_0082A711 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007D27DA | 0_2_007D27DA |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A87C8 | 0_2_007A87C8 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00864748 | 0_2_00864748 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0082E75D | 0_2_0082E75D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00792791 | 0_2_00792791 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0084E776 | 0_2_0084E776 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0088A88F | 0_2_0088A88F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00816893 | 0_2_00816893 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0080C894 | 0_2_0080C894 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007CE85D | 0_2_007CE85D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0084A8AE | 0_2_0084A8AE |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0071C840 | 0_2_0071C840 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A0846 | 0_2_007A0846 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008648C5 | 0_2_008648C5 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008308E1 | 0_2_008308E1 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F6816 | 0_2_007F6816 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008708EE | 0_2_008708EE |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0085C8EA | 0_2_0085C8EA |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0079880D | 0_2_0079880D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007CC80A | 0_2_007CC80A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F2809 | 0_2_007F2809 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0088C81A | 0_2_0088C81A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0088281D | 0_2_0088281D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00876820 | 0_2_00876820 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007D68CA | 0_2_007D68CA |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007488B0 | 0_2_007488B0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007868BD | 0_2_007868BD |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007E68B7 | 0_2_007E68B7 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007C08B1 | 0_2_007C08B1 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0072C8A0 | 0_2_0072C8A0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007AE892 | 0_2_007AE892 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00884874 | 0_2_00884874 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00794975 | 0_2_00794975 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0072E960 | 0_2_0072E960 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00838996 | 0_2_00838996 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0088899E | 0_2_0088899E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007D495C | 0_2_007D495C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0086C9AC | 0_2_0086C9AC |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F894D | 0_2_007F894D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007DE93B | 0_2_007DE93B |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008849D0 | 0_2_008849D0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00736910 | 0_2_00736910 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A8913 | 0_2_007A8913 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00880909 | 0_2_00880909 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007989FC | 0_2_007989FC |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0079A9EB | 0_2_0079A9EB |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007509E0 | 0_2_007509E0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00806915 | 0_2_00806915 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0073C9EB | 0_2_0073C9EB |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007EA9C2 | 0_2_007EA9C2 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007CE9AF | 0_2_007CE9AF |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0077C9AA | 0_2_0077C9AA |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007C499E | 0_2_007C499E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00858967 | 0_2_00858967 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008D297F | 0_2_008D297F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007B4983 | 0_2_007B4983 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A6A70 | 0_2_007A6A70 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007ECA6C | 0_2_007ECA6C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0085AAA5 | 0_2_0085AAA5 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00876AA5 | 0_2_00876AA5 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007E2A58 | 0_2_007E2A58 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0086AAA0 | 0_2_0086AAA0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00774A45 | 0_2_00774A45 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0074CA40 | 0_2_0074CA40 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0080AAB6 | 0_2_0080AAB6 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0078CA47 | 0_2_0078CA47 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00850ABA | 0_2_00850ABA |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00790A3E | 0_2_00790A3E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007B8A1B | 0_2_007B8A1B |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007DAA07 | 0_2_007DAA07 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0083AA06 | 0_2_0083AA06 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007ACAE6 | 0_2_007ACAE6 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0084AA22 | 0_2_0084AA22 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00820A33 | 0_2_00820A33 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00796AB8 | 0_2_00796AB8 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00802A43 | 0_2_00802A43 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00834A44 | 0_2_00834A44 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00872A4E | 0_2_00872A4E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00738ABC | 0_2_00738ABC |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007DCA80 | 0_2_007DCA80 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00836A7E | 0_2_00836A7E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00852B8D | 0_2_00852B8D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A2B5E | 0_2_007A2B5E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0083CBA9 | 0_2_0083CBA9 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0071AB40 | 0_2_0071AB40 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007BAB48 | 0_2_007BAB48 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00834BBA | 0_2_00834BBA |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0084CBBF | 0_2_0084CBBF |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0083EBBF | 0_2_0083EBBF |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007B0B24 | 0_2_007B0B24 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00868BD9 | 0_2_00868BD9 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00854BE5 | 0_2_00854BE5 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F0B1D | 0_2_007F0B1D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00728B1B | 0_2_00728B1B |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007B4B0B | 0_2_007B4B0B |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00886B09 | 0_2_00886B09 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007FEBFB | 0_2_007FEBFB |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00770BFB | 0_2_00770BFB |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00838B17 | 0_2_00838B17 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0085EB12 | 0_2_0085EB12 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00804B1A | 0_2_00804B1A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00846B28 | 0_2_00846B28 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0080EB3F | 0_2_0080EB3F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00714BA0 | 0_2_00714BA0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00844B5C | 0_2_00844B5C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0084EB67 | 0_2_0084EB67 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00776B9E | 0_2_00776B9E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00856B6C | 0_2_00856B6C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0078AB93 | 0_2_0078AB93 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00788B88 | 0_2_00788B88 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0072EB80 | 0_2_0072EB80 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0088EB74 | 0_2_0088EB74 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0086CC8C | 0_2_0086CC8C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00782C77 | 0_2_00782C77 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0088AC96 | 0_2_0088AC96 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007E0C5F | 0_2_007E0C5F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00880CBE | 0_2_00880CBE |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F8C3F | 0_2_007F8C3F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F2C3C | 0_2_007F2C3C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0082CCCB | 0_2_0082CCCB |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007CAC28 | 0_2_007CAC28 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00862CD0 | 0_2_00862CD0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0087CCDD | 0_2_0087CCDD |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F4C18 | 0_2_007F4C18 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00870CED | 0_2_00870CED |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0087ACE9 | 0_2_0087ACE9 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007DECF6 | 0_2_007DECF6 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0081AC1F | 0_2_0081AC1F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00780CD1 | 0_2_00780CD1 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0082AC2E | 0_2_0082AC2E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007D6CCE | 0_2_007D6CCE |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00806C35 | 0_2_00806C35 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0079ECB3 | 0_2_0079ECB3 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00724CA0 | 0_2_00724CA0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0081EC56 | 0_2_0081EC56 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007D2CA7 | 0_2_007D2CA7 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F6C9E | 0_2_007F6C9E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00784C96 | 0_2_00784C96 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00828D83 | 0_2_00828D83 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00818D84 | 0_2_00818D84 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007BED77 | 0_2_007BED77 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00804D96 | 0_2_00804D96 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007DCD65 | 0_2_007DCD65 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0073CD5E | 0_2_0073CD5E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007CED4B | 0_2_007CED4B |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0073CD4C | 0_2_0073CD4C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A8D3D | 0_2_007A8D3D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008C6DC6 | 0_2_008C6DC6 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007B8D2F | 0_2_007B8D2F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00750D20 | 0_2_00750D20 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00800DD5 | 0_2_00800DD5 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00736D2E | 0_2_00736D2E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00844DE2 | 0_2_00844DE2 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00798D14 | 0_2_00798D14 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00786D02 | 0_2_00786D02 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00832DF8 | 0_2_00832DF8 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0074CDF0 | 0_2_0074CDF0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00876D1F | 0_2_00876D1F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0077CDD1 | 0_2_0077CDD1 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A2DCB | 0_2_007A2DCB |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0085CD45 | 0_2_0085CD45 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00810D59 | 0_2_00810D59 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007C4DA1 | 0_2_007C4DA1 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0073EE63 | 0_2_0073EE63 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007B4E6F | 0_2_007B4E6F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0080AE95 | 0_2_0080AE95 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0085AE9D | 0_2_0085AE9D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0087EE9A | 0_2_0087EE9A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00732E6D | 0_2_00732E6D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00730E6C | 0_2_00730E6C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0085EEA4 | 0_2_0085EEA4 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007FCE49 | 0_2_007FCE49 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00840EC7 | 0_2_00840EC7 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0078AE2D | 0_2_0078AE2D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0077AE21 | 0_2_0077AE21 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0079AE2E | 0_2_0079AE2E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007BAE23 | 0_2_007BAE23 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0078EE27 | 0_2_0078EE27 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00872EE1 | 0_2_00872EE1 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00884E0A | 0_2_00884E0A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007D0EF5 | 0_2_007D0EF5 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007A4EE8 | 0_2_007A4EE8 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00808E14 | 0_2_00808E14 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00816E29 | 0_2_00816E29 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007AEECC | 0_2_007AEECC |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00712EB0 | 0_2_00712EB0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0072AEB0 | 0_2_0072AEB0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00780EB1 | 0_2_00780EB1 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00748EA0 | 0_2_00748EA0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00822E60 | 0_2_00822E60 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00882E6A | 0_2_00882E6A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007E2E96 | 0_2_007E2E96 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0082AE77 | 0_2_0082AE77 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0086AE71 | 0_2_0086AE71 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00824F8B | 0_2_00824F8B |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00776F78 | 0_2_00776F78 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00802F8F | 0_2_00802F8F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00864F91 | 0_2_00864F91 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F0F67 | 0_2_007F0F67 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008DAF93 | 0_2_008DAF93 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00842F9B | 0_2_00842F9B |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00726F52 | 0_2_00726F52 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0082CFCE | 0_2_0082CFCE |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007ECF2A | 0_2_007ECF2A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0088CFD3 | 0_2_0088CFD3 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00796F0F | 0_2_00796F0F |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007E8F09 | 0_2_007E8F09 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007C2F04 | 0_2_007C2F04 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008D0FF3 | 0_2_008D0FF3 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0085CFFB | 0_2_0085CFFB |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F8FF8 | 0_2_007F8FF8 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00838F1B | 0_2_00838F1B |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0084EF27 | 0_2_0084EF27 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007B2FC7 | 0_2_007B2FC7 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0083AF47 | 0_2_0083AF47 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007FEFB4 | 0_2_007FEFB4 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007FAFAA | 0_2_007FAFAA |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00874F60 | 0_2_00874F60 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0082AF6A | 0_2_0082AF6A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0077CF82 | 0_2_0077CF82 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00820F74 | 0_2_00820F74 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0088EF7E | 0_2_0088EF7E |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007C6F86 | 0_2_007C6F86 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007D9075 | 0_2_007D9075 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0083F093 | 0_2_0083F093 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008390A0 | 0_2_008390A0 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007E7054 | 0_2_007E7054 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0079F041 | 0_2_0079F041 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00773035 | 0_2_00773035 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0082B0C8 | 0_2_0082B0C8 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007C1037 | 0_2_007C1037 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0071D021 | 0_2_0071D021 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008470D2 | 0_2_008470D2 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007D301D | 0_2_007D301D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0072D003 | 0_2_0072D003 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007E3008 | 0_2_007E3008 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00857017 | 0_2_00857017 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007750E3 | 0_2_007750E3 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007BD0DB | 0_2_007BD0DB |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0085902A | 0_2_0085902A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00869034 | 0_2_00869034 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0086D03A | 0_2_0086D03A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007E10C3 | 0_2_007E10C3 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F70B5 | 0_2_007F70B5 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0081F071 | 0_2_0081F071 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0081307D | 0_2_0081307D |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0087B197 | 0_2_0087B197 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F5164 | 0_2_007F5164 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007BB164 | 0_2_007BB164 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007CF15C | 0_2_007CF15C |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007DD159 | 0_2_007DD159 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007DB150 | 0_2_007DB150 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0081B1B7 | 0_2_0081B1B7 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008851C3 | 0_2_008851C3 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_0084F1CA | 0_2_0084F1CA |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008611C8 | 0_2_008611C8 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008171D1 | 0_2_008171D1 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008151D3 | 0_2_008151D3 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007FF11A | 0_2_007FF11A |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008451E1 | 0_2_008451E1 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_007F3113 | 0_2_007F3113 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00795102 | 0_2_00795102 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_008071FE | 0_2_008071FE |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | Code function: 0_2_00881108 | 0_2_00881108 |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 76911A second address: 768A64 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ecx 0x00000007 push eax 0x00000008 js 00007F991CD146A1h 0x0000000e nop 0x0000000f jmp 00007F991CD1469Ch 0x00000014 push dword ptr [ebp+122D0C69h] 0x0000001a mov dword ptr [ebp+122D238Bh], edi 0x00000020 call dword ptr [ebp+122D2D14h] 0x00000026 pushad 0x00000027 xor dword ptr [ebp+122D1BB6h], esi 0x0000002d xor eax, eax 0x0000002f stc 0x00000030 mov edx, dword ptr [esp+28h] 0x00000034 mov dword ptr [ebp+122D1BBEh], esi 0x0000003a mov dword ptr [ebp+122D38E9h], eax 0x00000040 jbe 00007F991CD1469Ch 0x00000046 mov esi, 0000003Ch 0x0000004b jmp 00007F991CD1469Ch 0x00000050 add esi, dword ptr [esp+24h] 0x00000054 cmc 0x00000055 lodsw 0x00000057 clc 0x00000058 cmc 0x00000059 add eax, dword ptr [esp+24h] 0x0000005d cmc 0x0000005e mov ebx, dword ptr [esp+24h] 0x00000062 or dword ptr [ebp+122D1BB6h], edx 0x00000068 nop 0x00000069 jng 00007F991CD1469Eh 0x0000006f push eax 0x00000070 jg 00007F991CD146A4h 0x00000076 pushad 0x00000077 push eax 0x00000078 push edx 0x00000079 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8D59F4 second address: 8D5A05 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop esi 0x00000007 push eax 0x00000008 push edx 0x00000009 push esi 0x0000000a jp 00007F991CEDCA66h 0x00000010 pop esi 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8D5A05 second address: 8D5A0F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jnp 00007F991CD14696h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E2D3D second address: 8E2D58 instructions: 0x00000000 rdtsc 0x00000002 jnc 00007F991CEDCA66h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a jmp 00007F991CEDCA6Dh 0x0000000f push eax 0x00000010 push edx 0x00000011 pushad 0x00000012 popad 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E2D58 second address: 8E2D5E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E2D5E second address: 8E2D82 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 pushad 0x00000008 jp 00007F991CEDCA6Ah 0x0000000e push edx 0x0000000f ja 00007F991CEDCA66h 0x00000015 pop edx 0x00000016 push eax 0x00000017 push edx 0x00000018 pushad 0x00000019 popad 0x0000001a jns 00007F991CEDCA66h 0x00000020 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E2D82 second address: 8E2D86 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E2D86 second address: 8E2DA9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F991CEDCA70h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007F991CEDCA6Bh 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E2DA9 second address: 8E2DAD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E2DAD second address: 8E2DB3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E2EF5 second address: 8E2F24 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 pop edi 0x00000006 push eax 0x00000007 push edx 0x00000008 jnl 00007F991CD146A2h 0x0000000e jmp 00007F991CD146A5h 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E2F24 second address: 8E2F2E instructions: 0x00000000 rdtsc 0x00000002 jne 00007F991CEDCA72h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E2F2E second address: 8E2F34 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E3069 second address: 8E307B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 jmp 00007F991CEDCA6Dh 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E6210 second address: 8E6214 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E6214 second address: 768A64 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CEDCA72h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xor dword ptr [esp], 78BA4FDFh 0x00000010 jmp 00007F991CEDCA6Bh 0x00000015 push dword ptr [ebp+122D0C69h] 0x0000001b movzx esi, ax 0x0000001e call dword ptr [ebp+122D2D14h] 0x00000024 pushad 0x00000025 xor dword ptr [ebp+122D1BB6h], esi 0x0000002b xor eax, eax 0x0000002d stc 0x0000002e mov edx, dword ptr [esp+28h] 0x00000032 mov dword ptr [ebp+122D1BBEh], esi 0x00000038 mov dword ptr [ebp+122D38E9h], eax 0x0000003e jbe 00007F991CEDCA6Ch 0x00000044 mov esi, 0000003Ch 0x00000049 jmp 00007F991CEDCA6Ch 0x0000004e add esi, dword ptr [esp+24h] 0x00000052 cmc 0x00000053 lodsw 0x00000055 clc 0x00000056 cmc 0x00000057 add eax, dword ptr [esp+24h] 0x0000005b cmc 0x0000005c mov ebx, dword ptr [esp+24h] 0x00000060 or dword ptr [ebp+122D1BB6h], edx 0x00000066 nop 0x00000067 jng 00007F991CEDCA6Eh 0x0000006d push eax 0x0000006e jg 00007F991CEDCA74h 0x00000074 pushad 0x00000075 push eax 0x00000076 push edx 0x00000077 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E62B0 second address: 8E633F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 jmp 00007F991CD1469Eh 0x0000000a popad 0x0000000b xor dword ptr [esp], 295FE73Eh 0x00000012 mov dx, A728h 0x00000016 push 00000003h 0x00000018 sub dh, FFFFFFC2h 0x0000001b push 00000000h 0x0000001d push 00000000h 0x0000001f push ecx 0x00000020 call 00007F991CD14698h 0x00000025 pop ecx 0x00000026 mov dword ptr [esp+04h], ecx 0x0000002a add dword ptr [esp+04h], 00000018h 0x00000032 inc ecx 0x00000033 push ecx 0x00000034 ret 0x00000035 pop ecx 0x00000036 ret 0x00000037 mov cx, 8611h 0x0000003b push 00000003h 0x0000003d push 00000000h 0x0000003f push edi 0x00000040 call 00007F991CD14698h 0x00000045 pop edi 0x00000046 mov dword ptr [esp+04h], edi 0x0000004a add dword ptr [esp+04h], 00000019h 0x00000052 inc edi 0x00000053 push edi 0x00000054 ret 0x00000055 pop edi 0x00000056 ret 0x00000057 push F4803C66h 0x0000005c pushad 0x0000005d jmp 00007F991CD146A8h 0x00000062 push eax 0x00000063 push edx 0x00000064 pushad 0x00000065 popad 0x00000066 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E633F second address: 8E6376 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CEDCA6Ah 0x00000007 pop edx 0x00000008 pop eax 0x00000009 popad 0x0000000a xor dword ptr [esp], 34803C66h 0x00000011 mov dword ptr [ebp+122D2D8Dh], edi 0x00000017 lea ebx, dword ptr [ebp+12451125h] 0x0000001d push eax 0x0000001e push eax 0x0000001f push edx 0x00000020 jl 00007F991CEDCA72h 0x00000026 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E6537 second address: 8E653B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E653B second address: 8E6565 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 jmp 00007F991CEDCA75h 0x0000000d mov eax, dword ptr [esp+04h] 0x00000011 push edi 0x00000012 push eax 0x00000013 push edx 0x00000014 jno 00007F991CEDCA66h 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E6565 second address: 8E658A instructions: 0x00000000 rdtsc 0x00000002 jp 00007F991CD14696h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edi 0x0000000b mov eax, dword ptr [eax] 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007F991CD146A6h 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E658A second address: 8E65B9 instructions: 0x00000000 rdtsc 0x00000002 jnp 00007F991CEDCA76h 0x00000008 jmp 00007F991CEDCA70h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f mov dword ptr [esp+04h], eax 0x00000013 push eax 0x00000014 push edx 0x00000015 push eax 0x00000016 push edx 0x00000017 jmp 00007F991CEDCA6Dh 0x0000001c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E65B9 second address: 8E65BF instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E65BF second address: 8E65F7 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push esi 0x00000004 pop esi 0x00000005 pushad 0x00000006 popad 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop eax 0x0000000b push ecx 0x0000000c and edi, dword ptr [ebp+122D2D40h] 0x00000012 pop edi 0x00000013 push 00000003h 0x00000015 mov edi, dword ptr [ebp+122D3831h] 0x0000001b push 00000000h 0x0000001d or dword ptr [ebp+122D2D33h], edx 0x00000023 push 00000003h 0x00000025 mov ecx, eax 0x00000027 push FEFF98F2h 0x0000002c pushad 0x0000002d je 00007F991CEDCA68h 0x00000033 push ecx 0x00000034 pop ecx 0x00000035 pushad 0x00000036 push eax 0x00000037 push edx 0x00000038 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E65F7 second address: 8E6620 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 popad 0x00000008 xor dword ptr [esp], 3EFF98F2h 0x0000000f mov dl, cl 0x00000011 lea ebx, dword ptr [ebp+12451139h] 0x00000017 pushad 0x00000018 mov dl, cl 0x0000001a xor edx, 1C4F4AB2h 0x00000020 popad 0x00000021 movsx ecx, bx 0x00000024 xchg eax, ebx 0x00000025 push ecx 0x00000026 push edx 0x00000027 push eax 0x00000028 push edx 0x00000029 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E6620 second address: 8E6630 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop ecx 0x00000006 push eax 0x00000007 pushad 0x00000008 push eax 0x00000009 push edx 0x0000000a jp 00007F991CEDCA66h 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8E6630 second address: 8E6634 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9060CC second address: 9060D0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9060D0 second address: 9060DC instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 jl 00007F991CD14696h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9060DC second address: 9060E4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 pop eax 0x00000006 push edi 0x00000007 pop edi 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 906247 second address: 90625A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F991CD1469Fh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 906550 second address: 906555 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 906555 second address: 906580 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 jmp 00007F991CD146A9h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pushad 0x0000000d push eax 0x0000000e push edx 0x0000000f jnl 00007F991CD14696h 0x00000015 push ecx 0x00000016 pop ecx 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 906580 second address: 90658B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 90669E second address: 9066C4 instructions: 0x00000000 rdtsc 0x00000002 je 00007F991CD14696h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c jmp 00007F991CD146A8h 0x00000011 push ecx 0x00000012 pop ecx 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9066C4 second address: 9066DB instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CEDCA73h 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9066DB second address: 9066E1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 906C73 second address: 906C8D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push ecx 0x00000007 jmp 00007F991CEDCA72h 0x0000000c pop ecx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8F9F07 second address: 8F9F0C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8C690B second address: 8C6924 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 jne 00007F991CEDCA6Ch 0x0000000b push eax 0x0000000c push edx 0x0000000d jnp 00007F991CEDCA66h 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 907A18 second address: 907A1F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 popad 0x00000007 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 907D1E second address: 907D22 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 907D22 second address: 907D28 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8C6900 second address: 8C690B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 pushad 0x00000006 push edx 0x00000007 pushad 0x00000008 popad 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 90ABBA second address: 90ABD8 instructions: 0x00000000 rdtsc 0x00000002 jc 00007F991CD14698h 0x00000008 pushad 0x00000009 popad 0x0000000a jmp 00007F991CD1469Ah 0x0000000f pop edx 0x00000010 pop eax 0x00000011 pushad 0x00000012 pushad 0x00000013 push edi 0x00000014 pop edi 0x00000015 push edx 0x00000016 pop edx 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8CB98C second address: 8CB998 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 jne 00007F991CEDCA66h 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 90D8F4 second address: 90D8F8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 90E114 second address: 90E11A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 90E11A second address: 90E132 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F991CD146A4h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 90E132 second address: 90E136 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 90E136 second address: 90E148 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 pushad 0x0000000a jng 00007F991CD1469Ch 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 90F2FB second address: 90F300 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 90F300 second address: 90F306 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8CF05D second address: 8CF06B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 jbe 00007F991CEDCA66h 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 914BC2 second address: 914BCF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 jnl 00007F991CD14696h 0x0000000c popad 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 914BCF second address: 914BD5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 914BD5 second address: 914BEF instructions: 0x00000000 rdtsc 0x00000002 jp 00007F991CD14696h 0x00000008 jmp 00007F991CD1469Dh 0x0000000d pop edx 0x0000000e pop eax 0x0000000f pushad 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 914BEF second address: 914BF5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 914BF5 second address: 914BFB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 915391 second address: 915399 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 915399 second address: 9153A9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 pushad 0x00000007 popad 0x00000008 jg 00007F991CD14696h 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9153A9 second address: 9153AF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 915EAC second address: 915EC3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F991CD146A3h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 915EC3 second address: 915EE3 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 jne 00007F991CEDCA6Ah 0x0000000f mov eax, dword ptr [esp+04h] 0x00000013 push ebx 0x00000014 jp 00007F991CEDCA6Ch 0x0000001a push eax 0x0000001b push edx 0x0000001c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 915EE3 second address: 915F6B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 mov eax, dword ptr [eax] 0x00000007 push esi 0x00000008 pushad 0x00000009 js 00007F991CD14696h 0x0000000f pushad 0x00000010 popad 0x00000011 popad 0x00000012 pop esi 0x00000013 mov dword ptr [esp+04h], eax 0x00000017 jl 00007F991CD146ABh 0x0000001d jmp 00007F991CD146A5h 0x00000022 pop eax 0x00000023 push 00000000h 0x00000025 push edx 0x00000026 call 00007F991CD14698h 0x0000002b pop edx 0x0000002c mov dword ptr [esp+04h], edx 0x00000030 add dword ptr [esp+04h], 00000018h 0x00000038 inc edx 0x00000039 push edx 0x0000003a ret 0x0000003b pop edx 0x0000003c ret 0x0000003d push FC91BBD7h 0x00000042 push eax 0x00000043 push edx 0x00000044 pushad 0x00000045 jmp 00007F991CD146A9h 0x0000004a jmp 00007F991CD146A3h 0x0000004f popad 0x00000050 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 916C88 second address: 916C8E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 916D10 second address: 916D16 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 916D16 second address: 916D1A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 916D1A second address: 916D2B instructions: 0x00000000 rdtsc 0x00000002 jnl 00007F991CD14696h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d pushad 0x0000000e push edx 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 916FB2 second address: 916FC0 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push edi 0x00000009 pushad 0x0000000a pushad 0x0000000b popad 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 917883 second address: 917887 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 919151 second address: 919157 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 919157 second address: 91916B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 jmp 00007F991CD1469Dh 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91916B second address: 91916F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91916F second address: 9191B1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 mov dword ptr [esp], eax 0x0000000a mov di, 8D90h 0x0000000e movzx esi, si 0x00000011 push 00000000h 0x00000013 xor esi, dword ptr [ebp+122D38C1h] 0x00000019 push 00000000h 0x0000001b push 00000000h 0x0000001d push edx 0x0000001e call 00007F991CD14698h 0x00000023 pop edx 0x00000024 mov dword ptr [esp+04h], edx 0x00000028 add dword ptr [esp+04h], 00000014h 0x00000030 inc edx 0x00000031 push edx 0x00000032 ret 0x00000033 pop edx 0x00000034 ret 0x00000035 push eax 0x00000036 push eax 0x00000037 push edx 0x00000038 js 00007F991CD14698h 0x0000003e push eax 0x0000003f pop eax 0x00000040 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9191B1 second address: 9191B6 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 919B75 second address: 919B79 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91A55C second address: 91A560 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91A560 second address: 91A564 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8D8FB8 second address: 8D8FDB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jc 00007F991CEDCA66h 0x0000000a je 00007F991CEDCA66h 0x00000010 popad 0x00000011 pushad 0x00000012 jns 00007F991CEDCA66h 0x00000018 push ebx 0x00000019 pop ebx 0x0000001a push eax 0x0000001b pop eax 0x0000001c push edi 0x0000001d pop edi 0x0000001e popad 0x0000001f push eax 0x00000020 push edx 0x00000021 push eax 0x00000022 push edx 0x00000023 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8D8FDB second address: 8D8FE1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91DE47 second address: 91DE5E instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CEDCA73h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 921D5E second address: 921D62 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 921D62 second address: 921D7D instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CEDCA77h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 921D7D second address: 921D82 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 923D70 second address: 923DE3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F991CEDCA72h 0x00000009 popad 0x0000000a jno 00007F991CEDCA6Ch 0x00000010 popad 0x00000011 push eax 0x00000012 pushad 0x00000013 jp 00007F991CEDCA68h 0x00000019 pushad 0x0000001a popad 0x0000001b jmp 00007F991CEDCA6Ch 0x00000020 popad 0x00000021 nop 0x00000022 push 00000000h 0x00000024 push edi 0x00000025 call 00007F991CEDCA68h 0x0000002a pop edi 0x0000002b mov dword ptr [esp+04h], edi 0x0000002f add dword ptr [esp+04h], 00000015h 0x00000037 inc edi 0x00000038 push edi 0x00000039 ret 0x0000003a pop edi 0x0000003b ret 0x0000003c mov edi, edx 0x0000003e push 00000000h 0x00000040 clc 0x00000041 push 00000000h 0x00000043 mov dword ptr [ebp+12462751h], esi 0x00000049 push eax 0x0000004a push eax 0x0000004b push edx 0x0000004c pushad 0x0000004d jo 00007F991CEDCA66h 0x00000053 pushad 0x00000054 popad 0x00000055 popad 0x00000056 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 922F84 second address: 922F8E instructions: 0x00000000 rdtsc 0x00000002 jng 00007F991CD1469Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 923DE3 second address: 923DF6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F991CEDCA6Fh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 925CBE second address: 925D21 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CD146A5h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 popad 0x0000000a nop 0x0000000b push 00000000h 0x0000000d push ebp 0x0000000e call 00007F991CD14698h 0x00000013 pop ebp 0x00000014 mov dword ptr [esp+04h], ebp 0x00000018 add dword ptr [esp+04h], 00000018h 0x00000020 inc ebp 0x00000021 push ebp 0x00000022 ret 0x00000023 pop ebp 0x00000024 ret 0x00000025 and edi, dword ptr [ebp+122D3699h] 0x0000002b push 00000000h 0x0000002d mov dword ptr [ebp+1247532Ch], eax 0x00000033 push 00000000h 0x00000035 mov ebx, dword ptr [ebp+122D20DEh] 0x0000003b push eax 0x0000003c push eax 0x0000003d push edx 0x0000003e push eax 0x0000003f push edx 0x00000040 jmp 00007F991CD1469Dh 0x00000045 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 925D21 second address: 925D2B instructions: 0x00000000 rdtsc 0x00000002 jl 00007F991CEDCA66h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 927E55 second address: 927E6C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 jmp 00007F991CD146A2h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 925E7E second address: 925E82 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 927E6C second address: 927E71 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 925E82 second address: 925E88 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 925E88 second address: 925E92 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jne 00007F991CD14696h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9283AB second address: 928449 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CEDCA77h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a jmp 00007F991CEDCA76h 0x0000000f nop 0x00000010 push 00000000h 0x00000012 push eax 0x00000013 call 00007F991CEDCA68h 0x00000018 pop eax 0x00000019 mov dword ptr [esp+04h], eax 0x0000001d add dword ptr [esp+04h], 00000018h 0x00000025 inc eax 0x00000026 push eax 0x00000027 ret 0x00000028 pop eax 0x00000029 ret 0x0000002a push 00000000h 0x0000002c mov di, 3AB1h 0x00000030 xor dword ptr [ebp+122D207Bh], ebx 0x00000036 push 00000000h 0x00000038 and di, FB2Bh 0x0000003d jmp 00007F991CEDCA79h 0x00000042 xchg eax, esi 0x00000043 jmp 00007F991CEDCA79h 0x00000048 push eax 0x00000049 pushad 0x0000004a pushad 0x0000004b push eax 0x0000004c push edx 0x0000004d rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 928449 second address: 92844F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9292C9 second address: 9292CD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 92856F second address: 928574 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9292CD second address: 929348 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007F991CEDCA78h 0x0000000b popad 0x0000000c mov dword ptr [esp], eax 0x0000000f push 00000000h 0x00000011 push edi 0x00000012 call 00007F991CEDCA68h 0x00000017 pop edi 0x00000018 mov dword ptr [esp+04h], edi 0x0000001c add dword ptr [esp+04h], 00000015h 0x00000024 inc edi 0x00000025 push edi 0x00000026 ret 0x00000027 pop edi 0x00000028 ret 0x00000029 mov bx, si 0x0000002c push 00000000h 0x0000002e push 00000000h 0x00000030 push eax 0x00000031 call 00007F991CEDCA68h 0x00000036 pop eax 0x00000037 mov dword ptr [esp+04h], eax 0x0000003b add dword ptr [esp+04h], 0000001Ah 0x00000043 inc eax 0x00000044 push eax 0x00000045 ret 0x00000046 pop eax 0x00000047 ret 0x00000048 push 00000000h 0x0000004a js 00007F991CEDCA68h 0x00000050 mov ebx, eax 0x00000052 push eax 0x00000053 push esi 0x00000054 pushad 0x00000055 jnl 00007F991CEDCA66h 0x0000005b push eax 0x0000005c push edx 0x0000005d rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 928574 second address: 92860B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 pop edx 0x00000006 pop eax 0x00000007 mov dword ptr [esp], eax 0x0000000a mov dword ptr [ebp+122D283Eh], esi 0x00000010 push dword ptr fs:[00000000h] 0x00000017 push 00000000h 0x00000019 push edx 0x0000001a call 00007F991CD14698h 0x0000001f pop edx 0x00000020 mov dword ptr [esp+04h], edx 0x00000024 add dword ptr [esp+04h], 0000001Bh 0x0000002c inc edx 0x0000002d push edx 0x0000002e ret 0x0000002f pop edx 0x00000030 ret 0x00000031 mov bx, 212Ch 0x00000035 mov dword ptr fs:[00000000h], esp 0x0000003c sub edi, dword ptr [ebp+122D3931h] 0x00000042 mov eax, dword ptr [ebp+122D0A39h] 0x00000048 sbb bh, 00000002h 0x0000004b push FFFFFFFFh 0x0000004d push 00000000h 0x0000004f push edi 0x00000050 call 00007F991CD14698h 0x00000055 pop edi 0x00000056 mov dword ptr [esp+04h], edi 0x0000005a add dword ptr [esp+04h], 0000001Bh 0x00000062 inc edi 0x00000063 push edi 0x00000064 ret 0x00000065 pop edi 0x00000066 ret 0x00000067 sub ebx, dword ptr [ebp+122D367Dh] 0x0000006d push eax 0x0000006e push eax 0x0000006f push eax 0x00000070 push edx 0x00000071 jmp 00007F991CD146A4h 0x00000076 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 92A4A5 second address: 92A4B7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F991CEDCA6Eh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 92C25F second address: 92C2B8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pushad 0x00000004 popad 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov dword ptr [esp], eax 0x0000000b mov edi, esi 0x0000000d push 00000000h 0x0000000f push 00000000h 0x00000011 push edi 0x00000012 call 00007F991CD14698h 0x00000017 pop edi 0x00000018 mov dword ptr [esp+04h], edi 0x0000001c add dword ptr [esp+04h], 00000014h 0x00000024 inc edi 0x00000025 push edi 0x00000026 ret 0x00000027 pop edi 0x00000028 ret 0x00000029 sbb bl, 00000053h 0x0000002c push 00000000h 0x0000002e push 00000000h 0x00000030 push edi 0x00000031 call 00007F991CD14698h 0x00000036 pop edi 0x00000037 mov dword ptr [esp+04h], edi 0x0000003b add dword ptr [esp+04h], 00000016h 0x00000043 inc edi 0x00000044 push edi 0x00000045 ret 0x00000046 pop edi 0x00000047 ret 0x00000048 xchg eax, esi 0x00000049 jng 00007F991CD146B5h 0x0000004f push eax 0x00000050 push edx 0x00000051 pushad 0x00000052 popad 0x00000053 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 92D122 second address: 92D131 instructions: 0x00000000 rdtsc 0x00000002 jnp 00007F991CEDCA66h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b pushad 0x0000000c pushad 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 92D131 second address: 92D144 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnl 00007F991CD14696h 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d js 00007F991CD14696h 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 92D144 second address: 92D1A4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 nop 0x00000008 push 00000000h 0x0000000a push edi 0x0000000b call 00007F991CEDCA68h 0x00000010 pop edi 0x00000011 mov dword ptr [esp+04h], edi 0x00000015 add dword ptr [esp+04h], 00000015h 0x0000001d inc edi 0x0000001e push edi 0x0000001f ret 0x00000020 pop edi 0x00000021 ret 0x00000022 jmp 00007F991CEDCA75h 0x00000027 mov dword ptr [ebp+1245185Dh], ecx 0x0000002d push 00000000h 0x0000002f and edi, dword ptr [ebp+122D36D1h] 0x00000035 adc edi, 5A93730Fh 0x0000003b push 00000000h 0x0000003d ja 00007F991CEDCA69h 0x00000043 push eax 0x00000044 push eax 0x00000045 push edx 0x00000046 push eax 0x00000047 push edx 0x00000048 push esi 0x00000049 pop esi 0x0000004a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 92D1A4 second address: 92D1A8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 92D1A8 second address: 92D1AE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8D7565 second address: 8D756B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8D756B second address: 8D7571 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9304C5 second address: 9304CA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9304CA second address: 93050E instructions: 0x00000000 rdtsc 0x00000002 jns 00007F991CEDCA68h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a nop 0x0000000b mov ebx, dword ptr [ebp+122D3945h] 0x00000011 push 00000000h 0x00000013 sub dword ptr [ebp+122D2F92h], ebx 0x00000019 push 00000000h 0x0000001b jne 00007F991CEDCA7Ch 0x00000021 push eax 0x00000022 push eax 0x00000023 push edx 0x00000024 je 00007F991CEDCA6Ch 0x0000002a push eax 0x0000002b push edx 0x0000002c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 92C3CD second address: 92C3D7 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push edx 0x00000009 pop edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 93050E second address: 930512 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 92C4B0 second address: 92C4D2 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CD146A3h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a je 00007F991CD146A0h 0x00000010 push eax 0x00000011 push edx 0x00000012 push edx 0x00000013 pop edx 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 931640 second address: 93165D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ebx 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007F991CEDCA73h 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 93165D second address: 931701 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CD146A4h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 nop 0x0000000a push 00000000h 0x0000000c push ebp 0x0000000d call 00007F991CD14698h 0x00000012 pop ebp 0x00000013 mov dword ptr [esp+04h], ebp 0x00000017 add dword ptr [esp+04h], 00000018h 0x0000001f inc ebp 0x00000020 push ebp 0x00000021 ret 0x00000022 pop ebp 0x00000023 ret 0x00000024 jno 00007F991CD14699h 0x0000002a push dword ptr fs:[00000000h] 0x00000031 push 00000000h 0x00000033 push ecx 0x00000034 call 00007F991CD14698h 0x00000039 pop ecx 0x0000003a mov dword ptr [esp+04h], ecx 0x0000003e add dword ptr [esp+04h], 00000017h 0x00000046 inc ecx 0x00000047 push ecx 0x00000048 ret 0x00000049 pop ecx 0x0000004a ret 0x0000004b mov edi, dword ptr [ebp+12450AD1h] 0x00000051 mov dword ptr fs:[00000000h], esp 0x00000058 push eax 0x00000059 jnl 00007F991CD14696h 0x0000005f pop ebx 0x00000060 mov eax, dword ptr [ebp+122D029Dh] 0x00000066 call 00007F991CD1469Bh 0x0000006b xor dword ptr [ebp+122D20E8h], edx 0x00000071 pop ebx 0x00000072 push FFFFFFFFh 0x00000074 xor edi, 5C13D1EDh 0x0000007a nop 0x0000007b push edi 0x0000007c pushad 0x0000007d push esi 0x0000007e pop esi 0x0000007f push eax 0x00000080 push edx 0x00000081 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 931701 second address: 931727 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edi 0x00000006 push eax 0x00000007 push eax 0x00000008 push edx 0x00000009 pushad 0x0000000a jmp 00007F991CEDCA79h 0x0000000f push edx 0x00000010 pop edx 0x00000011 popad 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 931727 second address: 93172D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9387D0 second address: 93883B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F991CEDCA70h 0x00000009 jmp 00007F991CEDCA6Ah 0x0000000e popad 0x0000000f jmp 00007F991CEDCA78h 0x00000014 popad 0x00000015 push ebx 0x00000016 pushad 0x00000017 push ebx 0x00000018 pop ebx 0x00000019 jmp 00007F991CEDCA75h 0x0000001e jmp 00007F991CEDCA74h 0x00000023 popad 0x00000024 push edi 0x00000025 push edi 0x00000026 pop edi 0x00000027 push eax 0x00000028 push edx 0x00000029 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 93D914 second address: 93D91A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 93D4E4 second address: 93D4E9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 947EB4 second address: 947EF0 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CD1469Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pushad 0x0000000a jmp 00007F991CD1469Fh 0x0000000f push ecx 0x00000010 pop ecx 0x00000011 jmp 00007F991CD146A2h 0x00000016 push edx 0x00000017 pop edx 0x00000018 popad 0x00000019 push eax 0x0000001a push edx 0x0000001b push eax 0x0000001c push edx 0x0000001d rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 947EF0 second address: 947EF6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 8CD449 second address: 8CD44D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9471E9 second address: 947203 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F991CEDCA75h 0x00000009 pop eax 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 947370 second address: 947383 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 jmp 00007F991CD1469Eh 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 947383 second address: 9473B1 instructions: 0x00000000 rdtsc 0x00000002 jp 00007F991CEDCA79h 0x00000008 push edi 0x00000009 jmp 00007F991CEDCA70h 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9473B1 second address: 9473CD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 pop edx 0x00000006 pop eax 0x00000007 push eax 0x00000008 push edx 0x00000009 push ecx 0x0000000a pushad 0x0000000b popad 0x0000000c pop ecx 0x0000000d jmp 00007F991CD1469Fh 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9473CD second address: 9473D7 instructions: 0x00000000 rdtsc 0x00000002 jl 00007F991CEDCA6Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9478D7 second address: 9478DB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9478DB second address: 9478F9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jp 00007F991CEDCA6Eh 0x0000000c push eax 0x0000000d push edx 0x0000000e ja 00007F991CEDCA66h 0x00000014 push eax 0x00000015 pop eax 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9478F9 second address: 947906 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c popad 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 947906 second address: 947910 instructions: 0x00000000 rdtsc 0x00000002 jns 00007F991CEDCA66h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 94DA33 second address: 94DA6D instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CD1469Eh 0x00000007 jmp 00007F991CD146A9h 0x0000000c pop edx 0x0000000d pop eax 0x0000000e popad 0x0000000f jbe 00007F991CD146BBh 0x00000015 jc 00007F991CD146B5h 0x0000001b push eax 0x0000001c push edx 0x0000001d rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 94CDF9 second address: 94CDFD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 94CDFD second address: 94CE2B instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CD146A2h 0x00000007 jnl 00007F991CD14696h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f je 00007F991CD146A2h 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 94CE2B second address: 94CE50 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CEDCA78h 0x00000007 pushad 0x00000008 pushad 0x00000009 popad 0x0000000a jl 00007F991CEDCA66h 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 94CE50 second address: 94CE80 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jc 00007F991CD14696h 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d jc 00007F991CD146B9h 0x00000013 push eax 0x00000014 push edx 0x00000015 jmp 00007F991CD146A9h 0x0000001a pushad 0x0000001b popad 0x0000001c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 94C4E1 second address: 94C4E7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 94C4E7 second address: 94C506 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CD146A2h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pushad 0x0000000a ja 00007F991CD14696h 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 94D165 second address: 94D173 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a pushad 0x0000000b popad 0x0000000c push eax 0x0000000d pop eax 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 94D2DF second address: 94D2E3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 94D42D second address: 94D43F instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 jg 00007F991CEDCA66h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 94D43F second address: 94D443 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 94D742 second address: 94D758 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jmp 00007F991CEDCA6Ah 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push edx 0x0000000d push esi 0x0000000e pop esi 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 94D758 second address: 94D75C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 94D75C second address: 94D760 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9539B7 second address: 9539CC instructions: 0x00000000 rdtsc 0x00000002 jg 00007F991CD14696h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d jo 00007F991CD146B5h 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9539CC second address: 9539FB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F991CEDCA79h 0x00000009 push edi 0x0000000a jmp 00007F991CEDCA70h 0x0000000f pop edi 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 952208 second address: 952221 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 jmp 00007F991CD146A2h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 952221 second address: 952226 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 952226 second address: 95222B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95C42A second address: 95C43E instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 jmp 00007F991CEDCA6Bh 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95B3BE second address: 95B3E5 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007F991CD1469Dh 0x0000000b jp 00007F991CD1469Ch 0x00000011 jnp 00007F991CD146A2h 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91F0C4 second address: 91F0CA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91F0CA second address: 8F9F07 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 mov dword ptr [esp], eax 0x00000008 push 00000000h 0x0000000a push esi 0x0000000b call 00007F991CD14698h 0x00000010 pop esi 0x00000011 mov dword ptr [esp+04h], esi 0x00000015 add dword ptr [esp+04h], 00000018h 0x0000001d inc esi 0x0000001e push esi 0x0000001f ret 0x00000020 pop esi 0x00000021 ret 0x00000022 mov di, bx 0x00000025 call dword ptr [ebp+122D1C58h] 0x0000002b jnc 00007F991CD146B1h 0x00000031 push eax 0x00000032 push edx 0x00000033 push edx 0x00000034 jmp 00007F991CD1469Eh 0x00000039 pop edx 0x0000003a pushad 0x0000003b push edx 0x0000003c pop edx 0x0000003d push eax 0x0000003e push edx 0x0000003f rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91F18F second address: 91F222 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 xchg eax, ebx 0x00000005 mov cl, FBh 0x00000007 push dword ptr fs:[00000000h] 0x0000000e add dword ptr [ebp+1244AFC1h], ecx 0x00000014 mov dword ptr fs:[00000000h], esp 0x0000001b jc 00007F991CEDCA67h 0x00000021 cmc 0x00000022 mov dword ptr [ebp+12489E0Ch], esp 0x00000028 push eax 0x00000029 cmc 0x0000002a pop edx 0x0000002b cmp dword ptr [ebp+122D37F5h], 00000000h 0x00000032 jne 00007F991CEDCB63h 0x00000038 jmp 00007F991CEDCA77h 0x0000003d mov byte ptr [ebp+122D2CD5h], 00000047h 0x00000044 push 00000000h 0x00000046 push edx 0x00000047 call 00007F991CEDCA68h 0x0000004c pop edx 0x0000004d mov dword ptr [esp+04h], edx 0x00000051 add dword ptr [esp+04h], 00000015h 0x00000059 inc edx 0x0000005a push edx 0x0000005b ret 0x0000005c pop edx 0x0000005d ret 0x0000005e mov dword ptr [ebp+122D27AAh], esi 0x00000064 adc dh, FFFFFFD3h 0x00000067 mov ecx, dword ptr [ebp+122D397Dh] 0x0000006d mov eax, D49AA7D2h 0x00000072 mov dword ptr [ebp+124520B5h], eax 0x00000078 nop 0x00000079 pushad 0x0000007a push eax 0x0000007b push edx 0x0000007c push edx 0x0000007d pop edx 0x0000007e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91F499 second address: 768A64 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 popad 0x00000008 mov dword ptr [esp], eax 0x0000000b mov dword ptr [ebp+12451101h], eax 0x00000011 push dword ptr [ebp+122D0C69h] 0x00000017 movsx edi, bx 0x0000001a call dword ptr [ebp+122D2D14h] 0x00000020 pushad 0x00000021 xor dword ptr [ebp+122D1BB6h], esi 0x00000027 xor eax, eax 0x00000029 stc 0x0000002a mov edx, dword ptr [esp+28h] 0x0000002e mov dword ptr [ebp+122D1BBEh], esi 0x00000034 mov dword ptr [ebp+122D38E9h], eax 0x0000003a jbe 00007F991CD1469Ch 0x00000040 mov esi, 0000003Ch 0x00000045 jmp 00007F991CD1469Ch 0x0000004a add esi, dword ptr [esp+24h] 0x0000004e cmc 0x0000004f lodsw 0x00000051 clc 0x00000052 cmc 0x00000053 add eax, dword ptr [esp+24h] 0x00000057 cmc 0x00000058 mov ebx, dword ptr [esp+24h] 0x0000005c or dword ptr [ebp+122D1BB6h], edx 0x00000062 nop 0x00000063 jng 00007F991CD1469Eh 0x00000069 push eax 0x0000006a jg 00007F991CD146A4h 0x00000070 pushad 0x00000071 push eax 0x00000072 push edx 0x00000073 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91F670 second address: 91F69B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jng 00007F991CEDCA66h 0x0000000a popad 0x0000000b pop ebx 0x0000000c mov dword ptr [esp+04h], eax 0x00000010 push eax 0x00000011 push edx 0x00000012 jg 00007F991CEDCA79h 0x00000018 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91F69B second address: 91F6A5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jns 00007F991CD14696h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91FB23 second address: 91FB27 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91FB27 second address: 91FB48 instructions: 0x00000000 rdtsc 0x00000002 jg 00007F991CD14696h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a jc 00007F991CD14698h 0x00000010 push ecx 0x00000011 pop ecx 0x00000012 popad 0x00000013 push eax 0x00000014 push eax 0x00000015 push edx 0x00000016 jmp 00007F991CD1469Bh 0x0000001b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91FF51 second address: 91FF9D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 mov dword ptr [esp], eax 0x0000000a mov dword ptr [ebp+122D21CDh], eax 0x00000010 push 0000001Eh 0x00000012 push 00000000h 0x00000014 push eax 0x00000015 call 00007F991CEDCA68h 0x0000001a pop eax 0x0000001b mov dword ptr [esp+04h], eax 0x0000001f add dword ptr [esp+04h], 00000017h 0x00000027 inc eax 0x00000028 push eax 0x00000029 ret 0x0000002a pop eax 0x0000002b ret 0x0000002c nop 0x0000002d push eax 0x0000002e push eax 0x0000002f push ebx 0x00000030 pop ebx 0x00000031 pop eax 0x00000032 pop eax 0x00000033 push eax 0x00000034 push eax 0x00000035 push edx 0x00000036 jmp 00007F991CEDCA71h 0x0000003b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91FF9D second address: 91FFA2 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95B8E5 second address: 95B8FD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 push edi 0x00000006 pushad 0x00000007 popad 0x00000008 jmp 00007F991CEDCA6Fh 0x0000000d pop edi 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95B8FD second address: 95B91C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CD146A3h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push ecx 0x0000000a pushad 0x0000000b push esi 0x0000000c pop esi 0x0000000d pushad 0x0000000e popad 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95B91C second address: 95B924 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95BA77 second address: 95BA7D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95BA7D second address: 95BA81 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95BA81 second address: 95BA8F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 js 00007F991CD146A2h 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95BD3A second address: 95BD40 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95BD40 second address: 95BD44 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95BD44 second address: 95BD4A instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95BD4A second address: 95BD50 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edx 0x00000005 pop edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95BD50 second address: 95BD54 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95BD54 second address: 95BD5D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95BFCD second address: 95BFD1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95BFD1 second address: 95C007 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F991CD146A7h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b jmp 00007F991CD146A9h 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95C007 second address: 95C013 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 jc 00007F991CEDCA66h 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95C013 second address: 95C017 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95C017 second address: 95C023 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push edi 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 95C023 second address: 95C044 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jp 00007F991CD14696h 0x0000000a pushad 0x0000000b popad 0x0000000c popad 0x0000000d pushad 0x0000000e jmp 00007F991CD1469Fh 0x00000013 push ebx 0x00000014 pop ebx 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 96076A second address: 960770 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 960770 second address: 96077E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 pushad 0x00000007 popad 0x00000008 jg 00007F991CD14696h 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 96077E second address: 96079F instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ebx 0x00000007 pushad 0x00000008 pushad 0x00000009 push ecx 0x0000000a pop ecx 0x0000000b push esi 0x0000000c pop esi 0x0000000d push edx 0x0000000e pop edx 0x0000000f push esi 0x00000010 pop esi 0x00000011 popad 0x00000012 jp 00007F991CEDCA68h 0x00000018 pushad 0x00000019 pushad 0x0000001a popad 0x0000001b push esi 0x0000001c pop esi 0x0000001d push eax 0x0000001e push edx 0x0000001f rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 962A82 second address: 962A86 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 965801 second address: 965805 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 965805 second address: 965821 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F991CD146A3h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 965821 second address: 965832 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F991CEDCA6Ch 0x00000009 popad 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 965832 second address: 96583E instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pushad 0x00000004 popad 0x00000005 pushad 0x00000006 popad 0x00000007 pop edx 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 96583E second address: 965842 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 96EE68 second address: 96EE79 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 ja 00007F991CD14696h 0x0000000a jo 00007F991CD14696h 0x00000010 popad 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 96F027 second address: 96F051 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pushad 0x00000008 pushad 0x00000009 jnl 00007F991CEDCA66h 0x0000000f jno 00007F991CEDCA66h 0x00000015 pushad 0x00000016 popad 0x00000017 popad 0x00000018 jp 00007F991CEDCA6Ah 0x0000001e push eax 0x0000001f push edx 0x00000020 js 00007F991CEDCA66h 0x00000026 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 96F1BA second address: 96F1E4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jnl 00007F991CD146B5h 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 96F345 second address: 96F353 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jng 00007F991CEDCA6Eh 0x0000000a push edi 0x0000000b pop edi 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 96F353 second address: 96F36B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jng 00007F991CD146A8h 0x0000000a jmp 00007F991CD1469Ch 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 96F4EF second address: 96F52C instructions: 0x00000000 rdtsc 0x00000002 jp 00007F991CEDCA66h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a jno 00007F991CEDCA6Eh 0x00000010 jbe 00007F991CEDCA68h 0x00000016 push edx 0x00000017 pop edx 0x00000018 popad 0x00000019 push eax 0x0000001a push edx 0x0000001b pushad 0x0000001c jng 00007F991CEDCA66h 0x00000022 jmp 00007F991CEDCA6Ch 0x00000027 push edi 0x00000028 pop edi 0x00000029 popad 0x0000002a push edi 0x0000002b push edx 0x0000002c pop edx 0x0000002d pop edi 0x0000002e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 96F687 second address: 96F68D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 96F68D second address: 96F6B9 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CEDCA6Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jmp 00007F991CEDCA75h 0x0000000e popad 0x0000000f push eax 0x00000010 push edx 0x00000011 push eax 0x00000012 push edx 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 96F6B9 second address: 96F6BD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 96F6BD second address: 96F6C9 instructions: 0x00000000 rdtsc 0x00000002 jnc 00007F991CEDCA66h 0x00000008 push ecx 0x00000009 pop ecx 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 975CE2 second address: 975CE8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 974544 second address: 97454C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97483A second address: 97483F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97497A second address: 97497E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97497E second address: 974984 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 974984 second address: 974988 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 974C77 second address: 974CAB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 jmp 00007F991CD146A9h 0x0000000d jmp 00007F991CD146A3h 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91FDD0 second address: 91FDD4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 91FDD4 second address: 91FDE1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop esi 0x00000007 push eax 0x00000008 pushad 0x00000009 push eax 0x0000000a push edx 0x0000000b push esi 0x0000000c pop esi 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 974DF3 second address: 974E0C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F991CEDCA73h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 974E0C second address: 974E28 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jmp 00007F991CD146A4h 0x0000000a pushad 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97500E second address: 975019 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jl 00007F991CEDCA66h 0x0000000a popad 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97DCA1 second address: 97DCAD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push edi 0x0000000b pop edi 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97DCAD second address: 97DCB1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97DCB1 second address: 97DCBC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97DCBC second address: 97DCC4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97DCC4 second address: 97DCCD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97DCCD second address: 97DCD1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97DFFC second address: 97E001 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97E2CC second address: 97E2D9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jng 00007F991CEDCA68h 0x0000000b push ecx 0x0000000c pop ecx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97E2D9 second address: 97E2FA instructions: 0x00000000 rdtsc 0x00000002 jnc 00007F991CD14698h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push ecx 0x0000000b jmp 00007F991CD1469Bh 0x00000010 push edx 0x00000011 jl 00007F991CD14696h 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97E608 second address: 97E60C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97EB11 second address: 97EB1A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push esi 0x00000004 pop esi 0x00000005 push eax 0x00000006 pop eax 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97EE2C second address: 97EE30 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 97EE30 second address: 97EE36 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 983659 second address: 983674 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 jnp 00007F991CEDCA76h 0x0000000b jmp 00007F991CEDCA70h 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9829A7 second address: 9829AB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9829AB second address: 9829B6 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pushad 0x00000004 popad 0x00000005 pop esi 0x00000006 pushad 0x00000007 pushad 0x00000008 popad 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 982B26 second address: 982B40 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CD1469Eh 0x00000007 pushad 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e popad 0x0000000f push ebx 0x00000010 pop ebx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 982B40 second address: 982B46 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9830A2 second address: 9830A6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9830A6 second address: 9830AA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9830AA second address: 9830B0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9830B0 second address: 9830BA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9830BA second address: 9830BE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9830BE second address: 9830C2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9830C2 second address: 9830CA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 98323D second address: 983275 instructions: 0x00000000 rdtsc 0x00000002 js 00007F991CEDCA66h 0x00000008 jmp 00007F991CEDCA78h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f push esi 0x00000010 jmp 00007F991CEDCA73h 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 988431 second address: 988435 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 988435 second address: 988454 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnp 00007F991CEDCA66h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c jmp 00007F991CEDCA73h 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 988454 second address: 98845A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 98845A second address: 988472 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 jmp 00007F991CEDCA6Ch 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pop edx 0x0000000c pop eax 0x0000000d push ecx 0x0000000e push edx 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 99222F second address: 99224F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CD146A3h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push esi 0x0000000a jg 00007F991CD14696h 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9904FB second address: 990513 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 je 00007F991CEDCA66h 0x0000000e jmp 00007F991CEDCA6Ah 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 990513 second address: 990538 instructions: 0x00000000 rdtsc 0x00000002 je 00007F991CD14696h 0x00000008 push edx 0x00000009 pop edx 0x0000000a pop edx 0x0000000b pop eax 0x0000000c popad 0x0000000d push eax 0x0000000e push edx 0x0000000f jns 00007F991CD146A6h 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9907A2 second address: 9907A6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 990E69 second address: 990E6F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 990FC3 second address: 990FDA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push esi 0x00000007 pop esi 0x00000008 popad 0x00000009 pushad 0x0000000a pushad 0x0000000b popad 0x0000000c push esi 0x0000000d pop esi 0x0000000e push edx 0x0000000f pop edx 0x00000010 jl 00007F991CEDCA66h 0x00000016 popad 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 991896 second address: 99189F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 99189F second address: 9918B6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pushad 0x00000006 jmp 00007F991CEDCA6Fh 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 992028 second address: 992033 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 992033 second address: 992037 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 992037 second address: 992048 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CD1469Bh 0x00000007 push ebx 0x00000008 pop ebx 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 992048 second address: 992066 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 jmp 00007F991CEDCA79h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 992066 second address: 99208F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 jmp 00007F991CD146A9h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pushad 0x0000000d jl 00007F991CD1469Ch 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 98FF7B second address: 98FFAA instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pushad 0x00000008 jnc 00007F991CEDCA68h 0x0000000e pushad 0x0000000f je 00007F991CEDCA66h 0x00000015 jnp 00007F991CEDCA66h 0x0000001b popad 0x0000001c push eax 0x0000001d push edx 0x0000001e jmp 00007F991CEDCA6Fh 0x00000023 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 98FFAA second address: 98FFAE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9983DD second address: 9983E3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9983E3 second address: 9983EC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9983EC second address: 9983F0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9983F0 second address: 998414 instructions: 0x00000000 rdtsc 0x00000002 jbe 00007F991CD14696h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pushad 0x0000000c push esi 0x0000000d pushad 0x0000000e popad 0x0000000f je 00007F991CD14696h 0x00000015 pop esi 0x00000016 push eax 0x00000017 push edx 0x00000018 jmp 00007F991CD1469Ch 0x0000001d rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 997F88 second address: 997FA4 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CEDCA76h 0x00000007 push eax 0x00000008 push edx 0x00000009 pushad 0x0000000a popad 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 999AB7 second address: 999ACD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007F991CD1469Fh 0x00000008 pushad 0x00000009 popad 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9A6E76 second address: 9A6E7C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9A6E7C second address: 9A6E88 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jp 00007F991CD14696h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9A6E88 second address: 9A6E95 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 ja 00007F991CEDCA66h 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9A6E95 second address: 9A6E9F instructions: 0x00000000 rdtsc 0x00000002 jnc 00007F991CD14696h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9A6E9F second address: 9A6EA5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9A6EA5 second address: 9A6EAF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jnc 00007F991CD14696h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9A6EAF second address: 9A6ECF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 jnl 00007F991CEDCA68h 0x0000000f jbe 00007F991CEDCA6Ch 0x00000015 push eax 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9A6ECF second address: 9A6ED5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9A69E7 second address: 9A69F5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 jc 00007F991CEDCA66h 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9ABB9C second address: 9ABBAD instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CD1469Dh 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9ABBAD second address: 9ABBB6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9ABBB6 second address: 9ABBCE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F991CD146A0h 0x00000009 pushad 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9ABBCE second address: 9ABC09 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 je 00007F991CEDCA86h 0x0000000b jmp 00007F991CEDCA6Dh 0x00000010 jmp 00007F991CEDCA73h 0x00000015 push eax 0x00000016 push edx 0x00000017 jmp 00007F991CEDCA6Eh 0x0000001c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9AD85D second address: 9AD863 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9B4BC1 second address: 9B4BCB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop ebx 0x00000007 push ebx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9B4BCB second address: 9B4BD6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop ebx 0x00000007 push eax 0x00000008 push edx 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9B4BD6 second address: 9B4BDA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9B7268 second address: 9B7276 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 pushad 0x00000006 jl 00007F991CD14696h 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9B7276 second address: 9B728E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 popad 0x00000006 pushad 0x00000007 push esi 0x00000008 js 00007F991CEDCA66h 0x0000000e pop esi 0x0000000f pushad 0x00000010 jbe 00007F991CEDCA66h 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9B728E second address: 9B72CB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 jmp 00007F991CD1469Eh 0x0000000b popad 0x0000000c push edi 0x0000000d jmp 00007F991CD146A5h 0x00000012 pop edi 0x00000013 push eax 0x00000014 jmp 00007F991CD1469Eh 0x00000019 push eax 0x0000001a push edx 0x0000001b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9C8436 second address: 9C843A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9C843A second address: 9C8446 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a pushad 0x0000000b popad 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9C6CE0 second address: 9C6CE4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9C6CE4 second address: 9C6CF2 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 ja 00007F991CD1469Ch 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9C6CF2 second address: 9C6CF6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9C6CF6 second address: 9C6CFB instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9C6E56 second address: 9C6E5A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9C6FC2 second address: 9C6FD6 instructions: 0x00000000 rdtsc 0x00000002 js 00007F991CD14696h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a popad 0x0000000b push ecx 0x0000000c jl 00007F991CD1469Ch 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9C73CE second address: 9C73FB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jns 00007F991CEDCA6Ch 0x0000000e pushad 0x0000000f jmp 00007F991CEDCA6Ah 0x00000014 push ebx 0x00000015 pop ebx 0x00000016 jmp 00007F991CEDCA6Bh 0x0000001b popad 0x0000001c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9C75A8 second address: 9C7608 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CD1469Bh 0x00000007 push ebx 0x00000008 jmp 00007F991CD1469Dh 0x0000000d pop ebx 0x0000000e pop edx 0x0000000f pop eax 0x00000010 pushad 0x00000011 js 00007F991CD1469Eh 0x00000017 jnc 00007F991CD14696h 0x0000001d push edx 0x0000001e pop edx 0x0000001f pushad 0x00000020 jmp 00007F991CD146A8h 0x00000025 jmp 00007F991CD1469Bh 0x0000002a je 00007F991CD14696h 0x00000030 popad 0x00000031 js 00007F991CD146A2h 0x00000037 push eax 0x00000038 push edx 0x00000039 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9C7608 second address: 9C760E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9CB5F2 second address: 9CB5FA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9CB5FA second address: 9CB5FF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9CB5FF second address: 9CB617 instructions: 0x00000000 rdtsc 0x00000002 jo 00007F991CD14698h 0x00000008 pushad 0x00000009 popad 0x0000000a jno 00007F991CD14698h 0x00000010 pop edx 0x00000011 pop eax 0x00000012 pushad 0x00000013 pushad 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9D6463 second address: 9D6489 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 push eax 0x00000006 push edx 0x00000007 jne 00007F991CEDCA66h 0x0000000d jmp 00007F991CEDCA79h 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9D6489 second address: 9D648F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9D648F second address: 9D6495 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9D6495 second address: 9D64B0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F991CD1469Ah 0x00000009 jmp 00007F991CD1469Dh 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9D64B0 second address: 9D64B4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9EA1B5 second address: 9EA1E6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jmp 00007F991CD146A1h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pushad 0x0000000c jo 00007F991CD14696h 0x00000012 jmp 00007F991CD1469Fh 0x00000017 push edx 0x00000018 pop edx 0x00000019 push eax 0x0000001a push edx 0x0000001b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9E9FE8 second address: 9E9FEE instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9E9FEE second address: 9E9FF4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9E9FF4 second address: 9EA023 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CEDCA79h 0x00000007 jbe 00007F991CEDCA6Ah 0x0000000d pushad 0x0000000e popad 0x0000000f push ebx 0x00000010 pop ebx 0x00000011 pop edx 0x00000012 pop eax 0x00000013 push eax 0x00000014 push edx 0x00000015 push ebx 0x00000016 push edi 0x00000017 pop edi 0x00000018 push eax 0x00000019 pop eax 0x0000001a pop ebx 0x0000001b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9ED0E3 second address: 9ED0F3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jno 00007F991CD14696h 0x0000000a jne 00007F991CD14696h 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 9ED0F3 second address: 9ED112 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CEDCA77h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push ebx 0x0000000c pop ebx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A02DAF second address: A02DBB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pushad 0x00000006 push edx 0x00000007 pop edx 0x00000008 push eax 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A02F28 second address: A02F2C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A02F2C second address: A02F38 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jg 00007F991CD14696h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A02F38 second address: A02F40 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A02F40 second address: A02F44 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A02F44 second address: A02F52 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jl 00007F991CEDCA6Ch 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A030B2 second address: A030BC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 push ecx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A03209 second address: A03221 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CEDCA72h 0x00000007 push ecx 0x00000008 pop ecx 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A03221 second address: A0322B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jnp 00007F991CD14696h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A03397 second address: A033AF instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jne 00007F991CEDCA66h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pushad 0x0000000d push esi 0x0000000e pop esi 0x0000000f pushad 0x00000010 popad 0x00000011 jnp 00007F991CEDCA66h 0x00000017 popad 0x00000018 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A03890 second address: A03899 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push edx 0x00000006 pushad 0x00000007 popad 0x00000008 pop edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A03899 second address: A0389E instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A0389E second address: A038CB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 jmp 00007F991CD1469Bh 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007F991CD146A9h 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A09998 second address: A099B6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 popad 0x00000006 push eax 0x00000007 jmp 00007F991CEDCA6Dh 0x0000000c mov eax, dword ptr [esp+04h] 0x00000010 push eax 0x00000011 pushad 0x00000012 pushad 0x00000013 popad 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A099B6 second address: A099C7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop eax 0x00000006 mov eax, dword ptr [eax] 0x00000008 jnc 00007F991CD1469Eh 0x0000000e push esi 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A09D32 second address: A09D36 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A09D36 second address: A09D44 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push esi 0x00000004 pop esi 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c push esi 0x0000000d pop esi 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A09D44 second address: A09D48 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A09D48 second address: A09D60 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 mov eax, dword ptr [esp+04h] 0x0000000b pushad 0x0000000c push ecx 0x0000000d pushad 0x0000000e popad 0x0000000f pop ecx 0x00000010 push eax 0x00000011 push edx 0x00000012 ja 00007F991CD14696h 0x00000018 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A09D60 second address: A09D82 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F991CEDCA72h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 popad 0x0000000a mov eax, dword ptr [eax] 0x0000000c push eax 0x0000000d js 00007F991CEDCA6Ch 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A0B8CA second address: A0B8E4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 jmp 00007F991CD146A0h 0x0000000a pushad 0x0000000b pushad 0x0000000c popad 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A0D40C second address: A0D410 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: A0D410 second address: A0D416 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 918BDA second address: 918BFA instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push eax 0x00000008 push edx 0x00000009 ja 00007F991CEDCA77h 0x0000000f jmp 00007F991CEDCA71h 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\GHXsFkoroU.exe | RDTSC instruction interceptor: First address: 918FEB second address: 918FEF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |