Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B415450 VerSetConditionMask,NtQueryInformationProcess,OpenProcess,QueryFullProcessImageNameW,GetLastError,GetLastError,CloseHandle,getenv,_putenv,getenv,DebugBreak,memset,VerSetConditionMask,VerSetConditionMask,VerSetConditionMask,VerSetConditionMask,VerSetConditionMask,VerSetConditionMask,VerifyVersionInfoW,_wgetenv,wcstoul,GetCurrentProcessId,Sleep,GetCurrentProcess,QueryFullProcessImageNameW,getenv,getenv,GetModuleFileNameW,GetLastError,GetStdHandle,GetStdHandle,GetStdHandle,GetStdHandle,GetLastError,RtlInitUnicodeString,RtlInitUnicodeString,RtlEqualUnicodeString,free,free,free,CloseHandle,CloseHandle,GetStartupInfoW,CreateProcessW,GetLastError,TerminateProcess,ResumeThread,IsDebuggerPresent,GetLastError,TerminateProcess,WaitForSingleObject,CloseHandle,CloseHandle,CloseHandle,GetExitCodeProcess,exit,_Init_thread_header,_invalid_parameter_noinfo_noreturn, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B45D4F0 NtQueryVirtualMemory,RtlNtStatusToDosError,RtlSetLastWin32Error, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B41ACA0 NtReadVirtualMemory, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B45F4D0 NtQueryVirtualMemory,RtlNtStatusToDosError,RtlSetLastWin32Error,_Init_thread_header,GetSystemInfo, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B41CB60 moz_xmalloc,moz_xmalloc,moz_xmalloc,NtQueryVirtualMemory,RtlNtStatusToDosError,RtlSetLastWin32Error,moz_xmalloc, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B41F380 NtQueryVirtualMemory,RtlNtStatusToDosError,RtlSetLastWin32Error,_Init_thread_header,GetSystemInfo, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B423B40 NtQueryVirtualMemory,RtlCompareUnicodeString,RtlAcquireSRWLockShared,RtlRunOnceExecuteOnce,RtlReleaseSRWLockShared,RtlInitAnsiString,RtlAnsiStringToUnicodeString,RtlCompareUnicodeString,RtlFreeUnicodeString,RtlReleaseSRWLockShared,RtlDuplicateUnicodeString,RtlFreeUnicodeString,NtUnmapViewOfSection,RtlReleaseSRWLockShared, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B424BE0 NtQueryObject,NtUnmapViewOfSection, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B4262D0 NtMapViewOfSection,RtlNtStatusToDosError,RtlSetLastWin32Error, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B426130 NtMapViewOfSection,RtlNtStatusToDosError,RtlSetLastWin32Error,memcpy,NtUnmapViewOfSection,RtlNtStatusToDosError,RtlSetLastWin32Error, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B424120 NtMapViewOfSection,RtlNtStatusToDosError,RtlSetLastWin32Error,RtlInitUnicodeString,RtlCompareUnicodeString,RtlGetLastWin32Error,memcpy,memset,NtUnmapViewOfSection,RtlNtStatusToDosError,RtlSetLastWin32Error, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B41B050 NtQueryVirtualMemory,RtlNtStatusToDosError,RtlSetLastWin32Error, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B425FB0 CreateFileMappingW,RtlNtStatusToDosError,RtlSetLastWin32Error,GetLastError,GetLastError,NtUnmapViewOfSection,RtlNtStatusToDosError,RtlSetLastWin32Error, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B425620 NtQueryVirtualMemory,RtlDuplicateUnicodeString, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B425700 NtQueryVirtualMemory,memmove, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B41FEA0 rand_s,NtQueryVirtualMemory,NtQueryVirtualMemory,RtlNtStatusToDosError,RtlSetLastWin32Error,GetLastError,_Init_thread_header,GetSystemInfo, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B45CD50 NtQueryVirtualMemory,GetProcAddress,NtQueryVirtualMemory,RtlNtStatusToDosError,RtlSetLastWin32Error, |
Source: C:\Users\user\Desktop\zotero.exe | Code function: 0_2_00007FF78B425D40 NtQueryInformationProcess,RtlCompareUnicodeString, |