Source: C:\Users\user\Desktop\9ISNeRdj1B.exe | Code function: 1_2_00404B47 FindFirstFileW, | 1_2_00404B47 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400B8140 FindFirstFileW,FindClose,FindFirstFileW,FindClose, | 2_2_00000001400B8140 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014008C940 GetFullPathNameW,GetFullPathNameW,GetFileAttributesW,GetFileAttributesW,FindFirstFileW,GetLastError,wcsncpy,GetTickCount,PeekMessageW,GetTickCount,FindNextFileW,FindClose,MoveFileW,DeleteFileW,MoveFileW,GetLastError,CopyFileW,GetLastError, | 2_2_000000014008C940 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140072F50 FindFirstFileW,GetTickCount,PeekMessageW,GetTickCount,FindNextFileW,FindClose,FindFirstFileW,GetTickCount,PeekMessageW,GetTickCount,FindNextFileW,FindClose, | 2_2_0000000140072F50 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400B8040 GetFileAttributesW,FindFirstFileW,FindClose, | 2_2_00000001400B8040 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140073290 FindFirstFileW,GetLastError,FindClose,FileTimeToLocalFileTime,FileTimeToSystemTime, | 2_2_0000000140073290 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140049610 FindFirstFileW,FindNextFileW,FindClose,GetTickCount,FindNextFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,FindClose,FindClose, | 2_2_0000000140049610 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400738E0 CreateFileW,GetFileSizeEx,CloseHandle,FindFirstFileW,GetLastError,FindClose, | 2_2_00000001400738E0 |
Source: 9ISNeRdj1B.exe | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: 9ISNeRdj1B.exe | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: 9ISNeRdj1B.exe | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: FME.exe, 00000002.00000002.348655301.00000000066F0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: 9ISNeRdj1B.exe | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: 9ISNeRdj1B.exe | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: 9ISNeRdj1B.exe | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: 9ISNeRdj1B.exe | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: 9ISNeRdj1B.exe | String found in binary or memory: http://ocsp.digicert.com0 |
Source: 9ISNeRdj1B.exe | String found in binary or memory: http://ocsp.digicert.com0A |
Source: 9ISNeRdj1B.exe | String found in binary or memory: http://ocsp.digicert.com0X |
Source: 9ISNeRdj1B.exe | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: FME.exe, FME.exe, 00000002.00000000.328286935.00000001400EC000.00000002.00000001.01000000.00000004.sdmp, FME.exe, 00000002.00000002.350674986.00000001400EC000.00000002.00000001.01000000.00000004.sdmp, 7zS01A5A97E.exe, 00000004.00000002.421861033.0000000000C70000.00000002.00000001.00040000.00000009.sdmp, FME.exe, 0000000A.00000000.420472454.00000001400EC000.00000002.00000001.01000000.00000009.sdmp, FME.exe, 0000000A.00000002.433179389.00000001400EC000.00000002.00000001.01000000.00000009.sdmp, FME.exe.2.dr, FME.exe.1.dr | String found in binary or memory: https://autohotkey.com |
Source: 9ISNeRdj1B.exe, 00000001.00000003.325905862.0000000002A80000.00000004.00001000.00020000.00000000.sdmp, 9ISNeRdj1B.exe, 00000001.00000003.326101679.0000000002B00000.00000004.00001000.00020000.00000000.sdmp, FME.exe, 00000002.00000000.328286935.00000001400EC000.00000002.00000001.01000000.00000004.sdmp, FME.exe, 00000002.00000002.350674986.00000001400EC000.00000002.00000001.01000000.00000004.sdmp, 7zS01A5A97E.exe, 00000004.00000002.421861033.0000000000C70000.00000002.00000001.00040000.00000009.sdmp, FME.exe, 0000000A.00000000.420472454.00000001400EC000.00000002.00000001.01000000.00000009.sdmp, FME.exe, 0000000A.00000002.433179389.00000001400EC000.00000002.00000001.01000000.00000009.sdmp, FME.exe.2.dr, FME.exe.1.dr | String found in binary or memory: https://autohotkey.comCould |
Source: FME.html.4.dr | String found in binary or memory: https://cdn.jsdelivr.net/npm/bootstrap-icons |
Source: FME.html.4.dr | String found in binary or memory: https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.3/css/all.min.css |
Source: FME.ahk.1.dr | String found in binary or memory: https://fmev2.com/download |
Source: FME.exe, 00000002.00000002.348390140.0000000002980000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://fmev2.com/download= |
Source: bootstrap.min.css.4.dr, bootstrap.min.js.4.dr, bootstrap.bundle.min.js.4.dr | String found in binary or memory: https://getbootstrap.com/) |
Source: bootstrap4-toggle.min.js.4.dr, bootstrap4-toggle.min.css.4.dr | String found in binary or memory: https://gitbrent.github.io/bootstrap4-toggle/ |
Source: bootstrap.min.css.4.dr, bootstrap.min.js.4.dr, bootstrap.bundle.min.js.4.dr | String found in binary or memory: https://github.com/twbs/bootstrap/blob/master/LICENSE) |
Source: bootstrap.min.js.4.dr, bootstrap.bundle.min.js.4.dr | String found in binary or memory: https://github.com/twbs/bootstrap/graphs/contributors) |
Source: FME.html.4.dr | String found in binary or memory: https://i.imgur.com/1Dw6Crz.png |
Source: FME.html.4.dr | String found in binary or memory: https://i.imgur.com/9MPQS50.png |
Source: FME.html.4.dr | String found in binary or memory: https://i.imgur.com/C44UliA.png |
Source: FME.html.4.dr | String found in binary or memory: https://i.imgur.com/FHTgYYh.png |
Source: Lang.json.4.dr | String found in binary or memory: https://i.imgur.com/QVwU6ll.png |
Source: Lang.json.4.dr | String found in binary or memory: https://i.imgur.com/S4RVLev.png |
Source: Lang.json.4.dr | String found in binary or memory: https://i.imgur.com/jj0hOkl.png |
Source: Lang.json.4.dr | String found in binary or memory: https://i.imgur.com/lmySQj7.png |
Source: FME.html.4.dr | String found in binary or memory: https://i.imgur.com/p1gosK8.png |
Source: Lang.json.4.dr | String found in binary or memory: https://i.imgur.com/xbbVZDi.png |
Source: FME.exe, 00000002.00000002.348152335.000000000097B000.00000004.00000020.00020000.00000000.sdmp, FME.exe, 00000002.00000003.345105923.000000000097B000.00000004.00000020.00020000.00000000.sdmp, FME.exe, 00000002.00000003.345796925.000000000097B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com |
Source: FME.exe, 00000002.00000002.348152335.000000000097B000.00000004.00000020.00020000.00000000.sdmp, FME.exe, 00000002.00000003.345105923.000000000097B000.00000004.00000020.00020000.00000000.sdmp, FME.exe, 00000002.00000003.345796925.000000000097B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://raw.githubusercontent.com/ |
Source: 9ISNeRdj1B.exe, 00000001.00000003.324872626.00000000022E0000.00000004.00001000.00020000.00000000.sdmp, FME.exe, 00000002.00000003.346174894.000000000090E000.00000004.00000020.00020000.00000000.sdmp, FME.exe, 00000002.00000002.348080794.000000000090E000.00000004.00000020.00020000.00000000.sdmp, FME.exe, 00000002.00000002.348390140.0000000002980000.00000004.00000020.00020000.00000000.sdmp, FME.exe, 00000002.00000003.344644622.0000000004B75000.00000004.00000020.00020000.00000000.sdmp, FME.ahk.1.dr | String found in binary or memory: https://raw.githubusercontent.com/HexVexRtx/FME/main/file |
Source: FME.exe, 00000002.00000002.348390140.0000000002980000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://raw.githubusercontent.com/HexVexRtx/FME/main/filefile |
Source: C:\Users\user\Desktop\9ISNeRdj1B.exe | Code function: 1_2_0040BD85 | 1_2_0040BD85 |
Source: C:\Users\user\Desktop\9ISNeRdj1B.exe | Code function: 1_2_00403101 | 1_2_00403101 |
Source: C:\Users\user\Desktop\9ISNeRdj1B.exe | Code function: 1_2_00410138 | 1_2_00410138 |
Source: C:\Users\user\Desktop\9ISNeRdj1B.exe | Code function: 1_2_004192A1 | 1_2_004192A1 |
Source: C:\Users\user\Desktop\9ISNeRdj1B.exe | Code function: 1_2_0041937B | 1_2_0041937B |
Source: C:\Users\user\Desktop\9ISNeRdj1B.exe | Code function: 1_2_00416C70 | 1_2_00416C70 |
Source: C:\Users\user\Desktop\9ISNeRdj1B.exe | Code function: 1_2_00416536 | 1_2_00416536 |
Source: C:\Users\user\Desktop\9ISNeRdj1B.exe | Code function: 1_2_00417EC0 | 1_2_00417EC0 |
Source: C:\Users\user\Desktop\9ISNeRdj1B.exe | Code function: 1_2_00413ED0 | 1_2_00413ED0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140062010 | 2_2_0000000140062010 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140094340 | 2_2_0000000140094340 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400914B0 | 2_2_00000001400914B0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140028840 | 2_2_0000000140028840 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140029859 | 2_2_0000000140029859 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140005910 | 2_2_0000000140005910 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014002A93C | 2_2_000000014002A93C |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014004EAC0 | 2_2_000000014004EAC0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140001B6C | 2_2_0000000140001B6C |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140029D7D | 2_2_0000000140029D7D |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A1EA0 | 2_2_00000001400A1EA0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140027EE0 | 2_2_0000000140027EE0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140028F80 | 2_2_0000000140028F80 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140137000 | 2_2_0000000140137000 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014001EFF0 | 2_2_000000014001EFF0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014004600C | 2_2_000000014004600C |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400DF014 | 2_2_00000001400DF014 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014003D030 | 2_2_000000014003D030 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014008703E | 2_2_000000014008703E |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140093071 | 2_2_0000000140093071 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014005C08C | 2_2_000000014005C08C |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400EA0EC | 2_2_00000001400EA0EC |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014009E0F0 | 2_2_000000014009E0F0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A410D | 2_2_00000001400A410D |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140081120 | 2_2_0000000140081120 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014008C130 | 2_2_000000014008C130 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014004C140 | 2_2_000000014004C140 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140095150 | 2_2_0000000140095150 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014009A150 | 2_2_000000014009A150 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140071160 | 2_2_0000000140071160 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400DE18C | 2_2_00000001400DE18C |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014006E1B0 | 2_2_000000014006E1B0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400681B7 | 2_2_00000001400681B7 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400AA1E0 | 2_2_00000001400AA1E0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400791F0 | 2_2_00000001400791F0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014007A220 | 2_2_000000014007A220 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014006F230 | 2_2_000000014006F230 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014005A24B | 2_2_000000014005A24B |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400212B0 | 2_2_00000001400212B0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014000F2E0 | 2_2_000000014000F2E0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400DC2E4 | 2_2_00000001400DC2E4 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140037300 | 2_2_0000000140037300 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A130B | 2_2_00000001400A130B |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A1319 | 2_2_00000001400A1319 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014005231B | 2_2_000000014005231B |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A1324 | 2_2_00000001400A1324 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140067350 | 2_2_0000000140067350 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014006D350 | 2_2_000000014006D350 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014000335A | 2_2_000000014000335A |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140056380 | 2_2_0000000140056380 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140058380 | 2_2_0000000140058380 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400BC390 | 2_2_00000001400BC390 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014005B390 | 2_2_000000014005B390 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400983C0 | 2_2_00000001400983C0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A13E0 | 2_2_00000001400A13E0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A13F9 | 2_2_00000001400A13F9 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A1401 | 2_2_00000001400A1401 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A1417 | 2_2_00000001400A1417 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A8430 | 2_2_00000001400A8430 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140069430 | 2_2_0000000140069430 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140086460 | 2_2_0000000140086460 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140057480 | 2_2_0000000140057480 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140023490 | 2_2_0000000140023490 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400634A0 | 2_2_00000001400634A0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400B34B0 | 2_2_00000001400B34B0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400664E0 | 2_2_00000001400664E0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400BA4F0 | 2_2_00000001400BA4F0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014006B500 | 2_2_000000014006B500 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140065530 | 2_2_0000000140065530 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014005D550 | 2_2_000000014005D550 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014007D560 | 2_2_000000014007D560 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A3590 | 2_2_00000001400A3590 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A75E0 | 2_2_00000001400A75E0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400AC630 | 2_2_00000001400AC630 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014005263B | 2_2_000000014005263B |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A367B | 2_2_00000001400A367B |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140032690 | 2_2_0000000140032690 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014006F6A0 | 2_2_000000014006F6A0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014009A6AD | 2_2_000000014009A6AD |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014004C6B0 | 2_2_000000014004C6B0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014009A6BC | 2_2_000000014009A6BC |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014001F6C0 | 2_2_000000014001F6C0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014002F6C4 | 2_2_000000014002F6C4 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400EA6D0 | 2_2_00000001400EA6D0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400466E0 | 2_2_00000001400466E0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014009A6D8 | 2_2_000000014009A6D8 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014009A6FA | 2_2_000000014009A6FA |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140012700 | 2_2_0000000140012700 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014009A71B | 2_2_000000014009A71B |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014008A730 | 2_2_000000014008A730 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014009A727 | 2_2_000000014009A727 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014009A74D | 2_2_000000014009A74D |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140042768 | 2_2_0000000140042768 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014009A78E | 2_2_000000014009A78E |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400C27A0 | 2_2_00000001400C27A0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400897A0 | 2_2_00000001400897A0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A47A8 | 2_2_00000001400A47A8 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400867D0 | 2_2_00000001400867D0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014006B7D0 | 2_2_000000014006B7D0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014005C7F5 | 2_2_000000014005C7F5 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140058820 | 2_2_0000000140058820 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014000281C | 2_2_000000014000281C |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140038840 | 2_2_0000000140038840 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014009C838 | 2_2_000000014009C838 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014005F870 | 2_2_000000014005F870 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014004F880 | 2_2_000000014004F880 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400B6890 | 2_2_00000001400B6890 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400598C0 | 2_2_00000001400598C0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400D28E0 | 2_2_00000001400D28E0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400688E0 | 2_2_00000001400688E0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400DA90C | 2_2_00000001400DA90C |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400B8920 | 2_2_00000001400B8920 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014007D923 | 2_2_000000014007D923 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400D9944 | 2_2_00000001400D9944 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140064960 | 2_2_0000000140064960 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140071990 | 2_2_0000000140071990 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A39BC | 2_2_00000001400A39BC |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400909C0 | 2_2_00000001400909C0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014004D9C0 | 2_2_000000014004D9C0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400759F0 | 2_2_00000001400759F0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014007EA10 | 2_2_000000014007EA10 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014006AA20 | 2_2_000000014006AA20 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014003EA4C | 2_2_000000014003EA4C |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014004CA50 | 2_2_000000014004CA50 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A2A60 | 2_2_00000001400A2A60 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014007FA60 | 2_2_000000014007FA60 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014005CA64 | 2_2_000000014005CA64 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014005EA70 | 2_2_000000014005EA70 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A4A85 | 2_2_00000001400A4A85 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400E3AB8 | 2_2_00000001400E3AB8 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014007CAF0 | 2_2_000000014007CAF0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014008BB00 | 2_2_000000014008BB00 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140013B00 | 2_2_0000000140013B00 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140012B20 | 2_2_0000000140012B20 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014003FB36 | 2_2_000000014003FB36 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140054B50 | 2_2_0000000140054B50 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014004AB60 | 2_2_000000014004AB60 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140089B70 | 2_2_0000000140089B70 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140057C10 | 2_2_0000000140057C10 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140080C60 | 2_2_0000000140080C60 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014007BC60 | 2_2_000000014007BC60 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A1EA0 SetWindowTextW,IsZoomed,IsIconic,ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,IsWindowVisible,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,GetWindowLongW,GetWindowRect,GetClientRect,SystemParametersInfoW,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,GetForegroundWindow,DefDlgProcW,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow,SetFocus, | 2_2_00000001400A1EA0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A1EA0 SetWindowTextW,IsZoomed,IsIconic,ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,IsWindowVisible,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,GetWindowLongW,GetWindowRect,GetClientRect,SystemParametersInfoW,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,GetForegroundWindow,DefDlgProcW,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow,SetFocus, | 2_2_00000001400A1EA0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014009BFEF MulDiv,GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,IsWindowVisible,IsIconic,GetPropW,MapWindowPoints,GetWindowLongW,SendMessageW, | 2_2_000000014009BFEF |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A1FF6 ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,IsWindowVisible,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,GetForegroundWindow,DefDlgProcW,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow, | 2_2_00000001400A1FF6 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A2028 ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,IsWindowVisible,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,GetForegroundWindow,DefDlgProcW,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow, | 2_2_00000001400A2028 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014009C027 GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,IsWindowVisible,IsIconic,GetPropW,MapWindowPoints,GetWindowLongW,SendMessageW, | 2_2_000000014009C027 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014009C036 GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,IsWindowVisible,IsIconic,GetPropW,MapWindowPoints,GetWindowLongW,SendMessageW, | 2_2_000000014009C036 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A207A ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,IsWindowVisible,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,GetForegroundWindow,DefDlgProcW,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow, | 2_2_00000001400A207A |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A20CC ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,IsWindowVisible,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,GetForegroundWindow,DefDlgProcW,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow, | 2_2_00000001400A20CC |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014009E0F0 GetWindowLongW,GetWindowLongW,SetWindowPos,EnableWindow,GetWindowRect,GetClientRect,MulDiv,MulDiv,GetWindowRect,GetClientRect,MulDiv,MulDiv,_wcstoi64,IsWindow,SetParent,SetWindowLongPtrW,SetParent,IsWindowVisible,IsIconic,SetWindowLongW,SetWindowLongW,SetWindowPos,InvalidateRect, | 2_2_000000014009E0F0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A20F7 MulDiv,MulDiv,ShowWindow,IsIconic,GetParent,GetWindowLongW,GetWindowRect,MapWindowPoints,GetWindowLongW,IsWindowVisible,GetWindowLongW,GetMenu,GetWindowLongW,AdjustWindowRectEx,GetSystemMetrics,GetSystemMetrics,SendMessageW,GetClientRect,GetWindowRect,IsZoomed,ShowWindow,MoveWindow,GetWindowRect,GetClientRect,GetForegroundWindow,DefDlgProcW,ShowWindow,GetAncestor,GetForegroundWindow,GetFocus,GetDlgCtrlID,GetParent,GetDlgCtrlID,UpdateWindow, | 2_2_00000001400A20F7 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014009A150 realloc,SendMessageW,MulDiv,MulDiv,realloc,realloc,realloc,realloc,realloc,realloc,realloc,realloc,realloc,realloc,realloc,realloc,COMRefPtr,MulDiv,GetDC,SelectObject,GetTextMetricsW,MulDiv,GetDC,SelectObject,GetTextMetricsW,GetSystemMetrics,GetDC,SelectObject,GetTextMetricsW,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,DrawTextW,DrawTextW,GetCharABCWidthsW,MulDiv,GetSystemMetrics,GetSystemMetrics,MulDiv,GetDC,SelectObject,GetTextMetricsW,MulDiv,GetSystemMetrics,IsWindowVisible,IsIconic,GetPropW,MapWindowPoints,GetWindowLongW,SendMessageW,SelectObject,ReleaseDC,SendMessageW,SendMessageW,GetClientRect,SetWindowLongW,SendMessageW,SetWindowLongW,MoveWindow,GetWindowRect,SendMessageW,GetWindowRect,MapWindowPoints,InvalidateRect,SetWindowPos,SetWindowPos,MapWindowPoints, | 2_2_000000014009A150 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400631A0 SendMessageW,IsWindowVisible,ShowWindow,IsIconic,ShowWindow,GetForegroundWindow,SetForegroundWindow,SendMessageW, | 2_2_00000001400631A0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400BC1B0 GetForegroundWindow,IsWindowVisible,IsIconic,ShowWindow, | 2_2_00000001400BC1B0 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400BC390 GetWindowThreadProcessId,GetForegroundWindow,IsIconic,ShowWindow,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,BringWindowToTop, | 2_2_00000001400BC390 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400A8430 SendMessageW,GetWindowLongW,IsWindowVisible,IsIconic,GetFocus,GetWindowRect,GetPropW,ShowWindow,GetUpdateRect,SendMessageW,GetWindowLongW,ShowWindow,EnableWindow,GetWindowRect,PtInRect,PtInRect,SetFocus,SendMessageW,ShowWindow,SetFocus,InvalidateRect,MapWindowPoints,InvalidateRect, | 2_2_00000001400A8430 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014005C736 IsZoomed,IsIconic, | 2_2_000000014005C736 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140075790 GetTickCount,GetForegroundWindow,GetTickCount,GetWindowThreadProcessId,GetGUIThreadInfo,ClientToScreen,GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,_itow, | 2_2_0000000140075790 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400B8800 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen, | 2_2_00000001400B8800 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014005F870 GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,GetDC,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,CreateCompatibleDC,ReleaseDC,SelectObject,DeleteDC,DeleteObject,GetPixel,ReleaseDC, | 2_2_000000014005F870 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400AC8D0 CheckMenuItem,CheckMenuItem,GetCursorPos,GetForegroundWindow,IsIconic,GetWindowRect,ClientToScreen,GetForegroundWindow,GetWindowThreadProcessId,SetForegroundWindow,SetForegroundWindow,TrackPopupMenuEx,PostMessageW,GetForegroundWindow,SetForegroundWindow, | 2_2_00000001400AC8D0 |
Source: C:\Users\user\Desktop\9ISNeRdj1B.exe | Code function: 1_2_00404B47 FindFirstFileW, | 1_2_00404B47 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400B8140 FindFirstFileW,FindClose,FindFirstFileW,FindClose, | 2_2_00000001400B8140 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_000000014008C940 GetFullPathNameW,GetFullPathNameW,GetFileAttributesW,GetFileAttributesW,FindFirstFileW,GetLastError,wcsncpy,GetTickCount,PeekMessageW,GetTickCount,FindNextFileW,FindClose,MoveFileW,DeleteFileW,MoveFileW,GetLastError,CopyFileW,GetLastError, | 2_2_000000014008C940 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140072F50 FindFirstFileW,GetTickCount,PeekMessageW,GetTickCount,FindNextFileW,FindClose,FindFirstFileW,GetTickCount,PeekMessageW,GetTickCount,FindNextFileW,FindClose, | 2_2_0000000140072F50 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400B8040 GetFileAttributesW,FindFirstFileW,FindClose, | 2_2_00000001400B8040 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140073290 FindFirstFileW,GetLastError,FindClose,FileTimeToLocalFileTime,FileTimeToSystemTime, | 2_2_0000000140073290 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_0000000140049610 FindFirstFileW,FindNextFileW,FindClose,GetTickCount,FindNextFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,FindClose,FindClose, | 2_2_0000000140049610 |
Source: C:\Users\user\AppData\Local\Temp\7zS01A5A97E\FME.exe | Code function: 2_2_00000001400738E0 CreateFileW,GetFileSizeEx,CloseHandle,FindFirstFileW,GetLastError,FindClose, | 2_2_00000001400738E0 |