Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_0040C820 memset,lstrlenA,CryptStringToBinaryA,memcpy,lstrcatA,lstrcatA,lstrcatA, |
16_2_0040C820 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_00407240 GetProcessHeap,HeapAlloc,CryptUnprotectData,WideCharToMultiByte,LocalFree, |
16_2_00407240 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_00409AC0 CryptStringToBinaryA,LocalAlloc,CryptStringToBinaryA,LocalFree, |
16_2_00409AC0 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_00418EA0 CryptBinaryToStringA,GetProcessHeap,HeapAlloc,CryptBinaryToStringA, |
16_2_00418EA0 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_00409B60 CryptUnprotectData,LocalAlloc,memcpy,LocalFree, |
16_2_00409B60 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_022ACA87 memset,lstrlen,CryptStringToBinaryA,memcpy,lstrcat,lstrcat,lstrcat, |
16_2_022ACA87 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_022A74A7 GetProcessHeap,RtlAllocateHeap,CryptUnprotectData,WideCharToMultiByte,LocalFree, |
16_2_022A74A7 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_022A9D27 CryptStringToBinaryA,LocalAlloc,CryptStringToBinaryA,LocalFree, |
16_2_022A9D27 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_022B9107 CryptBinaryToStringA,GetProcessHeap,RtlAllocateHeap,CryptBinaryToStringA, |
16_2_022B9107 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_022A9DC7 CryptUnprotectData,LocalAlloc,memcpy,LocalFree, |
16_2_022A9DC7 |
Source: C:\Users\user\Desktop\M13W1o3scc.exe |
Code function: 0_2_004062D5 FindFirstFileW,FindClose, |
0_2_004062D5 |
Source: C:\Users\user\Desktop\M13W1o3scc.exe |
Code function: 0_2_00402E18 FindFirstFileW, |
0_2_00402E18 |
Source: C:\Users\user\Desktop\M13W1o3scc.exe |
Code function: 0_2_00406C9B DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, |
0_2_00406C9B |
Source: C:\Users\user\AppData\Local\Temp\773416\Welding.pif |
Code function: 15_2_00114005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
15_2_00114005 |
Source: C:\Users\user\AppData\Local\Temp\773416\Welding.pif |
Code function: 15_2_000BE26E Process32NextW,SetFileTime,GetFileAttributesW,FindFirstFileW,__floor_pentium4,GetShortPathNameW,DeleteFileW,__floor_pentium4, |
15_2_000BE26E |
Source: C:\Users\user\AppData\Local\Temp\773416\Welding.pif |
Code function: 15_2_0011C2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
15_2_0011C2FF |
Source: C:\Users\user\AppData\Local\Temp\773416\Welding.pif |
Code function: 15_2_0011494A GetFileAttributesW,FindFirstFileW,FindClose, |
15_2_0011494A |
Source: C:\Users\user\AppData\Local\Temp\773416\Welding.pif |
Code function: 15_2_0011CD14 FindFirstFileW,FindClose, |
15_2_0011CD14 |
Source: C:\Users\user\AppData\Local\Temp\773416\Welding.pif |
Code function: 15_2_0011CD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
15_2_0011CD9F |
Source: C:\Users\user\AppData\Local\Temp\773416\Welding.pif |
Code function: 15_2_0011F5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
15_2_0011F5D8 |
Source: C:\Users\user\AppData\Local\Temp\773416\Welding.pif |
Code function: 15_2_0011F735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
15_2_0011F735 |
Source: C:\Users\user\AppData\Local\Temp\773416\Welding.pif |
Code function: 15_2_0011FA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
15_2_0011FA36 |
Source: C:\Users\user\AppData\Local\Temp\773416\Welding.pif |
Code function: 15_2_00113CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
15_2_00113CE2 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_0040E430 FindFirstFileA,StrCmpCA,StrCmpCA,FindNextFileA, |
16_2_0040E430 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_004138B0 wsprintfA,FindFirstFileA,lstrcatA,StrCmpCA,StrCmpCA,wsprintfA,PathMatchSpecA,CoInitialize,CoUninitialize,lstrcatA,lstrlenA,StrCmpCA,wsprintfA,wsprintfA,PathMatchSpecA,wsprintfA,CopyFileA,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,DeleteFileA,FindNextFileA,FindClose, |
16_2_004138B0 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_00414570 GetProcessHeap,HeapAlloc,wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,lstrcatA,lstrcatA,lstrlenA,lstrlenA, |
16_2_00414570 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_00414910 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,StrCmpCA,wsprintfA,wsprintfA,PathMatchSpecA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
16_2_00414910 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_0040ED20 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,lstrlenA,DeleteFileA,CopyFileA,FindNextFileA,FindClose, |
16_2_0040ED20 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_0040BE70 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,StrCmpCA,DeleteFileA,StrCmpCA,FindNextFileA,FindClose, |
16_2_0040BE70 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_0040DE10 FindFirstFileA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
16_2_0040DE10 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_004016D0 FindFirstFileA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
16_2_004016D0 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_0040DA80 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,FindNextFileA,FindClose, |
16_2_0040DA80 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_00413EA0 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,FindNextFileA,FindClose, |
16_2_00413EA0 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_0040F6B0 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
16_2_0040F6B0 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_022AE697 FindFirstFileA,StrCmpCA,StrCmpCA,FindNextFileA, |
16_2_022AE697 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_022B3B17 wsprintfA,FindFirstFileA,lstrcat,StrCmpCA,StrCmpCA,wsprintfA,PathMatchSpecA,CoInitialize,CoUninitialize,lstrcat,lstrlen,StrCmpCA,wsprintfA,wsprintfA,PathMatchSpecA,wsprintfA,CopyFileA,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,DeleteFileA,FindNextFileA,FindClose, |
16_2_022B3B17 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_022B4B77 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,StrCmpCA,wsprintfA,wsprintfA,PathMatchSpecA,lstrcat,lstrcat,lstrcat,lstrcat,lstrcat,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
16_2_022B4B77 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_022AEF87 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,lstrlen,DeleteFileA,CopyFileA,FindNextFileA,FindClose, |
16_2_022AEF87 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_022B47D7 GetProcessHeap,RtlAllocateHeap,wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,lstrcat,lstrcat,lstrlen,lstrlen, |
16_2_022B47D7 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_022AE077 FindFirstFileA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
16_2_022AE077 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_022ADCE7 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,FindNextFileA,FindClose, |
16_2_022ADCE7 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_022AC0D7 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,StrCmpCA,DeleteFileA,StrCmpCA,FindNextFileA,FindClose, |
16_2_022AC0D7 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_022A1937 FindFirstFileA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
16_2_022A1937 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_022B4107 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,lstrcat,lstrcat,lstrcat,lstrcat,lstrcat,lstrcat,FindNextFileA,FindClose, |
16_2_022B4107 |
Source: C:\Users\user\AppData\Local\Temp\478F.tmp.exe |
Code function: 16_2_022AF917 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
16_2_022AF917 |