Source: C:\Users\user\Desktop\Uninstall.exe |
Code function: 0_2_00405E61 FindFirstFileA,FindClose, |
0_2_00405E61 |
Source: C:\Users\user\Desktop\Uninstall.exe |
Code function: 0_2_0040263E FindFirstFileA, |
0_2_0040263E |
Source: C:\Users\user\Desktop\Uninstall.exe |
Code function: 0_2_0040548B CloseHandle,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, |
0_2_0040548B |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_00405E61 FindFirstFileA,FindClose, |
1_2_00405E61 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_0040548B CloseHandle,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, |
1_2_0040548B |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_0040263E FindFirstFileA, |
1_2_0040263E |
Source: Uninstall.exe, Au_.exe.0.dr |
String found in binary or memory: http://crl.globalsign.com/gs/gscodesigng2.crl0 |
Source: Uninstall.exe, Au_.exe.0.dr |
String found in binary or memory: http://crl.globalsign.net/root.crl0 |
Source: Uninstall.exe, Au_.exe.0.dr |
String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0 |
Source: Au_.exe, Au_.exe, 00000001.00000002.2972607881.0000000000409000.00000004.00000001.01000000.00000004.sdmp, Au_.exe, 00000001.00000000.1721749700.0000000000409000.00000008.00000001.01000000.00000004.sdmp, Uninstall.exe, Au_.exe.0.dr |
String found in binary or memory: http://nsis.sf.net/NSIS_Error |
Source: Uninstall.exe, Au_.exe.0.dr |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: Uninstall.exe, Au_.exe.0.dr |
String found in binary or memory: http://ocsp.thawte.com0 |
Source: Uninstall.exe, Au_.exe.0.dr |
String found in binary or memory: http://ocsp2.globalsign.com/gscodesigng20 |
Source: Uninstall.exe, Au_.exe.0.dr |
String found in binary or memory: http://secure.globalsign.com/cacert/gscodesigng2.crt04 |
Source: Uninstall.exe, Au_.exe.0.dr |
String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0 |
Source: Uninstall.exe, Au_.exe.0.dr |
String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0( |
Source: Uninstall.exe, Au_.exe.0.dr |
String found in binary or memory: http://ts-ocsp.ws.symantec.com07 |
Source: Uninstall.exe, 00000000.00000002.1722365263.00000000005AE000.00000004.00000020.00020000.00000000.sdmp, Uninstall.exe, 00000000.00000002.1722642452.0000000002804000.00000004.00000020.00020000.00000000.sdmp, Au_.exe, 00000001.00000002.2973586073.000000000296D000.00000004.00000020.00020000.00000000.sdmp, Au_.exe, 00000001.00000002.2972921606.0000000000828000.00000004.00000020.00020000.00000000.sdmp, nsz1ED4.tmp.0.dr, nsu2089.tmp.1.dr |
String found in binary or memory: http://www.linkwizapp.com/uninstall-success |
Source: Uninstall.exe, 00000000.00000002.1722365263.00000000005AE000.00000004.00000020.00020000.00000000.sdmp, Uninstall.exe, 00000000.00000002.1722642452.0000000002804000.00000004.00000020.00020000.00000000.sdmp, Au_.exe, 00000001.00000002.2973586073.000000000296D000.00000004.00000020.00020000.00000000.sdmp, Au_.exe, 00000001.00000002.2972921606.0000000000828000.00000004.00000020.00020000.00000000.sdmp, nsz1ED4.tmp.0.dr, nsu2089.tmp.1.dr |
String found in binary or memory: http://www.linkwizapp.com/uninstall-successrundll32.exeopenShellExecuteAsSessionUserWithFallback |
Source: nsu2089.tmp.1.dr |
String found in binary or memory: https://weld.unitegenius.com/i?e=vitruvian-installer-uninstall-v0002 |
Source: Uninstall.exe, Au_.exe.0.dr |
String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: Uninstall.exe, Au_.exe.0.dr |
String found in binary or memory: https://www.globalsign.com/repository/03 |
Source: C:\Users\user\Desktop\Uninstall.exe |
Code function: 0_2_00405042 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,ShowWindow,ShowWindow,GetDlgItem,SendMessageA,SendMessageA,SendMessageA,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageA,CreatePopupMenu,AppendMenuA,GetWindowRect,TrackPopupMenu,SendMessageA,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageA,GlobalUnlock,SetClipboardData,CloseClipboard, |
0_2_00405042 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_10001529 GetWindowLongA,lstrlenA,lstrlenA,lstrlenA,GlobalAlloc,wsprintfA,CreateProcessA,GetLastError,MultiByteToWideChar,MultiByteToWideChar,lstrlenA,MultiByteToWideChar,GetDlgItem,GetDlgItem,SendMessageW,SendMessageW,GetDlgItem,SendMessageW,CreateProcessWithLogonW,GetLastError,GetLastError,FormatMessageA,MessageBoxA,LocalFree,GetLastError,GlobalFree,CloseHandle,EndDialog,SetWindowLongA,GetDlgItem,GetDlgItem,SendMessageA,SendMessageA,GetDlgItem,SendMessageA,LoadLibraryA,LoadImageA,GetDlgItem,SendMessageA,SendMessageA,GetDlgItem,SendMessageA,GetDlgItem,SendMessageA,DestroyWindow, |
1_2_10001529 |
Source: C:\Users\user\Desktop\Uninstall.exe |
Code function: 0_2_0040323C EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,DeleteFileA,ExitProcess,CoUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
0_2_0040323C |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_0040323C EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
1_2_0040323C |
Source: C:\Users\user\Desktop\Uninstall.exe |
Code function: 0_2_00404853 |
0_2_00404853 |
Source: C:\Users\user\Desktop\Uninstall.exe |
Code function: 0_2_00406131 |
0_2_00406131 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_00404853 |
1_2_00404853 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_00406131 |
1_2_00406131 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5C4ED2 |
1_2_6E5C4ED2 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5D4FD3 |
1_2_6E5D4FD3 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5D6FE7 |
1_2_6E5D6FE7 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5AAC87 |
1_2_6E5AAC87 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5D5CBF |
1_2_6E5D5CBF |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5C3D6C |
1_2_6E5C3D6C |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5D4A63 |
1_2_6E5D4A63 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5BFAF0 |
1_2_6E5BFAF0 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5CCA91 |
1_2_6E5CCA91 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5C3937 |
1_2_6E5C3937 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5D5543 |
1_2_6E5D5543 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5C351F |
1_2_6E5C351F |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5CB20C |
1_2_6E5CB20C |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5A83BA |
1_2_6E5A83BA |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5C302B |
1_2_6E5C302B |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5A3165 |
1_2_6E5A3165 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5C71AD |
1_2_6E5C71AD |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5C41A1 |
1_2_6E5C41A1 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: String function: 6E5C5E60 appears 48 times |
|
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: String function: 6E5C12ED appears 69 times |
|
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: String function: 6E5A165E appears 86 times |
|
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: String function: 6E5A22ED appears 33 times |
|
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: String function: 6E5C1320 appears 49 times |
|
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_10001529 GetWindowLongA,lstrlenA,lstrlenA,lstrlenA,GlobalAlloc,wsprintfA,CreateProcessA,GetLastError,MultiByteToWideChar,MultiByteToWideChar,lstrlenA,MultiByteToWideChar,GetDlgItem,GetDlgItem,SendMessageW,SendMessageW,GetDlgItem,SendMessageW,CreateProcessWithLogonW,GetLastError,GetLastError,FormatMessageA,MessageBoxA,LocalFree,GetLastError,GlobalFree,CloseHandle,EndDialog,SetWindowLongA,GetDlgItem,GetDlgItem,SendMessageA,SendMessageA,GetDlgItem,SendMessageA,LoadLibraryA,LoadImageA,GetDlgItem,SendMessageA,SendMessageA,GetDlgItem,SendMessageA,GetDlgItem,SendMessageA,DestroyWindow, |
1_2_10001529 |
Source: C:\Users\user\Desktop\Uninstall.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Uninstall.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Uninstall.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Uninstall.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Uninstall.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Uninstall.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Uninstall.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Uninstall.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Uninstall.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_6E5C4ED2 GetModuleHandleW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, |
1_2_6E5C4ED2 |
Source: C:\Users\user\Desktop\Uninstall.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Uninstall.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Uninstall.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Uninstall.exe |
Code function: 0_2_00405E61 FindFirstFileA,FindClose, |
0_2_00405E61 |
Source: C:\Users\user\Desktop\Uninstall.exe |
Code function: 0_2_0040263E FindFirstFileA, |
0_2_0040263E |
Source: C:\Users\user\Desktop\Uninstall.exe |
Code function: 0_2_0040548B CloseHandle,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, |
0_2_0040548B |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_00405E61 FindFirstFileA,FindClose, |
1_2_00405E61 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_0040548B CloseHandle,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, |
1_2_0040548B |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_0040263E FindFirstFileA, |
1_2_0040263E |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: 1_2_1000255E _,CreateEventA,CreateEventA,CreateEventA,CreateFileMappingA,MapViewOfFile,GetLastError,CreateThread,GetLastError,WaitForSingleObject,GetExitCodeThread,GetCurrentProcessId,GetCurrentProcessId,GetCurrentThreadId,wsprintfA,SendMessageA,GetCurrentProcessId,GetCurrentThreadId,SetWindowLongA,GetCurrentProcessId,GetCurrentThreadId,wsprintfA,GetCurrentProcessId,GetCurrentProcessId,GetCurrentThreadId,wsprintfA,GetLastError,GetCurrentProcessId,SetCurrentDirectoryA,PostMessageA,GetCommandLineA,IsWindowVisible,GetModuleHandleA,CreateDialogParamA,GetWindowLongA,GetWindowLongA,SetWindowLongA,SetWindowPos,LoadIconA,FindWindowExA,ShowWindow,ShowWindow,FindWindowExA,GetDlgItem,ShowWindow,GetClientRect,SetWindowPos,GetWindowLongA,SetWindowLongA,SendMessageA,SendMessageA,SendMessageA,ShowWindow,GlobalAlloc,GlobalFree,GlobalAlloc,GetModuleFileNameA,lstrlenA,GlobalAlloc,wsprintfA,SetForegroundWindow,ShellExecuteExA,GetLastError,UnhookWindowsHookEx,GetCurrentProcessId,GetCurrentThreadId,MsgWaitForMultipleObjects,GetExitCodeProcess,GetLastError,CloseHandle,CloseHandle,wsprintfA,wsprintfA,wsprintfA,wsprintfA,GlobalFree, |
1_2_1000255E |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: _GetPrimaryLen,EnumSystemLocalesW, |
1_2_6E5D1E0D |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,__wcsnicmp,GetLocaleInfoW, |
1_2_6E5D1E90 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo, |
1_2_6E5D0C69 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: GetLocaleInfoW, |
1_2_6E5D1CA2 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: EnumSystemLocalesW, |
1_2_6E5D1D50 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat, |
1_2_6E5CFDD8 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: _GetPrimaryLen,EnumSystemLocalesW, |
1_2_6E5D1D90 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: _TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_GetLocaleNameFromDefault,IsValidCodePage,_wcschr,_wcschr,__itow_s,__invoke_watson,GetLocaleInfoW, |
1_2_6E5D1AE0 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeW,_memmove,_memmove,_memmove,InterlockedDecrement,_free,_free,_free,_free,_free,_free,_free,_free,_free,InterlockedDecrement, |
1_2_6E5C2919 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,InterlockedDecrement,InterlockedDecrement,_free,_free, |
1_2_6E5D0665 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: GetLocaleInfoW, |
1_2_6E5C54E9 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: EnumSystemLocalesW, |
1_2_6E5C54AC |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,InterlockedDecrement,InterlockedDecrement,_free,_free, |
1_2_6E5D025C |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: GetLocaleInfoW,_GetPrimaryLen, |
1_2_6E5D2258 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: _memset,_TranslateName,_TranslateName,_GetLcidFromCountry,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,__itow_s, |
1_2_6E5D22C0 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,__invoke_watson, |
1_2_6E5C60D1 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: GetLocaleInfoW, |
1_2_6E5D2083 |
Source: C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe |
Code function: _wcscmp,_wcscmp,GetLocaleInfoW,GetLocaleInfoW,GetACP, |
1_2_6E5D21AB |