Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E34696 GetFileAttributesW,FindFirstFileW,FindClose, | 0_2_00E34696 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E3C9C7 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 0_2_00E3C9C7 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E3C93C FindFirstFileW,FindClose, | 0_2_00E3C93C |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E3F200 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_00E3F200 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E3F35D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_00E3F35D |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E3F65E FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_00E3F65E |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E33A2B FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_00E33A2B |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E33D4E FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_00E33D4E |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E3BF27 FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_00E3BF27 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CB4696 GetFileAttributesW,FindFirstFileW,FindClose, | 2_2_00CB4696 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CBC9C7 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 2_2_00CBC9C7 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CBC93C FindFirstFileW,FindClose, | 2_2_00CBC93C |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CBF200 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 2_2_00CBF200 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CBF35D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 2_2_00CBF35D |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CBF65E FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 2_2_00CBF65E |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CB3A2B FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 2_2_00CB3A2B |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CB3D4E FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 2_2_00CB3D4E |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CBBF27 FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 2_2_00CBBF27 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CB4696 GetFileAttributesW,FindFirstFileW,FindClose, | 5_2_00CB4696 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CBC9C7 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 5_2_00CBC9C7 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CBC93C FindFirstFileW,FindClose, | 5_2_00CBC93C |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CBF200 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 5_2_00CBF200 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CBF35D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 5_2_00CBF35D |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CBF65E FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 5_2_00CBF65E |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CB3A2B FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 5_2_00CB3A2B |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CB3D4E FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 5_2_00CB3D4E |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CBBF27 FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 5_2_00CBBF27 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5CDAC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 0_2_00E5CDAC |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDCDAC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 2_2_00CDCDAC |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDCDAC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 5_2_00CDCDAC |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DD3633 NtdllDefWindowProc_W,KillTimer,SetTimer,RegisterClipboardFormatW,CreatePopupMenu,PostQuitMessage,SetFocus,MoveWindow, | 0_2_00DD3633 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5C27C ReleaseCapture,SetWindowTextW,SendMessageW,NtdllDialogWndProc_W, | 0_2_00E5C27C |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5C220 NtdllDialogWndProc_W, | 0_2_00E5C220 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5C49C PostMessageW,GetFocus,GetDlgCtrlID,_memset,GetMenuItemInfoW,GetMenuItemCount,GetMenuItemID,GetMenuItemInfoW,GetMenuItemInfoW,CheckMenuRadioItem,NtdllDialogWndProc_W, | 0_2_00E5C49C |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5C788 GetCursorPos,TrackPopupMenuEx,GetCursorPos,NtdllDialogWndProc_W, | 0_2_00E5C788 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5C8EE DragQueryPoint,SendMessageW,DragQueryFileW,DragQueryFileW,_wcscat,SendMessageW,SendMessageW,SendMessageW,SendMessageW,DragFinish,NtdllDialogWndProc_W, | 0_2_00E5C8EE |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5C86D SendMessageW,NtdllDialogWndProc_W, | 0_2_00E5C86D |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5CBF9 NtdllDialogWndProc_W, | 0_2_00E5CBF9 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5CBAE NtdllDialogWndProc_W, | 0_2_00E5CBAE |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5CB7F NtdllDialogWndProc_W, | 0_2_00E5CB7F |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5CB50 NtdllDialogWndProc_W, | 0_2_00E5CB50 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5CC2E ClientToScreen,NtdllDialogWndProc_W, | 0_2_00E5CC2E |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5CDAC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 0_2_00E5CDAC |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5CD6C GetWindowLongW,NtdllDialogWndProc_W, | 0_2_00E5CD6C |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DD1290 NtdllDialogWndProc_W,GetClientRect,GetCursorPos,ScreenToClient, | 0_2_00DD1290 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DD1287 NtdllDialogWndProc_W,GetSysColor,SetBkColor,745AC8D0,NtdllDialogWndProc_W, | 0_2_00DD1287 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DD16DE GetParent,NtdllDialogWndProc_W, | 0_2_00DD16DE |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5D6C6 NtdllDialogWndProc_W, | 0_2_00E5D6C6 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DD16B5 NtdllDialogWndProc_W, | 0_2_00DD16B5 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DD167D NtdllDialogWndProc_W, | 0_2_00DD167D |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5D74C GetSystemMetrics,GetSystemMetrics,MoveWindow,SendMessageW,SendMessageW,ShowWindow,InvalidateRect,NtdllDialogWndProc_W, | 0_2_00E5D74C |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DD189B NtdllDialogWndProc_W, | 0_2_00DD189B |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5DA9A NtdllDialogWndProc_W, | 0_2_00E5DA9A |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5BF4D NtdllDialogWndProc_W,CallWindowProcW, | 0_2_00E5BF4D |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C53633 NtdllDefWindowProc_W,KillTimer,SetTimer,RegisterClipboardFormatW,CreatePopupMenu,PostQuitMessage,SetFocus,MoveWindow, | 2_2_00C53633 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDC27C ReleaseCapture,SetWindowTextW,SendMessageW,NtdllDialogWndProc_W, | 2_2_00CDC27C |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDC220 NtdllDialogWndProc_W, | 2_2_00CDC220 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDC49C PostMessageW,GetFocus,GetDlgCtrlID,_memset,GetMenuItemInfoW,GetMenuItemCount,GetMenuItemID,GetMenuItemInfoW,GetMenuItemInfoW,CheckMenuRadioItem,NtdllDialogWndProc_W, | 2_2_00CDC49C |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDC788 GetCursorPos,TrackPopupMenuEx,GetCursorPos,NtdllDialogWndProc_W, | 2_2_00CDC788 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDC8EE DragQueryPoint,SendMessageW,DragQueryFileW,DragQueryFileW,_wcscat,SendMessageW,SendMessageW,SendMessageW,SendMessageW,DragFinish,NtdllDialogWndProc_W, | 2_2_00CDC8EE |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDC86D SendMessageW,NtdllDialogWndProc_W, | 2_2_00CDC86D |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDCBF9 NtdllDialogWndProc_W, | 2_2_00CDCBF9 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDCBAE NtdllDialogWndProc_W, | 2_2_00CDCBAE |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDCB50 NtdllDialogWndProc_W, | 2_2_00CDCB50 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDCB7F NtdllDialogWndProc_W, | 2_2_00CDCB7F |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDCC2E ClientToScreen,NtdllDialogWndProc_W, | 2_2_00CDCC2E |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDCDAC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 2_2_00CDCDAC |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDCD6C GetWindowLongW,NtdllDialogWndProc_W, | 2_2_00CDCD6C |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C51287 NtdllDialogWndProc_W,GetSysColor,SetBkColor,745AC8D0,NtdllDialogWndProc_W, | 2_2_00C51287 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C51290 NtdllDialogWndProc_W,GetClientRect,GetCursorPos,ScreenToClient, | 2_2_00C51290 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDD6C6 NtdllDialogWndProc_W, | 2_2_00CDD6C6 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C516DE GetParent,NtdllDialogWndProc_W, | 2_2_00C516DE |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C516B5 NtdllDialogWndProc_W, | 2_2_00C516B5 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C5167D NtdllDialogWndProc_W, | 2_2_00C5167D |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDD74C GetSystemMetrics,GetSystemMetrics,MoveWindow,SendMessageW,SendMessageW,ShowWindow,InvalidateRect,NtdllDialogWndProc_W, | 2_2_00CDD74C |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C5189B NtdllDialogWndProc_W, | 2_2_00C5189B |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDDA9A NtdllDialogWndProc_W, | 2_2_00CDDA9A |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CDBF4D NtdllDialogWndProc_W,CallWindowProcW, | 2_2_00CDBF4D |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C53633 NtdllDefWindowProc_W,KillTimer,SetTimer,RegisterClipboardFormatW,CreatePopupMenu,PostQuitMessage,SetFocus,MoveWindow, | 5_2_00C53633 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDC27C ReleaseCapture,SetWindowTextW,SendMessageW,NtdllDialogWndProc_W, | 5_2_00CDC27C |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDC220 NtdllDialogWndProc_W, | 5_2_00CDC220 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDC49C PostMessageW,GetFocus,GetDlgCtrlID,_memset,GetMenuItemInfoW,GetMenuItemCount,GetMenuItemID,GetMenuItemInfoW,GetMenuItemInfoW,CheckMenuRadioItem,NtdllDialogWndProc_W, | 5_2_00CDC49C |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDC788 GetCursorPos,TrackPopupMenuEx,GetCursorPos,NtdllDialogWndProc_W, | 5_2_00CDC788 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDC8EE DragQueryPoint,SendMessageW,DragQueryFileW,DragQueryFileW,_wcscat,SendMessageW,SendMessageW,SendMessageW,SendMessageW,DragFinish,NtdllDialogWndProc_W, | 5_2_00CDC8EE |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDC86D SendMessageW,NtdllDialogWndProc_W, | 5_2_00CDC86D |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDCBF9 NtdllDialogWndProc_W, | 5_2_00CDCBF9 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDCBAE NtdllDialogWndProc_W, | 5_2_00CDCBAE |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDCB50 NtdllDialogWndProc_W, | 5_2_00CDCB50 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDCB7F NtdllDialogWndProc_W, | 5_2_00CDCB7F |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDCC2E ClientToScreen,NtdllDialogWndProc_W, | 5_2_00CDCC2E |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDCDAC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 5_2_00CDCDAC |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDCD6C GetWindowLongW,NtdllDialogWndProc_W, | 5_2_00CDCD6C |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C51287 NtdllDialogWndProc_W,GetSysColor,SetBkColor,745AC8D0,NtdllDialogWndProc_W, | 5_2_00C51287 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C51290 NtdllDialogWndProc_W,GetClientRect,GetCursorPos,ScreenToClient, | 5_2_00C51290 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDD6C6 NtdllDialogWndProc_W, | 5_2_00CDD6C6 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C516DE GetParent,NtdllDialogWndProc_W, | 5_2_00C516DE |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C516B5 NtdllDialogWndProc_W, | 5_2_00C516B5 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C5167D NtdllDialogWndProc_W, | 5_2_00C5167D |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDD74C GetSystemMetrics,GetSystemMetrics,MoveWindow,SendMessageW,SendMessageW,ShowWindow,InvalidateRect,NtdllDialogWndProc_W, | 5_2_00CDD74C |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C5189B NtdllDialogWndProc_W, | 5_2_00C5189B |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDDA9A NtdllDialogWndProc_W, | 5_2_00CDDA9A |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CDBF4D NtdllDialogWndProc_W,CallWindowProcW, | 5_2_00CDBF4D |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DDE800 | 0_2_00DDE800 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DFDBB5 | 0_2_00DFDBB5 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DDFE40 | 0_2_00DDFE40 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E5804A | 0_2_00E5804A |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DDE060 | 0_2_00DDE060 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DE4140 | 0_2_00DE4140 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DF2405 | 0_2_00DF2405 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E06522 | 0_2_00E06522 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E50665 | 0_2_00E50665 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E0267E | 0_2_00E0267E |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DE6843 | 0_2_00DE6843 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DF283A | 0_2_00DF283A |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E089DF | 0_2_00E089DF |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E50AE2 | 0_2_00E50AE2 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E06A94 | 0_2_00E06A94 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DE8A0E | 0_2_00DE8A0E |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E2EB07 | 0_2_00E2EB07 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E38B13 | 0_2_00E38B13 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DFCD61 | 0_2_00DFCD61 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E07006 | 0_2_00E07006 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DE3190 | 0_2_00DE3190 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DE710E | 0_2_00DE710E |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DD1287 | 0_2_00DD1287 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DF33C7 | 0_2_00DF33C7 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DFF419 | 0_2_00DFF419 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DF16C4 | 0_2_00DF16C4 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DE5680 | 0_2_00DE5680 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DF78D3 | 0_2_00DF78D3 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DE58C0 | 0_2_00DE58C0 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DF1BB8 | 0_2_00DF1BB8 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E09D05 | 0_2_00E09D05 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DF1FD0 | 0_2_00DF1FD0 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DFBFE6 | 0_2_00DFBFE6 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_01156318 | 0_2_01156318 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C7DBB5 | 2_2_00C7DBB5 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C5FE40 | 2_2_00C5FE40 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CD804A | 2_2_00CD804A |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C5E060 | 2_2_00C5E060 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C64140 | 2_2_00C64140 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C72405 | 2_2_00C72405 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C86522 | 2_2_00C86522 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CD0665 | 2_2_00CD0665 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C8267E | 2_2_00C8267E |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C66843 | 2_2_00C66843 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C5E800 | 2_2_00C5E800 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C7283A | 2_2_00C7283A |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C889DF | 2_2_00C889DF |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CD0AE2 | 2_2_00CD0AE2 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C86A94 | 2_2_00C86A94 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C68A0E | 2_2_00C68A0E |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CAEB07 | 2_2_00CAEB07 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CB8B13 | 2_2_00CB8B13 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C7CD61 | 2_2_00C7CD61 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C87006 | 2_2_00C87006 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C63190 | 2_2_00C63190 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C6710E | 2_2_00C6710E |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C51287 | 2_2_00C51287 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C733C7 | 2_2_00C733C7 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C7F419 | 2_2_00C7F419 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C716C4 | 2_2_00C716C4 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C65680 | 2_2_00C65680 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C658C0 | 2_2_00C658C0 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C778D3 | 2_2_00C778D3 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C71BB8 | 2_2_00C71BB8 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C89D05 | 2_2_00C89D05 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C71FD0 | 2_2_00C71FD0 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C7BFE6 | 2_2_00C7BFE6 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_011122D8 | 2_2_011122D8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_00A9B48A | 3_2_00A9B48A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_00A94A88 | 3_2_00A94A88 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_00A93E70 | 3_2_00A93E70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_00A941B8 | 3_2_00A941B8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_060E7E50 | 3_2_060E7E50 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_060E66C0 | 3_2_060E66C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_060E2440 | 3_2_060E2440 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_060E5270 | 3_2_060E5270 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_060EB318 | 3_2_060EB318 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_060E7770 | 3_2_060E7770 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_060EE478 | 3_2_060EE478 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_060E0040 | 3_2_060E0040 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_060E59C0 | 3_2_060E59C0 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C7DBB5 | 5_2_00C7DBB5 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CD804A | 5_2_00CD804A |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C5E060 | 5_2_00C5E060 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C64140 | 5_2_00C64140 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C72405 | 5_2_00C72405 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C86522 | 5_2_00C86522 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CD0665 | 5_2_00CD0665 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C8267E | 5_2_00C8267E |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C66843 | 5_2_00C66843 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C5E800 | 5_2_00C5E800 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C7283A | 5_2_00C7283A |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C889DF | 5_2_00C889DF |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CD0AE2 | 5_2_00CD0AE2 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C86A94 | 5_2_00C86A94 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C68A0E | 5_2_00C68A0E |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CAEB07 | 5_2_00CAEB07 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CB8B13 | 5_2_00CB8B13 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C7CD61 | 5_2_00C7CD61 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C87006 | 5_2_00C87006 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C63190 | 5_2_00C63190 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C6710E | 5_2_00C6710E |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C51287 | 5_2_00C51287 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C733C7 | 5_2_00C733C7 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C7F419 | 5_2_00C7F419 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C716C4 | 5_2_00C716C4 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C65680 | 5_2_00C65680 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C658C0 | 5_2_00C658C0 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C778D3 | 5_2_00C778D3 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C71BB8 | 5_2_00C71BB8 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C89D05 | 5_2_00C89D05 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C5FE40 | 5_2_00C5FE40 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C71FD0 | 5_2_00C71FD0 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C7BFE6 | 5_2_00C7BFE6 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_017CF4F0 | 5_2_017CF4F0 |
Source: 2.2.outvaunts.exe.1b30000.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.outvaunts.exe.1b30000.1.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 5.2.outvaunts.exe.3e90000.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 5.2.outvaunts.exe.3e90000.1.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 3.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 3.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 2.2.outvaunts.exe.1b30000.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.outvaunts.exe.1b30000.1.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 5.2.outvaunts.exe.3e90000.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 5.2.outvaunts.exe.3e90000.1.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 00000002.00000002.2069036182.0000000001B30000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 00000002.00000002.2069036182.0000000001B30000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 00000005.00000002.2187439534.0000000003E90000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 00000005.00000002.2187439534.0000000003E90000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00DD4A35 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 0_2_00DD4A35 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E555FD IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 0_2_00E555FD |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00C54A35 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 2_2_00C54A35 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CD55FD IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 2_2_00CD55FD |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00C54A35 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 5_2_00C54A35 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CD55FD IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 5_2_00CD55FD |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599844 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599734 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599624 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599515 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599398 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599252 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599125 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598889 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598343 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598234 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598124 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598015 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597906 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597796 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597687 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597578 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597468 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597359 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597249 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597140 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597031 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596921 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596790 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596560 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596437 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596324 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596217 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596094 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595984 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595874 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595765 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595546 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595437 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595218 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595109 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594999 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594890 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594562 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594453 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599891 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599562 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599453 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599331 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599203 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599094 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598982 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598875 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598766 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598438 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598297 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598092 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597953 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597540 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597438 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597109 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596891 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596563 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596438 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596094 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595985 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595860 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595735 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595610 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595438 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595115 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594975 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594859 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594750 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594641 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594531 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594422 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594312 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594203 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594094 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 593969 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 593859 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 593750 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 593641 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 593531 | Jump to behavior |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E34696 GetFileAttributesW,FindFirstFileW,FindClose, | 0_2_00E34696 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E3C9C7 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 0_2_00E3C9C7 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E3C93C FindFirstFileW,FindClose, | 0_2_00E3C93C |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E3F200 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_00E3F200 |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E3F35D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_00E3F35D |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E3F65E FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_00E3F65E |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E33A2B FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_00E33A2B |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E33D4E FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_00E33D4E |
Source: C:\Users\user\Desktop\toIuQILmr1.exe | Code function: 0_2_00E3BF27 FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_00E3BF27 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CB4696 GetFileAttributesW,FindFirstFileW,FindClose, | 2_2_00CB4696 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CBC9C7 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 2_2_00CBC9C7 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CBC93C FindFirstFileW,FindClose, | 2_2_00CBC93C |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CBF200 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 2_2_00CBF200 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CBF35D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 2_2_00CBF35D |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CBF65E FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 2_2_00CBF65E |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CB3A2B FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 2_2_00CB3A2B |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CB3D4E FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 2_2_00CB3D4E |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 2_2_00CBBF27 FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 2_2_00CBBF27 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CB4696 GetFileAttributesW,FindFirstFileW,FindClose, | 5_2_00CB4696 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CBC9C7 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 5_2_00CBC9C7 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CBC93C FindFirstFileW,FindClose, | 5_2_00CBC93C |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CBF200 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 5_2_00CBF200 |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CBF35D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 5_2_00CBF35D |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CBF65E FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 5_2_00CBF65E |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CB3A2B FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 5_2_00CB3A2B |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CB3D4E FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 5_2_00CB3D4E |
Source: C:\Users\user\AppData\Local\kinematical\outvaunts.exe | Code function: 5_2_00CBBF27 FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 5_2_00CBBF27 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599844 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599734 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599624 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599515 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599398 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599252 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599125 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598889 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598343 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598234 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598124 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598015 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597906 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597796 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597687 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597578 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597468 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597359 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597249 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597140 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597031 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596921 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596790 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596560 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596437 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596324 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596217 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596094 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595984 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595874 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595765 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595546 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595437 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595218 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595109 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594999 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594890 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594562 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594453 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599891 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599562 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599453 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599331 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599203 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599094 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598982 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598875 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598766 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598438 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598297 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598092 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597953 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597540 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597438 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597109 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596891 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596563 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596438 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596094 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595985 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595860 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595735 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595610 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595438 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595115 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594975 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594859 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594750 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594641 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594531 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594422 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594312 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594203 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594094 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 593969 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 593859 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 593750 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 593641 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 593531 | Jump to behavior |