Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005DD420 SendDlgItemMessageW,GetDlgItem,SetDlgItemTextW,SendDlgItemMessageW,FindFirstFileW,_swprintf,SetDlgItemTextW,FindClose,_swprintf,SetDlgItemTextW,SendDlgItemMessageW,_swprintf,SetDlgItemTextW,_swprintf,SetDlgItemTextW, |
0_2_005DD420 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005CBA94 FindFirstFileW,FindFirstFileW,GetLastError,FindNextFileW,GetLastError, |
0_2_005CBA94 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005C7AAF: __EH_prolog,_wcslen,_wcslen,CreateFileW,CloseHandle,CreateDirectoryW,CreateFileW,DeviceIoControl,CloseHandle,GetLastError,RemoveDirectoryW,DeleteFileW, |
0_2_005C7AAF |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005D5011 |
0_2_005D5011 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005D8253 |
0_2_005D8253 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005C92C6 |
0_2_005C92C6 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005D02F7 |
0_2_005D02F7 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005D5282 |
0_2_005D5282 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005E62A8 |
0_2_005E62A8 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005D13FD |
0_2_005D13FD |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005D742E |
0_2_005D742E |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005E64D7 |
0_2_005E64D7 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005D55B0 |
0_2_005D55B0 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005EE600 |
0_2_005EE600 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005D07A7 |
0_2_005D07A7 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005CD833 |
0_2_005CD833 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005D88AF |
0_2_005D88AF |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005C395A |
0_2_005C395A |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005C4A8E |
0_2_005C4A8E |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005EEAAE |
0_2_005EEAAE |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005F2BB4 |
0_2_005F2BB4 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005CFCCC |
0_2_005CFCCC |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005D7DDC |
0_2_005D7DDC |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005C2EB6 |
0_2_005C2EB6 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: String function: 005DFEFC appears 42 times |
|
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: String function: 005E07A0 appears 31 times |
|
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: String function: 005DFFD0 appears 56 times |
|
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005DB6D2 FindResourceW,SizeofResource,LoadResource,LockResource,GlobalAlloc,GlobalLock,CreateStreamOnHGlobal,GdipCreateHBITMAPFromBitmap,GlobalUnlock,GlobalFree, |
0_2_005DB6D2 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: <pi-ms-win-core-synch-l1-2-0.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: <pi-ms-win-core-fibers-l1-1-1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: <pi-ms-win-core-synch-l1-2-0.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: <pi-ms-win-core-fibers-l1-1-1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: <pi-ms-win-core-localization-l1-2-1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: dxgidebug.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: ieframe.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: netapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: wkscli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: dataexchange.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: d3d11.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: dcomp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: dxgi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: twinapi.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: msiso.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: mshtml.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: powrprof.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: umpdc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: srpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: msimtf.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: d2d1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: dwrite.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: resourcepolicyclient.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: d3d10warp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: dxcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: mlang.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: uiautomationcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: explorerframe.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: thumbcache.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: policymanager.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: msvcp110_win.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: samcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: samlib.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Section loaded: networkexplorer.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Automated click: OK |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Automated click: OK |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Automated click: OK |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Automated click: OK |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Automated click: OK |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Automated click: OK |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Automated click: OK |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Automated click: OK |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Automated click: OK |
Source: ET7GnkzV1D.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT |
Source: ET7GnkzV1D.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE |
Source: ET7GnkzV1D.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC |
Source: ET7GnkzV1D.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: ET7GnkzV1D.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG |
Source: ET7GnkzV1D.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT |
Source: ET7GnkzV1D.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: ET7GnkzV1D.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: ET7GnkzV1D.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: ET7GnkzV1D.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: ET7GnkzV1D.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005DD420 SendDlgItemMessageW,GetDlgItem,SetDlgItemTextW,SendDlgItemMessageW,FindFirstFileW,_swprintf,SetDlgItemTextW,FindClose,_swprintf,SetDlgItemTextW,SendDlgItemMessageW,_swprintf,SetDlgItemTextW,_swprintf,SetDlgItemTextW, |
0_2_005DD420 |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005CBA94 FindFirstFileW,FindFirstFileW,GetLastError,FindNextFileW,GetLastError, |
0_2_005CBA94 |
Source: ET7GnkzV1D.exe, 00000000.00000003.2452291158.000000000BC5C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:dJ |
Source: ET7GnkzV1D.exe, 00000000.00000003.2729022593.000000000BC4E000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Source: ET7GnkzV1D.exe, 00000000.00000002.2934766672.0000000002D09000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Source: ET7GnkzV1D.exe, 00000000.00000003.2592396114.000000000E91F000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:3 |
Source: ET7GnkzV1D.exe, 00000000.00000003.1893705518.000000000BC55000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Source: ET7GnkzV1D.exe, 00000000.00000003.2728807838.000000000E91F000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D: |
Source: ET7GnkzV1D.exe, 00000000.00000002.2934766672.0000000002D09000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005E0A0A IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_005E0A0A |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005E0B9D SetUnhandledExceptionFilter, |
0_2_005E0B9D |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005E0D8A SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
0_2_005E0D8A |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005E4FEF IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_005E4FEF |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Queries volume information: C:\Windows\Fonts\times.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\ET7GnkzV1D.exe |
Code function: 0_2_005DF05C GetCommandLineW,OpenFileMappingW,MapViewOfFile,UnmapViewOfFile,CloseHandle,GetModuleFileNameW,SetEnvironmentVariableW,GetLocalTime,_swprintf,SetEnvironmentVariableW,GetModuleHandleW,LoadIconW,DialogBoxParamW,Sleep,CloseHandle, |
0_2_005DF05C |