Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 2_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 2_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 4_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 4_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 6_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 6_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 8_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 8_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 10_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 10_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 12_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 12_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 14_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 14_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 16_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 16_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 18_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 18_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 20_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 20_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 22_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 22_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 24_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 24_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 26_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 26_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 28_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 28_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 30_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 30_2_00404E08 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 0 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 0 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 1 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 1 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 2 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 2 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 3 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 3 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 4 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 4 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 5 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 5 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 6 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 6 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 7 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 7 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 8 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 8 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 9 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 9 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 10 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 10 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 11 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 11 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 12 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 12 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 13 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 13 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 14 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 14 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 15 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 15 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 16 |
Source: unknown | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 16 |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\Microsoft\DirectX\nthost.exe 'C:\Users\user\AppData\Roaming\Microsoft\DirectX\nthost.exe' 17 DEL 'C:\Users\user\Desktop\obtG43AWHP.exe' |
Source: unknown | Process created: C:\Windows\explorer.exe explorer.exe C:\Users\user\AppData\Roaming\Microsoft\DirectX\nthost.exe |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\Microsoft\DirectX\nthost.exe 'C:\Users\user\AppData\Roaming\Microsoft\DirectX\nthost.exe' 17 DEL 'C:\Users\user\Desktop\obtG43AWHP.exe' |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 1 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 1 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 2 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 2 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 3 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 3 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 5 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 5 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 6 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 6 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 7 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 7 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 8 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 8 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 9 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 9 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 10 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 10 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 11 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 11 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 12 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 12 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 13 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 13 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 14 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 14 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 15 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 15 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 16 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\Desktop\obtG43AWHP.exe 'C:\Users\user\Desktop\obtG43AWHP.exe' 16 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Process created: C:\Users\user\AppData\Roaming\Microsoft\DirectX\nthost.exe 'C:\Users\user\AppData\Roaming\Microsoft\DirectX\nthost.exe' 17 DEL 'C:\Users\user\Desktop\obtG43AWHP.exe' |
Source: C:\Users\user\AppData\Roaming\Microsoft\DirectX\nthost.exe | Process created: C:\Users\user\AppData\Roaming\Microsoft\DirectX\nthost.exe 'C:\Users\user\AppData\Roaming\Microsoft\DirectX\nthost.exe' 17 DEL 'C:\Users\user\Desktop\obtG43AWHP.exe' |
Source: C:\Users\user\AppData\Roaming\Microsoft\DirectX\nthost.exe | Process created: unknown unknown |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 1_2_0027E080 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualAlloc,ReadProcessMemory,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread, | 1_2_0027E080 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 2_2_00417F5C CreateProcessA,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualFree,TerminateProcess, | 2_2_00417F5C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 3_2_0029E080 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualAlloc,ReadProcessMemory,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread, | 3_2_0029E080 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 4_2_00417F5C CreateProcessA,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualFree,TerminateProcess, | 4_2_00417F5C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 5_2_0020E080 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualAlloc,ReadProcessMemory,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread, | 5_2_0020E080 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 6_2_00417F5C CreateProcessA,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualFree,TerminateProcess, | 6_2_00417F5C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 7_2_0028E080 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualAlloc,ReadProcessMemory,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread, | 7_2_0028E080 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 8_2_00417F5C CreateProcessA,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualFree,TerminateProcess, | 8_2_00417F5C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 9_2_0028E080 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualAlloc,ReadProcessMemory,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread, | 9_2_0028E080 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 10_2_00417F5C CreateProcessA,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualFree,TerminateProcess, | 10_2_00417F5C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 11_2_001AE080 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualAlloc,ReadProcessMemory,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread, | 11_2_001AE080 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 12_2_00417F5C CreateProcessA,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualFree,TerminateProcess, | 12_2_00417F5C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 13_2_002DE080 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualAlloc,ReadProcessMemory,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread, | 13_2_002DE080 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 14_2_00417F5C CreateProcessA,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualFree,TerminateProcess, | 14_2_00417F5C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 15_2_0020E080 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualAlloc,ReadProcessMemory,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread, | 15_2_0020E080 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 16_2_00417F5C CreateProcessA,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualFree,TerminateProcess, | 16_2_00417F5C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 17_2_0037E080 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualAlloc,ReadProcessMemory,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread, | 17_2_0037E080 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 18_2_00417F5C CreateProcessA,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualFree,TerminateProcess, | 18_2_00417F5C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 19_2_0018E080 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualAlloc,ReadProcessMemory,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread, | 19_2_0018E080 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 20_2_00417F5C CreateProcessA,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualFree,TerminateProcess, | 20_2_00417F5C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 21_2_0024E080 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualAlloc,ReadProcessMemory,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread, | 21_2_0024E080 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 22_2_00417F5C CreateProcessA,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualFree,TerminateProcess, | 22_2_00417F5C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 23_2_0020E080 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualAlloc,ReadProcessMemory,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread, | 23_2_0020E080 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 24_2_00417F5C CreateProcessA,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualFree,TerminateProcess, | 24_2_00417F5C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 25_2_0027E080 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualAlloc,ReadProcessMemory,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread, | 25_2_0027E080 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 26_2_00417F5C CreateProcessA,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualFree,TerminateProcess, | 26_2_00417F5C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 27_2_0024E080 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualAlloc,ReadProcessMemory,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread, | 27_2_0024E080 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 28_2_00417F5C CreateProcessA,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualFree,TerminateProcess, | 28_2_00417F5C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 29_2_0027E080 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualAlloc,ReadProcessMemory,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,SetThreadContext,ResumeThread, | 29_2_0027E080 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 30_2_00417F5C CreateProcessA,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualFree,TerminateProcess, | 30_2_00417F5C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00405CF0 appears 90 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00411DBC appears 105 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00401268 appears 60 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 004118D4 appears 105 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 0040A628 appears 45 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00407F03 appears 45 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00217214 appears 33 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 0040CA14 appears 315 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 03005030 appears 38 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 0021589C appears 54 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 0040539C appears 75 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00404194 appears 60 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00401314 appears 75 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 004038E8 appears 105 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00403894 appears 60 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 0040F48C appears 45 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00281D0C appears 42 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00405A90 appears 150 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 0040346C appears 210 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 0040450C appears 105 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00211D0C appears 42 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00287214 appears 33 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00405C80 appears 255 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 0025589C appears 36 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00403EAC appears 405 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 0028589C appears 54 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 004111AC appears 45 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00403114 appears 105 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00408974 appears 165 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 0040DB18 appears 165 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00405C78 appears 45 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 0040345C appears 45 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00403E88 appears 1095 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00401260 appears 45 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 00406EFC appears 60 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: String function: 0029589C appears 36 times | |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 2_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 2_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 4_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 4_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 6_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 6_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 8_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 8_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 10_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 10_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 12_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 12_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 14_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 14_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 16_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 16_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 18_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 18_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 20_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 20_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 22_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 22_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 24_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 24_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 26_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 26_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 28_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 28_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: 30_2_00404E08 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 30_2_00404E08 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: _strlen,ShellExecuteA,ShellAboutW,ExtractIconA,GetColorSpace,GetLogColorSpaceA,ChoosePixelFormat,SetICMMode,GetPrivateProfileSectionNamesA,GetCalendarInfoW,GetLocaleInfoW,GetModuleHandleW,LocalAlloc,VirtualProtect,GetTickCount, | 1_2_0300966F |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 2_2_00404FC0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 2_2_004050CC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 2_2_0040587A |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA,GetACP, | 2_2_0040B2B4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 2_2_00409DB0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 2_2_0040587C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 2_2_00409DFC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: _strlen,ShellExecuteA,ShellAboutW,ExtractIconA,GetColorSpace,GetLogColorSpaceA,ChoosePixelFormat,SetICMMode,GetPrivateProfileSectionNamesA,GetCalendarInfoW,GetLocaleInfoW,GetModuleHandleW,LocalAlloc,VirtualProtect,GetTickCount, | 2_2_0300966F |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 4_2_00404FC0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 4_2_004050CC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 4_2_0040587A |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA,GetACP, | 4_2_0040B2B4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 4_2_00409DB0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 4_2_0040587C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 4_2_00409DFC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 6_2_00404FC0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 6_2_004050CC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 6_2_0040587A |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA,GetACP, | 6_2_0040B2B4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 6_2_00409DB0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 6_2_0040587C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 6_2_00409DFC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 8_2_00404FC0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 8_2_004050CC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 8_2_0040587A |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA,GetACP, | 8_2_0040B2B4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 8_2_00409DB0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 8_2_0040587C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 8_2_00409DFC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 10_2_00404FC0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 10_2_004050CC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 10_2_0040587A |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA,GetACP, | 10_2_0040B2B4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 10_2_00409DB0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 10_2_0040587C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 10_2_00409DFC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 12_2_00404FC0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 12_2_004050CC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 12_2_0040587A |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA,GetACP, | 12_2_0040B2B4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 12_2_00409DB0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 12_2_0040587C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 12_2_00409DFC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 14_2_00404FC0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 14_2_004050CC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 14_2_0040587A |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA,GetACP, | 14_2_0040B2B4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 14_2_00409DB0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 14_2_0040587C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 14_2_00409DFC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 16_2_00404FC0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 16_2_004050CC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 16_2_0040587A |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA,GetACP, | 16_2_0040B2B4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 16_2_00409DB0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 16_2_0040587C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 16_2_00409DFC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 18_2_00404FC0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 18_2_004050CC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 18_2_0040587A |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA,GetACP, | 18_2_0040B2B4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 18_2_00409DB0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 18_2_0040587C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 18_2_00409DFC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 20_2_00404FC0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 20_2_004050CC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 20_2_0040587A |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA,GetACP, | 20_2_0040B2B4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 20_2_00409DB0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 20_2_0040587C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 20_2_00409DFC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 22_2_00404FC0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 22_2_004050CC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 22_2_0040587A |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA,GetACP, | 22_2_0040B2B4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 22_2_00409DB0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 22_2_0040587C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 22_2_00409DFC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 24_2_00404FC0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 24_2_004050CC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 24_2_0040587A |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA,GetACP, | 24_2_0040B2B4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 24_2_00409DB0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 24_2_0040587C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 24_2_00409DFC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 26_2_00404FC0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 26_2_004050CC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 26_2_0040587A |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA,GetACP, | 26_2_0040B2B4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 26_2_00409DB0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 26_2_0040587C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 26_2_00409DFC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 28_2_00404FC0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 28_2_004050CC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 28_2_0040587A |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA,GetACP, | 28_2_0040B2B4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 28_2_00409DB0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 28_2_0040587C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 28_2_00409DFC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 30_2_00404FC0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 30_2_004050CC |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 30_2_0040587A |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA,GetACP, | 30_2_0040B2B4 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 30_2_00409DB0 |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 30_2_0040587C |
Source: C:\Users\user\Desktop\obtG43AWHP.exe | Code function: GetLocaleInfoA, | 30_2_00409DFC |