Source: 0.2.stage4.exe.1200000.1.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0.2.stage4.exe.1200000.1.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000000.00000002.395568798.0000000000DD0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000000.00000002.395568798.0000000000DD0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000000.00000002.395880682.0000000001201000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000000.00000002.395880682.0000000001201000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000016.00000002.526444104.0000000005250000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000016.00000002.526444104.0000000005250000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000001.00000000.285941222.000000000F494000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000001.00000000.285941222.000000000F494000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000000.00000002.396449038.0000000001774000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000000.00000002.396449038.0000000001774000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000000.00000002.395697071.0000000000E50000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000000.00000002.395697071.0000000000E50000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000016.00000002.523558447.0000000003480000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000016.00000002.523558447.0000000003480000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000001.00000000.305769049.000000000F494000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000001.00000000.305769049.000000000F494000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000016.00000002.522501930.00000000010D0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000016.00000002.522501930.00000000010D0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000F.00000000.382178283.00000000076F8000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000F.00000000.382178283.00000000076F8000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000F.00000000.362332180.00000000076F8000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000F.00000000.362332180.00000000076F8000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: C:\Users\user\Desktop\stage4.exe | Code function: 0_2_012185D0 NtCreateFile, | 0_2_012185D0 |
Source: C:\Users\user\Desktop\stage4.exe | Code function: 0_2_01218700 NtClose, | 0_2_01218700 |
Source: C:\Users\user\Desktop\stage4.exe | Code function: 0_2_012187B0 NtAllocateVirtualMemory, | 0_2_012187B0 |
Source: C:\Users\user\Desktop\stage4.exe | Code function: 0_2_01218680 NtReadFile, | 0_2_01218680 |
Source: C:\Users\user\Desktop\stage4.exe | Code function: 0_2_012185CA NtCreateFile, | 0_2_012185CA |
Source: C:\Users\user\Desktop\stage4.exe | Code function: 0_2_012187AA NtAllocateVirtualMemory, | 0_2_012187AA |
Source: C:\Users\user\Desktop\stage4.exe | Code function: 0_2_0121867C NtReadFile, | 0_2_0121867C |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9540 NtReadFile,LdrInitializeThunk, | 22_2_054F9540 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F95D0 NtClose,LdrInitializeThunk, | 22_2_054F95D0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9710 NtQueryInformationToken,LdrInitializeThunk, | 22_2_054F9710 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9FE0 NtCreateMutant,LdrInitializeThunk, | 22_2_054F9FE0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9780 NtMapViewOfSection,LdrInitializeThunk, | 22_2_054F9780 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9650 NtQueryValueKey,LdrInitializeThunk, | 22_2_054F9650 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9660 NtAllocateVirtualMemory,LdrInitializeThunk, | 22_2_054F9660 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F96D0 NtCreateKey,LdrInitializeThunk, | 22_2_054F96D0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F96E0 NtFreeVirtualMemory,LdrInitializeThunk, | 22_2_054F96E0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9910 NtAdjustPrivilegesToken,LdrInitializeThunk, | 22_2_054F9910 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F99A0 NtCreateSection,LdrInitializeThunk, | 22_2_054F99A0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9840 NtDelayExecution,LdrInitializeThunk, | 22_2_054F9840 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9860 NtQuerySystemInformation,LdrInitializeThunk, | 22_2_054F9860 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9A50 NtCreateFile,LdrInitializeThunk, | 22_2_054F9A50 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9560 NtWriteFile, | 22_2_054F9560 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9520 NtWaitForSingleObject, | 22_2_054F9520 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054FAD30 NtSetContextThread, | 22_2_054FAD30 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F95F0 NtQueryInformationFile, | 22_2_054F95F0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9760 NtOpenProcess, | 22_2_054F9760 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054FA770 NtOpenThread, | 22_2_054FA770 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9770 NtSetInformationFile, | 22_2_054F9770 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054FA710 NtOpenProcessToken, | 22_2_054FA710 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9730 NtQueryVirtualMemory, | 22_2_054F9730 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F97A0 NtUnmapViewOfSection, | 22_2_054F97A0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9670 NtQueryInformationProcess, | 22_2_054F9670 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9610 NtEnumerateValueKey, | 22_2_054F9610 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9950 NtQueueApcThread, | 22_2_054F9950 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F99D0 NtCreateProcessEx, | 22_2_054F99D0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054FB040 NtSuspendThread, | 22_2_054FB040 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9820 NtEnumerateKey, | 22_2_054F9820 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F98F0 NtReadVirtualMemory, | 22_2_054F98F0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F98A0 NtWriteVirtualMemory, | 22_2_054F98A0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9B00 NtSetValueKey, | 22_2_054F9B00 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054FA3B0 NtGetContextThread, | 22_2_054FA3B0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9A00 NtProtectVirtualMemory, | 22_2_054F9A00 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9A10 NtQuerySection, | 22_2_054F9A10 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9A20 NtResumeThread, | 22_2_054F9A20 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F9A80 NtOpenDirectoryObject, | 22_2_054F9A80 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_010E85D0 NtCreateFile, | 22_2_010E85D0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_010E8700 NtClose, | 22_2_010E8700 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_010E87B0 NtAllocateVirtualMemory, | 22_2_010E87B0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_010E8680 NtReadFile, | 22_2_010E8680 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_010E85CA NtCreateFile, | 22_2_010E85CA |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_010E87AA NtAllocateVirtualMemory, | 22_2_010E87AA |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_010E867C NtReadFile, | 22_2_010E867C |
Source: explorer.exe, 0000000F.00000000.359059122.0000000005CF6000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}.1_neutQ |
Source: explorer.exe, 0000000F.00000003.344090419.0000000008610000.00000004.00000001.sdmp | Binary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\5&280b647&0&000000Z |
Source: explorer.exe, 0000000F.00000000.358953220.0000000005C70000.00000004.00000001.sdmp | Binary or memory string: NECVMWarVMware SATA CD001.00WBG |
Source: explorer.exe, 0000000F.00000000.358953220.0000000005C70000.00000004.00000001.sdmp | Binary or memory string: NECVMWarVMware SATA CD001.00 |
Source: explorer.exe, 0000000F.00000000.385407093.00000000087B3000.00000004.00000001.sdmp | Binary or memory string: SCSI\CDROM&VEN_NECVMWAR&PROD_VMWARE_SATA_CD00\5&280B647&0&000000R |
Source: explorer.exe, 0000000F.00000000.359059122.0000000005CF6000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 00000001.00000000.255243120.00000000011B3000.00000004.00000020.sdmp | Binary or memory string: fb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5& 6 |
Source: explorer.exe, 0000000F.00000003.349672505.0000000008816000.00000004.00000001.sdmp | Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#5&280b647&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 0000000F.00000003.349066047.00000000087EB000.00000004.00000001.sdmp | Binary or memory string: war&prod_vmware_sata_cd00#5& |
Source: explorer.exe, 0000000F.00000003.380241749.00000000087E8000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}Bn |
Source: explorer.exe, 0000000F.00000000.358953220.0000000005C70000.00000004.00000001.sdmp | Binary or memory string: VMware SATA CD00 |
Source: explorer.exe, 0000000F.00000003.354472315.00000000087AE000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B |
Source: explorer.exe, 00000001.00000000.255243120.00000000011B3000.00000004.00000020.sdmp | Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\5&1ec51bf7&0&000000tft\0 |
Source: explorer.exe, 0000000F.00000000.359006696.0000000005CAF000.00000004.00000001.sdmp | Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\5&1ec51bf7&0&000000b |
Source: explorer.exe, 0000000F.00000003.380241749.00000000087E8000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}Be |
Source: explorer.exe, 0000000F.00000003.344802418.00000000086AA000.00000004.00000001.sdmp | Binary or memory string: \\?\SCSI#Disk&Ven_VMware&Prod_Virtual_disk#5&1ec51bf7&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}ri& |
Source: explorer.exe, 0000000F.00000003.354483065.00000000087B0000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}Bg |
Source: explorer.exe, 00000001.00000000.264327118.00000000089B5000.00000004.00000001.sdmp | Binary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\5&280b647&0&0000002 |
Source: explorer.exe, 0000000F.00000003.349672505.0000000008816000.00000004.00000001.sdmp | Binary or memory string: \??\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#5&280b647&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\h |
Source: explorer.exe, 0000000F.00000003.381262125.00000000087E7000.00000004.00000001.sdmp | Binary or memory string: VMware SATA CD00f |
Source: explorer.exe, 0000000F.00000003.354472315.00000000087AE000.00000004.00000001.sdmp | Binary or memory string: 2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B] |
Source: explorer.exe, 0000000F.00000000.358953220.0000000005C70000.00000004.00000001.sdmp | Binary or memory string: NECVMWarVMware SATA CD001.00C |
Source: explorer.exe, 0000000F.00000003.349672505.0000000008816000.00000004.00000001.sdmp | Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#5&280b647&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 0000000F.00000003.345040104.0000000008610000.00000004.00000001.sdmp | Binary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\5&280b647&0&000000~ |
Source: explorer.exe, 0000000F.00000003.354705201.00000000085E7000.00000004.00000001.sdmp | Binary or memory string: VMware SATA CD00e |
Source: explorer.exe, 0000000F.00000003.354472315.00000000087AE000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00 |
Source: explorer.exe, 0000000F.00000003.344899906.0000000008703000.00000004.00000001.sdmp | Binary or memory string: ;;SCSI\Disk&Ven_VMware&Prod_Virtual_disk\5&1ec51bf7&0&000000 |
Source: explorer.exe, 0000000F.00000000.379208597.0000000005E3F000.00000004.00000001.sdmp | Binary or memory string: VMware SATA CD00 |
Source: explorer.exe, 0000000F.00000003.349672505.0000000008816000.00000004.00000001.sdmp | Binary or memory string: \??\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#5&280b647&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 0000000F.00000003.380241749.00000000087E8000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B |
Source: explorer.exe, 0000000F.00000003.380241749.00000000087E8000.00000004.00000001.sdmp | Binary or memory string: me#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B[ |
Source: explorer.exe, 0000000F.00000000.316777777.0000000000A07000.00000004.00000020.sdmp | Binary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 0000000F.00000003.344899906.0000000008703000.00000004.00000001.sdmp | Binary or memory string: AASCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\5&280b647&0&000000 |
Source: explorer.exe, 0000000F.00000003.349672505.0000000008816000.00000004.00000001.sdmp | Binary or memory string: _VMware_SATA_CD00#5& |
Source: explorer.exe, 0000000F.00000003.349949395.000000000870A000.00000004.00000001.sdmp | Binary or memory string: 9Tm\Device\HarddiskVolume2\??\Volume{ef47ea26-ec76-4a6e-8680-9e53b539546d}\??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{e6e9dfd8-98f2-11e9-90ce-806e6f6e6963}\DosDevices\D: |
Source: explorer.exe, 0000000F.00000003.380336457.000000000881E000.00000004.00000001.sdmp | Binary or memory string: STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B\ |
Source: explorer.exe, 0000000F.00000000.316777777.0000000000A07000.00000004.00000020.sdmp | Binary or memory string: SCSI\CDROM&VEN_NECVMWAR&PROD_VMWARE_SATA_CD00\5&280B647&0&000000k4 |
Source: explorer.exe, 00000001.00000000.264327118.00000000089B5000.00000004.00000001.sdmp | Binary or memory string: SCSI\CDROM&VEN_NECVMWAR&PROD_VMWARE_SATA_CD00\5&280B647&0&000000% |
Source: explorer.exe, 00000001.00000000.274439870.00000000053C4000.00000004.00000001.sdmp | Binary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}>'R\" |
Source: explorer.exe, 0000000F.00000000.359059122.0000000005CF6000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}[ |
Source: explorer.exe, 0000000F.00000003.380241749.00000000087E8000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}B** |
Source: explorer.exe, 0000000F.00000000.364230659.00000000085A5000.00000004.00000001.sdmp | Binary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\5&280b647&0&000000 |
Source: explorer.exe, 0000000F.00000003.331167484.0000000005CFA000.00000004.00000001.sdmp | Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}are\Cla |
Source: explorer.exe, 0000000F.00000003.344899906.0000000008703000.00000004.00000001.sdmp | Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\5&1ec51bf7&0&000000C@v |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F3D43 mov eax, dword ptr fs:[00000030h] | 22_2_054F3D43 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05533540 mov eax, dword ptr fs:[00000030h] | 22_2_05533540 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054D7D50 mov eax, dword ptr fs:[00000030h] | 22_2_054D7D50 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054DC577 mov eax, dword ptr fs:[00000030h] | 22_2_054DC577 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054DC577 mov eax, dword ptr fs:[00000030h] | 22_2_054DC577 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0553A537 mov eax, dword ptr fs:[00000030h] | 22_2_0553A537 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05588D34 mov eax, dword ptr fs:[00000030h] | 22_2_05588D34 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0557E539 mov eax, dword ptr fs:[00000030h] | 22_2_0557E539 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E4D3B mov eax, dword ptr fs:[00000030h] | 22_2_054E4D3B |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E4D3B mov eax, dword ptr fs:[00000030h] | 22_2_054E4D3B |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E4D3B mov eax, dword ptr fs:[00000030h] | 22_2_054E4D3B |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C3D34 mov eax, dword ptr fs:[00000030h] | 22_2_054C3D34 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C3D34 mov eax, dword ptr fs:[00000030h] | 22_2_054C3D34 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C3D34 mov eax, dword ptr fs:[00000030h] | 22_2_054C3D34 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C3D34 mov eax, dword ptr fs:[00000030h] | 22_2_054C3D34 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C3D34 mov eax, dword ptr fs:[00000030h] | 22_2_054C3D34 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C3D34 mov eax, dword ptr fs:[00000030h] | 22_2_054C3D34 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C3D34 mov eax, dword ptr fs:[00000030h] | 22_2_054C3D34 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C3D34 mov eax, dword ptr fs:[00000030h] | 22_2_054C3D34 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C3D34 mov eax, dword ptr fs:[00000030h] | 22_2_054C3D34 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C3D34 mov eax, dword ptr fs:[00000030h] | 22_2_054C3D34 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C3D34 mov eax, dword ptr fs:[00000030h] | 22_2_054C3D34 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C3D34 mov eax, dword ptr fs:[00000030h] | 22_2_054C3D34 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C3D34 mov eax, dword ptr fs:[00000030h] | 22_2_054C3D34 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054BAD30 mov eax, dword ptr fs:[00000030h] | 22_2_054BAD30 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05536DC9 mov eax, dword ptr fs:[00000030h] | 22_2_05536DC9 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05536DC9 mov eax, dword ptr fs:[00000030h] | 22_2_05536DC9 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05536DC9 mov eax, dword ptr fs:[00000030h] | 22_2_05536DC9 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05536DC9 mov ecx, dword ptr fs:[00000030h] | 22_2_05536DC9 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05536DC9 mov eax, dword ptr fs:[00000030h] | 22_2_05536DC9 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05536DC9 mov eax, dword ptr fs:[00000030h] | 22_2_05536DC9 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05568DF1 mov eax, dword ptr fs:[00000030h] | 22_2_05568DF1 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054CD5E0 mov eax, dword ptr fs:[00000030h] | 22_2_054CD5E0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054CD5E0 mov eax, dword ptr fs:[00000030h] | 22_2_054CD5E0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0557FDE2 mov eax, dword ptr fs:[00000030h] | 22_2_0557FDE2 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0557FDE2 mov eax, dword ptr fs:[00000030h] | 22_2_0557FDE2 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0557FDE2 mov eax, dword ptr fs:[00000030h] | 22_2_0557FDE2 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0557FDE2 mov eax, dword ptr fs:[00000030h] | 22_2_0557FDE2 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B2D8A mov eax, dword ptr fs:[00000030h] | 22_2_054B2D8A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B2D8A mov eax, dword ptr fs:[00000030h] | 22_2_054B2D8A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B2D8A mov eax, dword ptr fs:[00000030h] | 22_2_054B2D8A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B2D8A mov eax, dword ptr fs:[00000030h] | 22_2_054B2D8A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B2D8A mov eax, dword ptr fs:[00000030h] | 22_2_054B2D8A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E2581 mov eax, dword ptr fs:[00000030h] | 22_2_054E2581 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E2581 mov eax, dword ptr fs:[00000030h] | 22_2_054E2581 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E2581 mov eax, dword ptr fs:[00000030h] | 22_2_054E2581 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E2581 mov eax, dword ptr fs:[00000030h] | 22_2_054E2581 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054EFD9B mov eax, dword ptr fs:[00000030h] | 22_2_054EFD9B |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054EFD9B mov eax, dword ptr fs:[00000030h] | 22_2_054EFD9B |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E35A1 mov eax, dword ptr fs:[00000030h] | 22_2_054E35A1 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_055805AC mov eax, dword ptr fs:[00000030h] | 22_2_055805AC |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_055805AC mov eax, dword ptr fs:[00000030h] | 22_2_055805AC |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E1DB5 mov eax, dword ptr fs:[00000030h] | 22_2_054E1DB5 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E1DB5 mov eax, dword ptr fs:[00000030h] | 22_2_054E1DB5 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E1DB5 mov eax, dword ptr fs:[00000030h] | 22_2_054E1DB5 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0554C450 mov eax, dword ptr fs:[00000030h] | 22_2_0554C450 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0554C450 mov eax, dword ptr fs:[00000030h] | 22_2_0554C450 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054EA44B mov eax, dword ptr fs:[00000030h] | 22_2_054EA44B |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054D746D mov eax, dword ptr fs:[00000030h] | 22_2_054D746D |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05571C06 mov eax, dword ptr fs:[00000030h] | 22_2_05571C06 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05571C06 mov eax, dword ptr fs:[00000030h] | 22_2_05571C06 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05571C06 mov eax, dword ptr fs:[00000030h] | 22_2_05571C06 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05571C06 mov eax, dword ptr fs:[00000030h] | 22_2_05571C06 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05571C06 mov eax, dword ptr fs:[00000030h] | 22_2_05571C06 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05571C06 mov eax, dword ptr fs:[00000030h] | 22_2_05571C06 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05571C06 mov eax, dword ptr fs:[00000030h] | 22_2_05571C06 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05571C06 mov eax, dword ptr fs:[00000030h] | 22_2_05571C06 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05571C06 mov eax, dword ptr fs:[00000030h] | 22_2_05571C06 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05571C06 mov eax, dword ptr fs:[00000030h] | 22_2_05571C06 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05571C06 mov eax, dword ptr fs:[00000030h] | 22_2_05571C06 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05571C06 mov eax, dword ptr fs:[00000030h] | 22_2_05571C06 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05571C06 mov eax, dword ptr fs:[00000030h] | 22_2_05571C06 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05571C06 mov eax, dword ptr fs:[00000030h] | 22_2_05571C06 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0558740D mov eax, dword ptr fs:[00000030h] | 22_2_0558740D |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0558740D mov eax, dword ptr fs:[00000030h] | 22_2_0558740D |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0558740D mov eax, dword ptr fs:[00000030h] | 22_2_0558740D |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05536C0A mov eax, dword ptr fs:[00000030h] | 22_2_05536C0A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05536C0A mov eax, dword ptr fs:[00000030h] | 22_2_05536C0A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05536C0A mov eax, dword ptr fs:[00000030h] | 22_2_05536C0A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05536C0A mov eax, dword ptr fs:[00000030h] | 22_2_05536C0A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054EBC2C mov eax, dword ptr fs:[00000030h] | 22_2_054EBC2C |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05588CD6 mov eax, dword ptr fs:[00000030h] | 22_2_05588CD6 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05536CF0 mov eax, dword ptr fs:[00000030h] | 22_2_05536CF0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05536CF0 mov eax, dword ptr fs:[00000030h] | 22_2_05536CF0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05536CF0 mov eax, dword ptr fs:[00000030h] | 22_2_05536CF0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_055714FB mov eax, dword ptr fs:[00000030h] | 22_2_055714FB |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C849B mov eax, dword ptr fs:[00000030h] | 22_2_054C849B |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054CEF40 mov eax, dword ptr fs:[00000030h] | 22_2_054CEF40 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054CFF60 mov eax, dword ptr fs:[00000030h] | 22_2_054CFF60 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05588F6A mov eax, dword ptr fs:[00000030h] | 22_2_05588F6A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054EA70E mov eax, dword ptr fs:[00000030h] | 22_2_054EA70E |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054EA70E mov eax, dword ptr fs:[00000030h] | 22_2_054EA70E |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0554FF10 mov eax, dword ptr fs:[00000030h] | 22_2_0554FF10 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0554FF10 mov eax, dword ptr fs:[00000030h] | 22_2_0554FF10 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0558070D mov eax, dword ptr fs:[00000030h] | 22_2_0558070D |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0558070D mov eax, dword ptr fs:[00000030h] | 22_2_0558070D |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054DF716 mov eax, dword ptr fs:[00000030h] | 22_2_054DF716 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B4F2E mov eax, dword ptr fs:[00000030h] | 22_2_054B4F2E |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B4F2E mov eax, dword ptr fs:[00000030h] | 22_2_054B4F2E |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054EE730 mov eax, dword ptr fs:[00000030h] | 22_2_054EE730 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F37F5 mov eax, dword ptr fs:[00000030h] | 22_2_054F37F5 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05537794 mov eax, dword ptr fs:[00000030h] | 22_2_05537794 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05537794 mov eax, dword ptr fs:[00000030h] | 22_2_05537794 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05537794 mov eax, dword ptr fs:[00000030h] | 22_2_05537794 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C8794 mov eax, dword ptr fs:[00000030h] | 22_2_054C8794 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C7E41 mov eax, dword ptr fs:[00000030h] | 22_2_054C7E41 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C7E41 mov eax, dword ptr fs:[00000030h] | 22_2_054C7E41 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C7E41 mov eax, dword ptr fs:[00000030h] | 22_2_054C7E41 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C7E41 mov eax, dword ptr fs:[00000030h] | 22_2_054C7E41 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C7E41 mov eax, dword ptr fs:[00000030h] | 22_2_054C7E41 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C7E41 mov eax, dword ptr fs:[00000030h] | 22_2_054C7E41 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0557AE44 mov eax, dword ptr fs:[00000030h] | 22_2_0557AE44 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0557AE44 mov eax, dword ptr fs:[00000030h] | 22_2_0557AE44 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C766D mov eax, dword ptr fs:[00000030h] | 22_2_054C766D |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054DAE73 mov eax, dword ptr fs:[00000030h] | 22_2_054DAE73 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054DAE73 mov eax, dword ptr fs:[00000030h] | 22_2_054DAE73 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054DAE73 mov eax, dword ptr fs:[00000030h] | 22_2_054DAE73 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054DAE73 mov eax, dword ptr fs:[00000030h] | 22_2_054DAE73 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054DAE73 mov eax, dword ptr fs:[00000030h] | 22_2_054DAE73 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054BC600 mov eax, dword ptr fs:[00000030h] | 22_2_054BC600 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054BC600 mov eax, dword ptr fs:[00000030h] | 22_2_054BC600 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054BC600 mov eax, dword ptr fs:[00000030h] | 22_2_054BC600 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E8E00 mov eax, dword ptr fs:[00000030h] | 22_2_054E8E00 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054EA61C mov eax, dword ptr fs:[00000030h] | 22_2_054EA61C |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054EA61C mov eax, dword ptr fs:[00000030h] | 22_2_054EA61C |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05571608 mov eax, dword ptr fs:[00000030h] | 22_2_05571608 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0556FE3F mov eax, dword ptr fs:[00000030h] | 22_2_0556FE3F |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054BE620 mov eax, dword ptr fs:[00000030h] | 22_2_054BE620 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E36CC mov eax, dword ptr fs:[00000030h] | 22_2_054E36CC |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F8EC7 mov eax, dword ptr fs:[00000030h] | 22_2_054F8EC7 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05588ED6 mov eax, dword ptr fs:[00000030h] | 22_2_05588ED6 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0556FEC0 mov eax, dword ptr fs:[00000030h] | 22_2_0556FEC0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E16E0 mov ecx, dword ptr fs:[00000030h] | 22_2_054E16E0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C76E2 mov eax, dword ptr fs:[00000030h] | 22_2_054C76E2 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0554FE87 mov eax, dword ptr fs:[00000030h] | 22_2_0554FE87 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_055346A7 mov eax, dword ptr fs:[00000030h] | 22_2_055346A7 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05580EA5 mov eax, dword ptr fs:[00000030h] | 22_2_05580EA5 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05580EA5 mov eax, dword ptr fs:[00000030h] | 22_2_05580EA5 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05580EA5 mov eax, dword ptr fs:[00000030h] | 22_2_05580EA5 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054DB944 mov eax, dword ptr fs:[00000030h] | 22_2_054DB944 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054DB944 mov eax, dword ptr fs:[00000030h] | 22_2_054DB944 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054BC962 mov eax, dword ptr fs:[00000030h] | 22_2_054BC962 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054BB171 mov eax, dword ptr fs:[00000030h] | 22_2_054BB171 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054BB171 mov eax, dword ptr fs:[00000030h] | 22_2_054BB171 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B9100 mov eax, dword ptr fs:[00000030h] | 22_2_054B9100 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B9100 mov eax, dword ptr fs:[00000030h] | 22_2_054B9100 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B9100 mov eax, dword ptr fs:[00000030h] | 22_2_054B9100 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054D4120 mov eax, dword ptr fs:[00000030h] | 22_2_054D4120 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054D4120 mov eax, dword ptr fs:[00000030h] | 22_2_054D4120 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054D4120 mov eax, dword ptr fs:[00000030h] | 22_2_054D4120 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054D4120 mov eax, dword ptr fs:[00000030h] | 22_2_054D4120 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054D4120 mov ecx, dword ptr fs:[00000030h] | 22_2_054D4120 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E513A mov eax, dword ptr fs:[00000030h] | 22_2_054E513A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E513A mov eax, dword ptr fs:[00000030h] | 22_2_054E513A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054BB1E1 mov eax, dword ptr fs:[00000030h] | 22_2_054BB1E1 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054BB1E1 mov eax, dword ptr fs:[00000030h] | 22_2_054BB1E1 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054BB1E1 mov eax, dword ptr fs:[00000030h] | 22_2_054BB1E1 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_055441E8 mov eax, dword ptr fs:[00000030h] | 22_2_055441E8 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054EA185 mov eax, dword ptr fs:[00000030h] | 22_2_054EA185 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054DC182 mov eax, dword ptr fs:[00000030h] | 22_2_054DC182 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E2990 mov eax, dword ptr fs:[00000030h] | 22_2_054E2990 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_055351BE mov eax, dword ptr fs:[00000030h] | 22_2_055351BE |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_055351BE mov eax, dword ptr fs:[00000030h] | 22_2_055351BE |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_055351BE mov eax, dword ptr fs:[00000030h] | 22_2_055351BE |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_055351BE mov eax, dword ptr fs:[00000030h] | 22_2_055351BE |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E61A0 mov eax, dword ptr fs:[00000030h] | 22_2_054E61A0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E61A0 mov eax, dword ptr fs:[00000030h] | 22_2_054E61A0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_055369A6 mov eax, dword ptr fs:[00000030h] | 22_2_055369A6 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054D0050 mov eax, dword ptr fs:[00000030h] | 22_2_054D0050 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054D0050 mov eax, dword ptr fs:[00000030h] | 22_2_054D0050 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05572073 mov eax, dword ptr fs:[00000030h] | 22_2_05572073 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05581074 mov eax, dword ptr fs:[00000030h] | 22_2_05581074 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05537016 mov eax, dword ptr fs:[00000030h] | 22_2_05537016 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05537016 mov eax, dword ptr fs:[00000030h] | 22_2_05537016 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05537016 mov eax, dword ptr fs:[00000030h] | 22_2_05537016 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05584015 mov eax, dword ptr fs:[00000030h] | 22_2_05584015 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05584015 mov eax, dword ptr fs:[00000030h] | 22_2_05584015 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E002D mov eax, dword ptr fs:[00000030h] | 22_2_054E002D |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E002D mov eax, dword ptr fs:[00000030h] | 22_2_054E002D |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E002D mov eax, dword ptr fs:[00000030h] | 22_2_054E002D |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E002D mov eax, dword ptr fs:[00000030h] | 22_2_054E002D |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E002D mov eax, dword ptr fs:[00000030h] | 22_2_054E002D |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054CB02A mov eax, dword ptr fs:[00000030h] | 22_2_054CB02A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054CB02A mov eax, dword ptr fs:[00000030h] | 22_2_054CB02A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054CB02A mov eax, dword ptr fs:[00000030h] | 22_2_054CB02A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054CB02A mov eax, dword ptr fs:[00000030h] | 22_2_054CB02A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0554B8D0 mov eax, dword ptr fs:[00000030h] | 22_2_0554B8D0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0554B8D0 mov ecx, dword ptr fs:[00000030h] | 22_2_0554B8D0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0554B8D0 mov eax, dword ptr fs:[00000030h] | 22_2_0554B8D0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0554B8D0 mov eax, dword ptr fs:[00000030h] | 22_2_0554B8D0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0554B8D0 mov eax, dword ptr fs:[00000030h] | 22_2_0554B8D0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0554B8D0 mov eax, dword ptr fs:[00000030h] | 22_2_0554B8D0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B58EC mov eax, dword ptr fs:[00000030h] | 22_2_054B58EC |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B9080 mov eax, dword ptr fs:[00000030h] | 22_2_054B9080 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05533884 mov eax, dword ptr fs:[00000030h] | 22_2_05533884 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05533884 mov eax, dword ptr fs:[00000030h] | 22_2_05533884 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F90AF mov eax, dword ptr fs:[00000030h] | 22_2_054F90AF |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E20A0 mov eax, dword ptr fs:[00000030h] | 22_2_054E20A0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E20A0 mov eax, dword ptr fs:[00000030h] | 22_2_054E20A0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E20A0 mov eax, dword ptr fs:[00000030h] | 22_2_054E20A0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E20A0 mov eax, dword ptr fs:[00000030h] | 22_2_054E20A0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E20A0 mov eax, dword ptr fs:[00000030h] | 22_2_054E20A0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E20A0 mov eax, dword ptr fs:[00000030h] | 22_2_054E20A0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054EF0BF mov ecx, dword ptr fs:[00000030h] | 22_2_054EF0BF |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054EF0BF mov eax, dword ptr fs:[00000030h] | 22_2_054EF0BF |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054EF0BF mov eax, dword ptr fs:[00000030h] | 22_2_054EF0BF |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05588B58 mov eax, dword ptr fs:[00000030h] | 22_2_05588B58 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054BDB40 mov eax, dword ptr fs:[00000030h] | 22_2_054BDB40 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054BF358 mov eax, dword ptr fs:[00000030h] | 22_2_054BF358 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054BDB60 mov ecx, dword ptr fs:[00000030h] | 22_2_054BDB60 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E3B7A mov eax, dword ptr fs:[00000030h] | 22_2_054E3B7A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E3B7A mov eax, dword ptr fs:[00000030h] | 22_2_054E3B7A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0557131B mov eax, dword ptr fs:[00000030h] | 22_2_0557131B |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_055353CA mov eax, dword ptr fs:[00000030h] | 22_2_055353CA |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_055353CA mov eax, dword ptr fs:[00000030h] | 22_2_055353CA |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054DDBE9 mov eax, dword ptr fs:[00000030h] | 22_2_054DDBE9 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E03E2 mov eax, dword ptr fs:[00000030h] | 22_2_054E03E2 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E03E2 mov eax, dword ptr fs:[00000030h] | 22_2_054E03E2 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E03E2 mov eax, dword ptr fs:[00000030h] | 22_2_054E03E2 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E03E2 mov eax, dword ptr fs:[00000030h] | 22_2_054E03E2 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E03E2 mov eax, dword ptr fs:[00000030h] | 22_2_054E03E2 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E03E2 mov eax, dword ptr fs:[00000030h] | 22_2_054E03E2 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C1B8F mov eax, dword ptr fs:[00000030h] | 22_2_054C1B8F |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C1B8F mov eax, dword ptr fs:[00000030h] | 22_2_054C1B8F |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0556D380 mov ecx, dword ptr fs:[00000030h] | 22_2_0556D380 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E2397 mov eax, dword ptr fs:[00000030h] | 22_2_054E2397 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0557138A mov eax, dword ptr fs:[00000030h] | 22_2_0557138A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054EB390 mov eax, dword ptr fs:[00000030h] | 22_2_054EB390 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E4BAD mov eax, dword ptr fs:[00000030h] | 22_2_054E4BAD |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E4BAD mov eax, dword ptr fs:[00000030h] | 22_2_054E4BAD |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E4BAD mov eax, dword ptr fs:[00000030h] | 22_2_054E4BAD |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05585BA5 mov eax, dword ptr fs:[00000030h] | 22_2_05585BA5 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0557EA55 mov eax, dword ptr fs:[00000030h] | 22_2_0557EA55 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05544257 mov eax, dword ptr fs:[00000030h] | 22_2_05544257 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B9240 mov eax, dword ptr fs:[00000030h] | 22_2_054B9240 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B9240 mov eax, dword ptr fs:[00000030h] | 22_2_054B9240 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B9240 mov eax, dword ptr fs:[00000030h] | 22_2_054B9240 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B9240 mov eax, dword ptr fs:[00000030h] | 22_2_054B9240 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F927A mov eax, dword ptr fs:[00000030h] | 22_2_054F927A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0556B260 mov eax, dword ptr fs:[00000030h] | 22_2_0556B260 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0556B260 mov eax, dword ptr fs:[00000030h] | 22_2_0556B260 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_05588A62 mov eax, dword ptr fs:[00000030h] | 22_2_05588A62 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0557AA16 mov eax, dword ptr fs:[00000030h] | 22_2_0557AA16 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_0557AA16 mov eax, dword ptr fs:[00000030h] | 22_2_0557AA16 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054C8A0A mov eax, dword ptr fs:[00000030h] | 22_2_054C8A0A |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054D3A1C mov eax, dword ptr fs:[00000030h] | 22_2_054D3A1C |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B5210 mov eax, dword ptr fs:[00000030h] | 22_2_054B5210 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B5210 mov ecx, dword ptr fs:[00000030h] | 22_2_054B5210 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B5210 mov eax, dword ptr fs:[00000030h] | 22_2_054B5210 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B5210 mov eax, dword ptr fs:[00000030h] | 22_2_054B5210 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054BAA16 mov eax, dword ptr fs:[00000030h] | 22_2_054BAA16 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054BAA16 mov eax, dword ptr fs:[00000030h] | 22_2_054BAA16 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F4A2C mov eax, dword ptr fs:[00000030h] | 22_2_054F4A2C |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054F4A2C mov eax, dword ptr fs:[00000030h] | 22_2_054F4A2C |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E2ACB mov eax, dword ptr fs:[00000030h] | 22_2_054E2ACB |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054E2AE4 mov eax, dword ptr fs:[00000030h] | 22_2_054E2AE4 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054ED294 mov eax, dword ptr fs:[00000030h] | 22_2_054ED294 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054ED294 mov eax, dword ptr fs:[00000030h] | 22_2_054ED294 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B52A5 mov eax, dword ptr fs:[00000030h] | 22_2_054B52A5 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B52A5 mov eax, dword ptr fs:[00000030h] | 22_2_054B52A5 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B52A5 mov eax, dword ptr fs:[00000030h] | 22_2_054B52A5 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B52A5 mov eax, dword ptr fs:[00000030h] | 22_2_054B52A5 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054B52A5 mov eax, dword ptr fs:[00000030h] | 22_2_054B52A5 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054CAAB0 mov eax, dword ptr fs:[00000030h] | 22_2_054CAAB0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054CAAB0 mov eax, dword ptr fs:[00000030h] | 22_2_054CAAB0 |
Source: C:\Windows\SysWOW64\cscript.exe | Code function: 22_2_054EFAB0 mov eax, dword ptr fs:[00000030h] | 22_2_054EFAB0 |