Summary | ZeroBOX

GOMAUDIOKORSETUP_NEW.EXE

NPKI Formbook Emotet Gen1 North Korea backdoor njRAT Eredel Stealer Extended Generic Malware UPX ASPack Antivirus Malicious Library Malicious Packer Admin Tool (Sysinternals etc ...) Anti_VM PWS Escalate priviledges Socket
Category Machine Started Completed
FILE s1_win7_x6402 Oct. 27, 2021, 2:21 p.m. Oct. 27, 2021, 2:23 p.m.
Size 12.4MB
Type PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5 9f869aecfc2c65dc3a0c170ebcd4d429
SHA256 4f3ab21915ecedde2ddde10abeab7969f31ef640fff698bad0973649b5dce1a1
CRC32 5F83C7A3
ssdeep 196608:plLjrWYmNp6Upyji3J7/kRXK6LY9LEfIG7jiYlxgA01BwQX17SY8S3F:plzTg6Hi3eRXprf/ji0xgAuvF7NF
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
shepherd.ff.avast.com 69.94.69.113
s-vps18tiny.avcdn.net
AAAA 2600:1410:4000:18f::240d
AAAA 2600:1410:4000:1a6::240d
23.40.45.32
cdn2.gomlab.com 14.0.114.116
l4691727.iavs9x.u.avast.com 23.43.165.50
c3978047.iavs9x.u.avast.com
AAAA 2600:1410:1000::172b:a532
AAAA 2600:1410:1000::172b:a54b
23.43.165.50
bits.avcdn.net 23.40.45.32
m0658849.iavs9x.u.avast.com 23.43.165.75
r0965026.vps18tiny.u.avcdn.net
AAAA 2600:1410:1000::172b:a50a
AAAA 2600:1410:1000::172b:a53b
23.43.165.59
h4444966.iavs9x.u.avast.com
AAAA 2600:1410:1000::172b:a54b
AAAA 2600:1410:1000::172b:a532
23.43.165.75
ana.gomtv.com 183.110.10.189
r3802239.iavs9x.u.avast.com
AAAA 2600:1410:1000::172b:a54b
AAAA 2600:1410:1000::172b:a532
23.43.165.50
s-iavs9x.avcdn.net
AAAA 2600:1410:4000:1a6::240d
AAAA 2600:1410:4000:18f::240d
23.40.45.32
g1928587.vps18tiny.u.avcdn.net 23.43.165.59
r4427608.vps18tiny.u.avcdn.net 23.43.165.59
www.google-analytics.com 172.217.31.142
h4444966.vps18tiny.u.avcdn.net
AAAA 2600:1410:1000::172b:a50a
AAAA 2600:1410:1000::172b:a53b
23.43.165.59
z4055813.iavs9x.u.avast.com
AAAA 2600:1410:1000::172b:a54b
AAAA 2600:1410:1000::172b:a532
23.43.165.50
y8002308.iavs9x.u.avast.com
AAAA 2600:1410:1000::172b:a54b
AAAA 2600:1410:1000::172b:a532
23.43.165.50
n4291289.vps18tiny.u.avcdn.net 23.43.165.59
h4444966.iavs9x.u.avast.com 23.43.165.75
r4427608.vps18tiny.u.avcdn.net
AAAA 2600:1410:1000::172b:a50a
AAAA 2600:1410:1000::172b:a53b
23.43.165.59
p9854759.iavs9x.u.avast.com 23.43.165.50
download.visualstudio.microsoft.com 192.229.232.200
s-vps18tiny.avcdn.net 23.40.45.32
r6726306.iavs9x.u.avast.com
AAAA 2600:1410:1000::172b:a532
AAAA 2600:1410:1000::172b:a54b
23.43.165.50
ncube.gomtv.com 183.110.10.192
iavs9x.u.avast.com 23.43.165.50
estat-thirdparty.zum.com 112.175.191.56
playinfo.gomlab.com 13.224.42.10
cdn.gomlab.com 14.0.114.117
l7814800.iavs9x.u.avast.com
AAAA 2600:1410:1000::172b:a54b
AAAA 2600:1410:1000::172b:a532
23.43.165.75
shepherd.ff.avast.com 69.94.69.113
h4444966.vps18tiny.u.avcdn.net 23.43.165.59
z4055813.iavs9x.u.avast.com 23.43.165.50
y8002308.iavs9x.u.avast.com 23.43.165.50
n4291289.vps18tiny.u.avcdn.net
AAAA 2600:1410:1000::172b:a53b
AAAA 2600:1410:1000::172b:a50a
23.43.165.59
r6726306.iavs9x.u.avast.com 23.43.165.50
log.gomlab.com 34.202.213.193
m0658849.iavs9x.u.avast.com
AAAA 2600:1410:1000::172b:a532
AAAA 2600:1410:1000::172b:a54b
23.43.165.75
r0965026.vps18tiny.u.avcdn.net 23.43.165.59
r3802239.iavs9x.u.avast.com 23.43.165.50
p9854759.iavs9x.u.avast.com
AAAA 2600:1410:1000::172b:a532
AAAA 2600:1410:1000::172b:a54b
23.43.165.50
alpha-license-dealer.ff.avast.com 69.94.69.205
l4691727.iavs9x.u.avast.com
AAAA 2600:1410:1000::172b:a54b
AAAA 2600:1410:1000::172b:a532
23.43.165.50
s-iavs9x.avcdn.net 23.40.45.32
img.gomlab.com 54.192.70.16
www.microsoft.com 104.109.241.178
v7event.stats.avast.com 69.94.68.209
l7814800.iavs9x.u.avast.com 23.43.165.75
c3978047.iavs9x.u.avast.com 23.43.165.50
g1928587.vps18tiny.u.avcdn.net
AAAA 2600:1410:1000::172b:a50a
AAAA 2600:1410:1000::172b:a53b
23.43.165.59
IP Address Status Action
112.175.191.56 Active Moloch
14.0.114.116 Active Moloch
142.250.199.78 Active Moloch
164.124.101.2 Active Moloch
183.110.10.189 Active Moloch
183.110.10.192 Active Moloch
192.229.232.200 Active Moloch
23.53.224.176 Active Moloch
34.202.213.193 Active Moloch
5.62.53.239 Active Moloch
96.7.251.224 Active Moloch
99.84.224.136 Active Moloch
99.86.207.102 Active Moloch
23.201.37.168 Active Moloch
23.43.165.50 Active Moloch
23.43.165.59 Active Moloch
23.43.165.75 Active Moloch
5.62.38.16 Active Moloch
5.62.40.201 Active Moloch
77.234.46.23 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49184 -> 14.0.114.116:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49182 -> 14.0.114.116:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49183 -> 14.0.114.116:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49197 -> 14.0.114.116:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49181 -> 99.84.224.136:80 2011227 ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) Potentially Bad Traffic
TCP 192.168.56.102:49223 -> 14.0.114.116:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49229 -> 23.53.224.176:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.229.232.200:80 -> 192.168.56.102:49239 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 192.229.232.200:80 -> 192.168.56.102:49239 2014520 ET INFO EXE - Served Attached HTTP Misc activity
TCP 192.168.56.102:49235 -> 112.175.191.56:80 2011227 ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) Potentially Bad Traffic
TCP 96.7.251.224:80 -> 192.168.56.102:49248 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.102:49184
14.0.114.116:443
None None None
TLSv1
192.168.56.102:49182
14.0.114.116:443
C=US, O=DigiCert Inc, CN=DigiCert TLS RSA SHA256 2020 CA1 C=US, ST=California, L=Campbell, O=CDNetworks Inc., CN=support18.cdnetworks.net 99:61:0c:bb:af:ec:d1:3f:78:8c:35:33:f9:01:ae:94:5a:91:36:d9
TLSv1
192.168.56.102:49183
14.0.114.116:443
C=US, O=DigiCert Inc, CN=DigiCert TLS RSA SHA256 2020 CA1 C=US, ST=California, L=Campbell, O=CDNetworks Inc., CN=support18.cdnetworks.net 99:61:0c:bb:af:ec:d1:3f:78:8c:35:33:f9:01:ae:94:5a:91:36:d9
TLSv1
192.168.56.102:49197
14.0.114.116:443
None None None
TLSv1
192.168.56.102:49223
14.0.114.116:443
None None None
TLSv1
192.168.56.102:49229
23.53.224.176:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=GB, L=London, O=Avast plc, OU=avcdn, CN=*.avcdn.net ff:97:bf:fa:16:55:c5:95:15:f5:0d:8f:d7:f8:40:a5:e7:61:a5:e8
TLS 1.1
192.168.56.102:49233
96.7.251.224:443
C=US, O=DigiCert Inc, CN=DigiCert SHA2 Secure Server CA C=US, ST=Massachusetts, L=Cambridge, O=Akamai Technologies, Inc., CN=a248.e.akamai.net 4e:74:27:b2:2c:d7:8f:7a:a4:71:65:18:cf:6a:09:fb:74:a8:72:e8
TLS 1.1
192.168.56.102:49244
96.7.251.224:443
C=US, O=DigiCert Inc, CN=DigiCert SHA2 Secure Server CA C=US, ST=Massachusetts, L=Cambridge, O=Akamai Technologies, Inc., CN=a248.e.akamai.net 4e:74:27:b2:2c:d7:8f:7a:a4:71:65:18:cf:6a:09:fb:74:a8:72:e8
TLS 1.1
192.168.56.102:49241
96.7.251.224:443
C=US, O=DigiCert Inc, CN=DigiCert SHA2 Secure Server CA C=US, ST=Massachusetts, L=Cambridge, O=Akamai Technologies, Inc., CN=a248.e.akamai.net 4e:74:27:b2:2c:d7:8f:7a:a4:71:65:18:cf:6a:09:fb:74:a8:72:e8
TLS 1.1
192.168.56.102:49247
96.7.251.224:443
C=US, O=DigiCert Inc, CN=DigiCert SHA2 Secure Server CA C=US, ST=Massachusetts, L=Cambridge, O=Akamai Technologies, Inc., CN=a248.e.akamai.net 4e:74:27:b2:2c:d7:8f:7a:a4:71:65:18:cf:6a:09:fb:74:a8:72:e8
TLS 1.1
192.168.56.102:49246
96.7.251.224:443
C=US, O=DigiCert Inc, CN=DigiCert SHA2 Secure Server CA C=US, ST=Massachusetts, L=Cambridge, O=Akamai Technologies, Inc., CN=a248.e.akamai.net 4e:74:27:b2:2c:d7:8f:7a:a4:71:65:18:cf:6a:09:fb:74:a8:72:e8
TLS 1.1
192.168.56.102:49256
5.62.53.239:443
C=US, O=DigiCert Inc, CN=DigiCert TLS Hybrid ECC SHA384 2020 CA1 C=GB, L=London, O=Avast plc, CN=*.avast.com 34:92:a3:a3:65:65:33:d4:f1:e1:26:ed:59:64:32:ee:96:67:4b:6e
TLS 1.1
192.168.56.102:49264
5.62.40.201:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=GB, L=London, O=Avast plc, OU=certificates@avast.com, CN=*.avast.com ff:ac:7e:c7:dd:bd:f0:a5:c2:b1:c0:f6:42:9e:68:49:f6:68:a8:cc
TLS 1.1
192.168.56.102:49321
77.234.46.23:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=GB, L=London, O=Avast plc, OU=certificates@avast.com, CN=*.avast.com ff:ac:7e:c7:dd:bd:f0:a5:c2:b1:c0:f6:42:9e:68:49:f6:68:a8:cc
TLS 1.1
192.168.56.102:49809
5.62.38.16:443
C=US, O=DigiCert Inc, CN=DigiCert TLS Hybrid ECC SHA384 2020 CA1 C=GB, L=London, O=Avast plc, CN=*.avast.com 12:d8:7c:36:23:88:53:d4:88:42:1d:fc:43:cb:ec:09:b6:a9:2a:57

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0

__exception__

stacktrace:
CharNextA+0xfb DispatchMessageA-0xa5 user32+0x17b16 @ 0x74c47b16
GetMessageW+0xe5 KillTimer-0x14 user32+0x179c7 @ 0x74c479c7
DispatchMessageW+0xf GetMessageW-0x58 user32+0x1788a @ 0x74c4788a
IsDialogMessageW+0x11e GetLastActivePopup-0x274 user32+0x3c81f @ 0x74c6c81f
DialogBoxIndirectParamW+0x1f4 DialogBoxIndirectParamAorW-0x6d user32+0x3cde7 @ 0x74c6cde7
DialogBoxIndirectParamAorW+0x108 SetDlgItemTextW-0x44 user32+0x3cf5c @ 0x74c6cf5c
DialogBoxIndirectParamAorW+0x36 SetDlgItemTextW-0x116 user32+0x3ce8a @ 0x74c6ce8a
DialogBoxParamW+0x3f GetCursorFrameInfo-0xa2 user32+0x3d009 @ 0x74c6d009
gomaudiokorsetup_new+0x3e9a @ 0x403e9a

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x70662320
registers.esp: 1636992
registers.edi: 0
registers.eax: 1885741856
registers.ebp: 1637032
registers.edx: 0
registers.ebx: 0
registers.esi: 1885741856
registers.ecx: 15666536
1 0 0
suspicious_features POST method with no referer header suspicious_request POST http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
suspicious_features POST method with no referer header suspicious_request POST http://www.google-analytics.com/collect
suspicious_features POST method with no referer header suspicious_request POST https://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
suspicious_features POST method with no referer header suspicious_request POST https://shepherd.ff.avast.com/
suspicious_features POST method with no referer header suspicious_request POST https://alpha-license-dealer.ff.avast.com/common/v1/device/unattendedtrial
request GET http://playinfo.gomlab.com/setup_v2/index.gom?setup=audio&name=GOMAUDIOKORSETUP_NEW&bit=32&lang=kor&version=2.2.27.0&checkdate=202104151505
request GET http://playinfo.gomlab.com/setup_v2/bundle.gom?bundle=clipdown&resource=true&country=KR&setup=audio
request GET http://playinfo.gomlab.com/setup_v2/bundle.gom?bundle=avast&resource=true&country=KR&setup=audio
request GET http://ncube.gomtv.com/gom/Promotion.ini
request GET http://ana.gomtv.com/cgi-bin/prdpromo.cgi?promo=zum_dirpage&prd=audio&type=check&param=KOR,2.2.27.0&agent=GomAudio_Setup&ukey=7446
request GET http://ana.gomtv.com/cgi-bin/prdpromo.cgi?promo=zum_dirpage&prd=audio&type=view&param=KOR,2.2.27.0&agent=GomAudio_Setup&ukey=7446
request GET http://img.gomlab.com/css/gomproduct/setup.css?20170228
request GET http://img.gomlab.com/js/web/jquery-1.8.x.js?20170228
request GET http://img.gomlab.com/img/gomproduct/setup/gomaudio_header.png
request GET http://ana.gomtv.com/cgi-bin/prdpromo.cgi?promo=clipdown&prd=gomaudio&type=check&param=KOR,2.2.27.0&agent=GomAudio_Setup&ukey=7446
request GET http://playinfo.gomlab.com/cms/bundle/log.gom?log=avast,KR,KR,175.208.134.150&mode=new&type=check
request GET http://ana.gomtv.com/cgi-bin/prdpromo.cgi?promo=clipdown&prd=gomaudio&type=view&param=KOR,2.2.27.0&agent=GomAudio_Setup&ukey=7446
request GET http://playinfo.gomlab.com/cms/bundle/log.gom?log=avast,KR,KR,175.208.134.150&mode=new&type=show
request GET http://playinfo.gomlab.com/cms/bundle/log.gom?log=avast,KR,KR,175.208.134.150&mode=new&type=AcceptClicked
request GET http://ana.gomtv.com/cgi-bin/prdpromo.cgi?promo=clipdown&prd=gomaudio&type=set&param=KOR,2.2.27.0&agent=GomAudio_Setup&ukey=7446
request GET http://playinfo.gomlab.com/cms/bundle/log.gom?log=avast,KR,KR,175.208.134.150&mode=new&type=installed
request POST http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
request POST http://www.google-analytics.com/collect
request GET http://ana.gomtv.com/cgi-bin/prdpromo.cgi?promo=zum_dirpage&prd=audio&type=set&param=KOR,2.2.27.0&agent=GomAudio_Setup&ukey=7446
request GET http://estat-thirdparty.zum.com/at.gif?data=eyAiZXZlbnQiOiAiQENvbnNlbnQiLCAicHJvcGVydGllcyI6IHsgInNvZnR3YXJlIjogIkdvbUF1ZGlvIiwgImNoZWNrYm94Q2xpY2siOiAidHJ1ZSIsICJjaGVja1N0ZXAiOiAyLCAidGltZSI6IDE2MzUzNDkzNDAgfSB9&time=1635349340621
request GET http://log.gomlab.com/audio/install?build=new_kor&fpb=&version=2.2.27.0&os=windows764bit&lang=kor&bit=32bit&guid=9604e1a277cf0c84fd663ec04db3d3fb&browser=ie
request GET http://go.microsoft.com/fwlink/?linkid=2088631
request GET http://download.visualstudio.microsoft.com/download/pr/2d6bb6b2-226a-4baa-bdec-798822606ff1/8494001c276a4b96804cde7829c04d7f/ndp48-x86-x64-allos-enu.exe
request GET http://ana.gomtv.com/cgi-bin/prdpromo.cgi?promo=zum_finish&prd=audio&type=check&param=KOR,2.2.27.0&agent=GomAudio_Setup&ukey=7446
request GET http://iavs9x.u.avast.com/iavs9x/avast_free_antivirus_setup_online_x64.exe
request GET http://www.google-analytics.com/collect?aiid=mmm_gom_ppi_003_434_m&an=Free&av=21.8.6586&cd=stub-extended&cd3=Online&cid=f67aa09e-bd89-4ed5-8e92-1707c1a27e97&dt=Installation&t=screenview&tid=UA-58120669-3&v=1
request GET http://r6726306.iavs9x.u.avast.com/iavs9x/servers.def.vpx
request GET http://r6726306.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx
request GET http://r6726306.iavs9x.u.avast.com/iavs9x/part-setup_ais-15020997.vpx
request GET http://r6726306.iavs9x.u.avast.com/iavs9x/avbugreport_x64_ais-997.vpx
request GET http://r6726306.iavs9x.u.avast.com/iavs9x/avdump_x64_ais-997.vpx
request GET http://r6726306.iavs9x.u.avast.com/iavs9x/avdump_x86_ais-997.vpx
request GET http://r6726306.iavs9x.u.avast.com/iavs9x/instcont_x64_ais-997.vpx
request GET http://r6726306.iavs9x.u.avast.com/iavs9x/instup_x64_ais-997.vpx
request GET http://r6726306.iavs9x.u.avast.com/iavs9x/offertool_x64_ais-997.vpx
request GET http://r6726306.iavs9x.u.avast.com/iavs9x/sbr_x64_ais-997.vpx
request GET http://r6726306.iavs9x.u.avast.com/iavs9x/setgui_x64_ais-997.vpx
request GET http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
request GET http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
request GET http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl
request GET http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl
request GET http://r3802239.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx
request GET http://r3802239.iavs9x.u.avast.com/iavs9x/part-prg_ais-15020997.vpx
request GET http://g1928587.vps18tiny.u.avcdn.net/vps18tiny/prod-vps.vpx
request GET http://g1928587.vps18tiny.u.avcdn.net/vps18tiny/part-jrog2-41.vpx
request GET http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl
request GET http://g1928587.vps18tiny.u.avcdn.net/vps18tiny/part-vps_windows-21102505.vpx
request GET http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
request GET http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl
request GET https://cdn2.gomlab.com/gretech/GOMSetupV2/ruledef.ini
request POST http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
request POST http://www.google-analytics.com/collect
request POST https://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
request POST https://shepherd.ff.avast.com/
request POST https://alpha-license-dealer.ff.avast.com/common/v1/device/unattendedtrial
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x10004000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x730f2000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72e33000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2532
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04ce0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08120000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08120000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08120000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08121000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08121000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08122000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08122000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08122000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08123000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08123000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08124000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08124000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08125000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08125000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08126000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08126000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08127000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08127000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08127000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08127000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08128000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08128000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08128000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08129000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08129000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x08129000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0812a000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0812a000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0812b000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0812b000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0812c000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0812d000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0812d000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0812e000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0812f000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0812f000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x081d0000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x081d1000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x081d2000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x081d2000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x081d3000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x081d4000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x081d4000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x081d4000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x081d4000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x081d5000
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

GetDiskFreeSpaceExW

total_number_of_free_bytes: 4213123
free_bytes_available: 1
root_path: C:\Program Files (x86)\GOM\GOMAudio
total_number_of_bytes: 51740234064330753
0 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 4213123
free_bytes_available: 1
root_path: C:\Program Files (x86)\GOM\
total_number_of_bytes: 51740234064330753
0 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 10864807936
free_bytes_available: 10864807936
root_path: C:\Program Files (x86)\
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 6231
free_bytes_available: 1972697604522469
root_path: C:\Program Files (x86)\GOM\GOMAudio
total_number_of_bytes: 7022701025689601
0 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 6231
free_bytes_available: 1972697604522469
root_path: C:\Program Files (x86)\GOM\
total_number_of_bytes: 7022701025689601
0 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 10864807936
free_bytes_available: 10864807936
root_path: C:\Program Files (x86)\
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 10836000768
free_bytes_available: 10836000768
root_path: C:\
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 10836000768
free_bytes_available: 10836000768
root_path: C:\
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 98825680
free_bytes_available: 0
root_path: D:\
total_number_of_bytes: 98821232
0 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 104615312
free_bytes_available: 3
root_path: D:\
total_number_of_bytes: 98821232
0 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 0
free_bytes_available: 10782552064
root_path: C:\Windows\Temp\asw.bf47894bd73193d0
total_number_of_bytes: 0
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 0
free_bytes_available: 10650763264
root_path:
total_number_of_bytes: 0
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 10606804992
free_bytes_available: 10606804992
root_path: C:\
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 0
free_bytes_available: 10606800896
root_path:
total_number_of_bytes: 0
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 0
free_bytes_available: 10606800896
root_path:
total_number_of_bytes: 0
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 0
free_bytes_available: 10606800896
root_path: C:\
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 0
free_bytes_available: 10202341376
root_path:
total_number_of_bytes: 0
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 0
free_bytes_available: 10202324992
root_path:
total_number_of_bytes: 0
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 0
free_bytes_available: 10202177536
root_path: C:\
total_number_of_bytes: 34252779520
1 1 0
registry HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
name RT_VERSION language LANG_KOREAN filetype data sublanguage SUBLANG_KOREAN offset 0x006d1c20 size 0x000002cc
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\1038\SetupResources.dll
file C:\Program Files (x86)\GOM\GOMAudio\plugins\bass\bassalac.dll
file C:\Program Files (x86)\GOM\GOMAudio\7za.dll
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\NetFx452\netfx_Full_GDR_x64.msi
file C:\Program Files (x86)\GOM\GOMAudio\Visualizer.exe
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\NetFx462\netfx_Full_x64.msi
file C:\Users\Public\Desktop\곰오디오.lnk
file C:\Program Files (x86)\GOM\GOMAudio\plugins\bass\bassenc_opus.dll
file C:\Program Files (x86)\GOM\GOMAudio\plugins\bass\basswv.dll
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\SetupUtility.exe
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\1044\SetupResources.dll
file C:\Users\test22\AppData\Local\Temp\nsjC273.tmp\System.dll
file C:\Windows\Temp\asw.60b8d26201f36095\uat_812.dll
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\1053\SetupResources.dll
file C:\Program Files (x86)\GOM\GOMAudio\plugins\bass\bassflac.dll
file C:\Windows\Temp\asw.60b8d26201f36095\uat_2040.dll
file C:\Program Files (x86)\GOM\GOMAudio\MACSSDK.dll
file C:\Program Files (x86)\GOM\GOMAudio\plugins\bass\basscd.dll
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\1029\SetupResources.dll
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\2070\SetupResources.dll
file C:\Program Files (x86)\GOM\GOMAudio\gasconvert.exe
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\NetFx452\netfx_Full_GDR_x86.msi
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\2052\SetupResources.dll
file C:\Users\test22\AppData\Local\Temp\nsjC273.tmp\md5dll.dll
file C:\Users\test22\AppData\Local\Temp\NSISPromotionEx.dll
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\NetFx452\netfx_Full_LDR_x86.msi
file C:\Program Files (x86)\GOM\GOMAudio\plugins\bass\basswma.dll
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\NetFx451\netfx_Full_LDR_x64.msi
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\1055\SetupResources.dll
file C:\Program Files (x86)\GOM\GOMAudio\plugins\bass\bassenc_flac.dll
file C:\Users\test22\AppData\Local\Temp\nsjC273.tmp\INetC.dll
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\1040\SetupResources.dll
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\SetupUi.dll
file C:\Program Files (x86)\GOM\GOMAudio\plugins\bass\bass_ape.dll
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM\곰오디오\프로그램 제거.lnk
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\netfx_Full_x64.msi
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\NetFx461\netfx_Full_x64.msi
file C:\Program Files (x86)\GOM\GOMAudio\Goma.exe
file C:\Program Files (x86)\GOM\GOMAudio\plugins\bass\bassenc.dll
file C:\Program Files (x86)\GOM\GOMAudio\Uninstall.exe
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\1030\SetupResources.dll
file C:\Windows\Temp\asw.60b8d26201f36095\Instup.dll
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\1046\SetupResources.dll
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\NetFx452\netfx_Full_LDR_x64.msi
file C:\Program Files (x86)\GOM\GOMAudio\plugins\bass\bass_fx.dll
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\3082\SetupResources.dll
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\1049\SetupResources.dll
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM\곰오디오\곰오디오.lnk
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\1041\SetupResources.dll
file C:\862a6ab14c8a0e6f9f6d1a24394d0a\NetFx45\netfx_Full_x64.msi
Time & API Arguments Status Return Repeated

SetFileAttributesW

file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: C:\ProgramData\GRETECH\GOMAudio\images
filepath: C:\ProgramData\GRETECH\GomAudio\images
1 1 0
file C:\Users\test22\Links\Desktop.lnk
file C:\Users\test22\Links\RecentPlaces.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\곰오디오.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM\곰오디오\곰오디오.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM\곰오디오\프로그램 제거.lnk
file C:\Users\Public\Desktop\곰오디오.lnk
file C:\Users\test22\Links\Downloads.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\곰오디오.lnk
cmdline "regsvr32" /s "C:\Program Files (x86)\Common Files\GOM & Company\VSUtil.dll"
cmdline "regsvr32" /s "C:\Program Files (x86)\GOM\GOMAudio\MiniBand.dll"
file C:\Windows\Temp\asw.60b8d26201f36095\Instup.exe
file C:\Users\test22\AppData\Local\Temp\nsdA32E.tmp\DotNetChecker.dll
file C:\Users\test22\AppData\Local\Temp\HwInfo.dll
file C:\Users\test22\AppData\Local\Temp\nsjC273.tmp\System.dll
file C:\Users\test22\AppData\Local\Temp\NSISTrigger.dll
file C:\Users\test22\AppData\Local\Temp\nsdA32E.tmp\nsisdl.dll
file C:\Users\test22\AppData\Local\Temp\NSISPromotionEx.dll
file C:\Users\test22\AppData\Local\Temp\nsjC273.tmp\nsn9624.tmp
file C:\Users\test22\AppData\Local\Temp\nsjC273.tmp\nsb9EA1.tmp
file C:\Users\test22\AppData\Local\Temp\nsjC273.tmp\nsDialogs.dll
file C:\Users\test22\AppData\Local\Temp\dotnetfx.exe
file C:\Users\test22\AppData\Local\Temp\nsjC273.tmp\LangDLL.dll
file C:\Users\test22\AppData\Local\Temp\nsjC273.tmp\INetC.dll
file C:\Users\test22\AppData\Local\Temp\nsjC273.tmp\advsplash.dll
file C:\Users\test22\AppData\Local\Temp\nsjC273.tmp\nsJSON.dll
file C:\Users\test22\AppData\Local\Temp\atl110.dll
file C:\Users\test22\AppData\Local\Temp\nsjC273.tmp\md5dll.dll
file C:\Users\test22\AppData\Local\Temp\nsjC273.tmp\Dialer.dll
file C:\Users\test22\AppData\Local\Temp\nsjC273.tmp\UserInfo.dll
Cylance Unsafe
K7AntiVirus Adware ( 005487401 )
K7GW Adware ( 005487401 )
ESET-NOD32 a variant of Win32/GOMLab.A potentially unwanted
Sophos Generic ML PUA (PUA)
Antiy-AVL Trojan/Generic.ASMalwNS.6
Zoner Probably Heur.ExeHeaderH
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2532
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 16 (PAGE_EXECUTE)
base_address: 0x08120000
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 0
family: 0
1 0 0
Time & API Arguments Status Return Repeated

InternetReadFile

buffer: MZÿÿ¸@غ´ Í!¸LÍ!This program cannot be run in DOS mode. $­±(éÐFÒéÐFÒéÐFÒ*ßÒëÐFÒéÐGÒvÐFÒ*ßÒæÐFÒ½óvÒãÐFÒ.Ö@ÒèÐFÒRichéÐFÒPEL)\à d| 2€@ðå<@…<… P8@_ +€˜.textbd `.rdata\€h@@.dataU |@À.ndataP€À.rsrc8P’‚@@U‹ìƒì\ƒ} t+ƒ} F‹Eu ƒH‹ ôB‰HPÿuÿu ÿuÿ‚@éBSV‹5ôBE¤WPÿuÿ‚@ƒeô‰E EäPÿuÿ ‚@‹}ðƒeð‹\€@逶FR¶VV¯Uè‹Ï+Mè¯Á‰M™÷ÿ3Ҋð¶FQ¯Á¶NU¯MèÁ‹Ê™÷ÿ¶VT¯UèŠÈ¶FP¯E™÷ÿÁá¶À ȍEôP‰Møÿd€@ƒEð‰EPEäPÿu ÿ‚@ÿuÿӃEè9}èŒwÿÿÿƒ~Xÿteÿv4ÿT€@…À‰EtU‹} jWÇEäÇEèÿP€@ÿvXWÿX€@ÿu‹5L€@Wÿ։E Eäh PjÿhìBWÿ‚@ÿu WÿÖÿuÿӍE¤Pÿuÿl‚@_^3À[É‹L$¡HôB‹ÑSiÒVW‹TöÂtOq3ÿ;5LôBsB‹ÎiɍD‹öÁtGëöÁt ‹ÏO…Ét ëöÁu ‹Ù3ڃã3ىF;5LôBrÊ_^[ÂU‹ìQQ‹USV‹òiö‹HôB3ÉóW‰Mü‰Mø‹F¨t 9M t$¾B‰F;LôBsD‹ÂiÀ|B‹öÁt jRè¥ÿÿÿ‹öÁu(öÁ@tÿEüöÁtÿEüëÿEø;LôB‹Ðr¼3À_^[Ƀ}ütóƒ}øtƒN@ëç‹N€áƒÉ‰NëًL$¡HôBV3öƒù s495LôBv,PW‹¨u3ÿGÓç…züt ë$þ‰FÂ;5LôBrÙ_^ÂU‹ìƒì ¡ôBƒeüSV”W‹=LôB‰Eø‹Eø3Û9tK;ßsE‹5HôBƒÆ‹öÂu(‹E…Àtƒ<˜t‹Mü3À@ƒâÓà‹Nü#ȋÁ‹MüÓâ;Âu CÆ;ßrÆ;ßt ÿEüƒEøƒ}ü rŸ‹Eü_^[É‹D$…À}@¹CÁà +ÈQè‘KÂV‹t$ëj‹Æ‹ PôBkÀÁƒ8t\PèŒ=ÿÿÿtUPè¸ÿÿÿ…Àu@FëH‹Î‹ð+Áƒ|$ t/ìëBjÿ5ÔëBh0uÿ5ìëBÿH@Phÿt$ÿ‚@…ö}’3À^¸ÿÿÿëõ‹D$‹ ôBjÿtlèiÿÿÿÂh¨@ÿt$è–<ÂU‹ììÈ¡ôBSV‹uWjY}ԉEø3Ûó¥‹E؋U܋ð‹úÁæ ¹C‰]üÁç ñùM؉ T¸@‹MԃÁþƒùA‡Îÿ$i)@SPè0<éKÿÌëB9]ø„<Sÿȁ@é0Pè°þÿÿHSPèÄþÿÿé˜SPèö;éSè̓øY‰UÄ3À@PÿŒ€@écÿuøÿL‚@éUÁà9]àu&‹ˆ ôBj‰ˆàôBèŒY‰UċM؉ ôBé'‹ˆàôB‰ˆ ôBé‹Eà4… ôB3À‹;Ë”À#Mä‹D…؉éÿ4• ôBV鐋 ÐëB‹5x‚@;ËtRQÿ֋E؋ äëB;Ë„ÃPQÿÖéºjðè'ÿuÜPÿø€@…À…¡éajðè ‹øWèD‹ð;ótTj\Vè‹C‹ðŠˆ:ÈE u9]àtè8@…ÀtWè”?ëWè @;Ãt=·u Wÿü€@¨uÿEüŠE ˆF:Ãu¬9]Üt)jæèóýÿÿWhXCèeIWÿ´€@…À… ÿEüéjõéä SèlPè>LéjÐèZjߋðèQj‹øèHWVÿ@…Àtjãé§ 9]à„}VèþK…À„oWVèËFjäé‚ Sè ‹ðEPWhVÿ@…Àt#‹E;Æv%8t!VèºK;ÃtƒÀ,Pÿuè§Hë ÇEüˆ9]à…JhWWÿ@é8jÿ襍MQVhSPSÿ@…À…éªjïè~PVèDéUþÿÿj1èk‹ð‹E؃àV‰uø‰Eè1BV¾¤@…ÀtVèHëhXCVèHPè¡APèHVègJ¿¬@ƒ}|1VèïJ3É;ÃtMäƒÀQPÿô€@‹È‹EƒÀý €#Á÷ØÀ@‰E9]uVè*C3Àƒ}•À@Ph@Vè9Cƒøÿ‰Eôuv9]uShCWèˆGVhCè}Gÿuìh¨@è’GWhCèeG‹EØÁøPh¨@èp>ƒè„SÿÿÿHtVjúé2üÿÿÿuøjâè]8ƒ}é=ýÿÿÿ¨ôBéâÿuøjêè?8ÿÔôBSSÿuôÿuàèÿ ÔôBƒ}äÿ‹øuƒ}èÿtEäPEäSPÿuôÿ @ÿuôÿ@;û…ƒÿþujéVèãFÿuøVèÔFëjîVèÐFh Véå Së4j1èÄÿuØPè¬=;Ä;Eà„g;Eè…-‹Eìé0jðè’ÿuÜPè&>éjè}PèbFé$ jèIj‰EÀ‰UÄè<Y‹ø‹EÀYj‰}ȉỦEèGP‰EÐè)F9]Ĉu‰E9]„·‹MÈ;Ë} <;ûŒ¥;ø~‹ø‹EÐÇPVèÜE9]}VèçEEy‰]‹E=rˆ0éjj è×j1‹ðèÎ9]èPVuÿ@…Àuz‹EàéLÿ$@ëì3ÿGWè¤hVP‰Eÿ`@…Àt9]àtVÿuÿ$@…Àu‰}üˆˆžÿéù‹uìSèBj‹ø‰UÄè6Y;óY‰UÄu;ø|~Œë;øs‹EäéÒ†xÿÿÿ‹EèéÄjè‹øj‰Uĉ}èõY‰UÄY‹È‹Eäƒø wsÿ$…q*@ùëk+ùëg¯Ïë;ËtD‹Ç™÷ù‹øëU Ïë#Ïë3ϋùëG3À;û”Àëå;ûuë3ÿë4;ûtø;Ëtô3ÿGë';Ët ‹Ç™÷ù‹úë3ÿÇEüëÓçë ÓÿëÓïë‹}Wé*úÿÿjè…j‹øèZPWV‰UÄÿt‚@ƒÄéô ‹Eà‹=X¸@;ÃtDH;û„[‹?;Ãuñ;û„MƒÇ¾¤@WVè D¡X¸@ƒÀPWèûC¡X¸@VƒÀPéÁ ;Ót%;û„\ GPVèÖC‹W£X¸@ÿ\@éz hj@ÿX@ÿu؋ðFPèÊC¡X¸@‰‰
request_handle: 0x00cc0010
1 1 0

InternetReadFile

buffer: MZÿÿ¸@º´ Í!¸LÍ!This program cannot be run in DOS mode. $²ÐcÕö± †ö± †ö± †B-ü†ý± †B-þ†ˆ± †B-ÿ†î± †¤Ù ‡ä± †¤Ù‡ã± †SØ ‡ô± †¤Ù‡Æ± †ö± †'± †ÿɞ†ç± †ÿɉ†÷± †S؇û± †SØò†÷± †ö±š†ô± †S؇÷± †Richö± †PELš7aà" p  @°SC@ÁL®´ð°™Hxà0”p•€<@ ì\¬€.textz `.rdataŸ  @@.data°À ´@À.didat<à¾@À.rsrc°™ðšÀ@@.reloc0Z@B¹¼ÍBè¦þhpBè÷YÃÌÌÌÌÌÌÌÌÌÌVjjjjÿô Bhœ%Bÿ!B…Àt%h¸%BPÿè B‹ð…öth‹Îÿì"BÿօÀu?hÔ%Bÿ !BhØ%Bÿ!B…Àt%hì%BPÿè B‹ð…ötjh@j‹Îÿì"BÿÖj ÿü B…ÀuhëèH)ƒÄhÀÿ„!Bè5g=shìè$)ƒÄh~ÿ„!Bè¿ïPÿ„!BÌÌÌÌÌÌÌÌÌÌU‹ì‹EVW‹}Æ·w$ƒÆÿð BVjPÿ`!B£hÉB…Àtu·O$SQÿw(PèSþ·O$ƒÄ ¡hÉB3ÒÑéhRf‰Hÿð BPÿ`!B‹Ø…Ût8j`Sÿ!B‹ð…öt)ƒþ`w$h€%B sQÿ!Bu‰_(f‰G$ƒÀf‰G&[_^] ÌÌÌÌÌÌÌU‹ìjÿuÿˆ"B…ÀtPÿ¤"B…Àt°]Ã2À]ÃÌÌÌÌÌÌÌÌÌÌÌU‹ìì ¡ÀB3ʼnEü‹ESV‹u W‹}P‰…à÷ÿÿÿ "BVP‰…ä÷ÿÿÿL BW…ü÷ÿÿWÀhPf…ô÷ÿÿè(…è÷ÿÿP…ü÷ÿÿhT&BPè„)‹½ø÷ÿÿ‹Ð‹…ô÷ÿÿƒÄ3ۉ…ø÷ÿÿ‹Êqf‹ƒÁf…Àuõ+΍…ì÷ÿÿ‹µä÷ÿÿPÑùQRVÿP B‹…ì÷ÿÿ;…ø÷ÿÿLýð÷ÿÿ‹Ø…è÷ÿÿPhT&Bj‰ø÷ÿÿè)‹ÐƒÄ …ÒušVÿµà÷ÿÿÿP"B‹Mü‹×_^‹Ã3Í[è¢ð‹å]ÃU‹ììl¡ÀB3ʼnEü‹E S‹]‰¤ýÿÿV‹uW‹}‰½ôýÿÿƒè„ÿƒèt}-…Ï;œÉBtF…Ûuƒþt=; ÉBt…Û…®ƒþ…¥Wÿ¼"BjÿÈ"B_^3À[‹Mü3Íèð‹å]ÂWÿ¼"BjÿÈ"B_^3À[‹Mü3Íèëï‹å]Âÿ5ŒÉBÿ¼"Bÿ5ÉBÿ¼"Bÿ5”ÉBÿ¼"Bÿ5˜ÉBÿ¼"Bÿ5 ÉBÿ¼"Bÿ5œÉBÿ¼"Bÿ5¨ÉBÿT Bÿ5¬ÉBÿT Bÿ5¤ÉBÿT Bÿ5ˆÉBÿ„"Béà‹C‹3hð£„ÉB…üýÿÿjPDžøýÿÿôècƒÄ …øýÿÿjPhôj)ÿx"BEPÿ` BfnEóæÀ£¬ÉBòYˆ&Bò,À‰EEPÿ` BfnEóæÀ£¨ÉBòY€&Bò,À‰EEPÿ` B£¤ÉB†'Pèñ$Ž8'‹ØQ‰ÄýÿÿèÝ$ŽV'‰…èýÿÿQèË$Sÿ5¤ÉB‰…äýÿÿWèØüÿÿÿµèýÿÿ‹È‹òÿ5¨ÉB¸0»P+ÆWÀ™Ù+ÂfօœýÿÿÑøƒÀ‰Èýÿÿ‰…ÐýÿÿÆW‰…Ìýÿÿèüÿÿ(&Bf~Á…”ýÿÿ‰¼ýÿÿ4‰µÀýÿÿÿµäýÿÿ‹…˜ýÿÿÿ5¬ÉBÂW‰…ìýÿÿèLüÿÿ‹ìýÿÿƒÀƒÁ‰…´ýÿÿWÀ‰¸ýÿÿƒÄ0fօÜýÿÿʉµÜýÿÿ‰ðýÿÿµØýÿÿ‰Øýÿÿ•Üýÿÿ‰…àýÿÿ‹‹Ê;…äýÿÿM΃‹ñ;Ðu苹ƒè ‹µðýÿÿ™+ÂÑøjj0j0fnÀVóæÀjjd‰•ðýÿÿZ ÿ5„ÉBòYx&Bò,ÀWÀÈfօÜýÿÿ‰°ýÿÿƒÁÁ‰¨ýÿÿfօÜýÿÿ‰…¬ýÿÿÿ€"Bjÿ5„ÉB£ˆÉBjWj0j0jjhPjhX&BjÿÀ"Bÿ5ˆÉB£ŒÉBjhrPÿ\"B‹…Ðýÿÿ‹Ìýÿÿjÿ5„ÉB+ÈjWQ‹ÈýÿÿƒéPQPjPhPÿµÄýÿÿhX&BjÿÀ"Bjÿ5¤ÉB£ÉBj0Pÿ\"B‹…ìýÿÿ‹•˜ýÿÿ+Âjÿ5„ÉBjW‹¼ýÿÿP‹…Àýÿÿ+ÁPRQhPÿµèýÿÿhX&BjÿÀ"B‹¸ýÿÿºjÿ5„ÉB£”ÉB+ñ‹…´ýÿÿjWV+ÂPQRhPÿµäýÿÿhX&BjÿÀ"Bjÿ5¨ÉB£˜ÉBj0ÿ5”ÉBÿ\"Bjÿ5¬ÉBj0ÿ5˜ÉBÿ\"Bhr'èø!hs'‹ðèì!+ðýÿÿƒÄ‹ø‹…°ýÿÿƒèjÿ5„ÉBjÿµôýÿÿS‹ðýÿÿPSjhPVhh&BjÿÀ"B‹µ¬ýÿÿ‹¨ýÿÿjÿ5„ÉB£œÉBC jÿµôýÿÿ+ÃP‹Æ+ÁPSQhPWhh&BjÿÀ"Bjÿ5¬ÉB£ ÉBj0ÿ5œÉBÿ\"Bjÿ5¬ÉBj0ÿ5 ÉBÿ\"BjEìƒÆPjj0{0ÿx"B…Àu_^¸[‹Mü3ÍèÚê‹å]‹Eô+Ɖuô™+‹ȋEø+ÇÑùjW™V+‰}ø‹½ôýÿÿÑøPQjW‰Mì‰Eðÿ¸"Bÿ5œÉBÿ´"B‹¤ýÿÿ‹uSVÿu Wÿœ"B‹Mü_^3Í[èoê‹å]ÂÌÌÌÌÌÌÌÌÌÌÌU‹ìƒìT¡ÀB3ʼnEü·ESVWhL&B3ÛPS‰]¬‰]¼ÿX!B‹ð…ötoVSÿ\!BVS‰Eøÿd!B…ÀtXPÿh!B‹ø…ÿtKÿuøjÿ€!B‹ð…öt:Vÿ|!B…Àt!ÿuøWPèäõƒÄ Vÿx!BE¼PjVÿÜ"B‹}¼…ÿuVÿø B‹}¼…ÿ„ýjj‰]´‰]Àÿä"B…Àˆ¢EÀPh<&Bjjh|.Bÿà"B…Àˆ‚‹MÀjWQ‹‹p‹Îÿì"BÿօÀxh‹MÀ‰]ð‹‹p0EðPQ‹Îÿì"BÿօÀxJƒ}ðuD‹MÀ‰]¸‹‹p4E¸PjQ‹Îÿì"BÿօÀx$E´Pÿu¸hŒ.Bè¼U‹E¸P‹‹q‹Îÿì"Bÿ֋MÀ…Ét‹Q‹p‹Îÿì"Bÿ֋]´…Û„ý‹ÇE¬ÇEôÇEø‹p EøPEô‹ÎPSÿì"BÿօÀˆ¸‹Mô…É„­‹Eø…À„¢WÀÇEÄ(÷ØfEØjfEàfEè‰MȉEÌÇEÐ ÇEÔÇE°ÿ "Bj‹ðE°jPjEÄPVÿH BVj‰E¬ÿP"Bƒ}¬t;‹Eôÿu°…‹‹Ê¯Mø‹pQRjS‹Îÿì"BÿօÀyÿu¬ÿT BÇE¬‹S‹p‹Îÿì"Bÿ֋W‹q‹Îÿì"Bÿ֋E¬_^[‹Mü3Íè¹ç‹å]ËMü‹Ã_^3Í[è¦ç‹å]ÃÌÌÌÌU‹ìjþhžBhPAd
request_handle: 0x00cc0010
1 1 0
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
url http://ns.adobe.com/xap/1.0/mm/
url http://ns.adobe.com/xap/1.0/sType/ResourceRef
url http://ns.adobe.com/xap/1.0/
description Communications over RAW Socket rule Network_TCP_Socket
description Escalate priviledges rule Escalate_priviledges
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerCheck__RemoteAPI
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
description Communications over RAW Socket rule Network_TCP_Socket
description Escalate priviledges rule Escalate_priviledges
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerCheck__RemoteAPI
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
description Escalate priviledges rule Escalate_priviledges
description Take ScreenShot rule ScreenShot
description Match Windows Http API call rule Str_Win32_Http_API
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
Time & API Arguments Status Return Repeated

RegOpenKeyExW

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
base_handle: 0x80000002
key_handle: 0x0000035c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
1 0 0

RegOpenKeyExW

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
base_handle: 0x80000002
key_handle: 0x0000035c
options: 0
access: 0x00020119
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
1 0 0

RegOpenKeyExW

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
base_handle: 0x80000002
key_handle: 0x0000035c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
1 0 0

RegOpenKeyExW

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
base_handle: 0x80000002
key_handle: 0x0000035c
options: 0
access: 0x00020119
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
1 0 0

RegOpenKeyExW

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
base_handle: 0x80000002
key_handle: 0x0000035c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
1 0 0

RegOpenKeyExW

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
base_handle: 0x80000002
key_handle: 0x0000035c
options: 0
access: 0x00020119
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
1 0 0

RegOpenKeyExW

regkey_r: SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
base_handle: 0x80000002
key_handle: 0x0000035c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
1 0 0

RegOpenKeyExW

regkey_r: SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
base_handle: 0x80000002
key_handle: 0x0000035c
options: 0
access: 0x00020119
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
1 0 0

RegOpenKeyExW

regkey_r: SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
base_handle: 0x80000002
key_handle: 0x0000035c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
1 0 0

RegOpenKeyExW

regkey_r: SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
base_handle: 0x80000002
key_handle: 0x0000035c
options: 0
access: 0x00020119
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
1 0 0

RegOpenKeyExW

regkey_r: SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
base_handle: 0x80000002
key_handle: 0x0000035c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
1 0 0

RegOpenKeyExW

regkey_r: SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
base_handle: 0x80000002
key_handle: 0x0000035c
options: 0
access: 0x00020119
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
1 0 0

RegOpenKeyExW

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
base_handle: 0x80000002
key_handle: 0x0000035c
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
1 0 0

RegOpenKeyExW

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
base_handle: 0x80000002
key_handle: 0x0000035c
options: 0
access: 0x00020119
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
1 0 0

RegOpenKeyExW

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\11stIcon
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00000009
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\11stIcon
2 0

RegOpenKeyExW

regkey_r: Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\11stIcon
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00000009
regkey: HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\11stIcon
2 0

RegOpenKeyExW

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\11stIcon
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00000009
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\11stIcon
2 0

RegOpenKeyExW

regkey_r: Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\11stIcon
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00000009
regkey: HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\11stIcon
2 0

RegOpenKeyExW

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NVDA
base_handle: 0xffffffff80000002
key_handle: 0x0000000000000000
options: 0
access: 0x00020219
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NVDA
2 0
Time & API Arguments Status Return Repeated

InternetOpenW

proxy_name:
proxy_bypass:
flags: 0
user_agent: GOMAudioKorSETUP
access_type: 0
1 13369352 0
file \\.\C:\ProgramData\Avast Software
file C:\ProgramData\Avast Software\Persistent Data\Avast\Logs\event_manager.log
file C:\ProgramData\Avast Software\Persistent Data\Avast\Logs\Setup.log
file C:\ProgramData\Avast Software\Avast\log
file C:\ProgramData\Avast Software\Persistent Data\Avast\Logs
file C:\ProgramData\Avast Software\Persistent Data\Avast\Logs\Setup.log.tmp.c7d6bcff-db2e-4441-a104-3c446abd8c52
file C:\ProgramData\Avast Software\Avast\Ring\farewell.ini
file C:\ProgramData\Avast Software\Persistent Data\Avast\Reboot.txt
file C:\ProgramData\Avast Software\Persistent Data\Avast\Logs\event_manager.log.tmp.cc64e93d-3175-403c-824c-581857a31b70
registry HKEY_LOCAL_MACHINE\SOFTWARE\AVG\Antivirus
registry HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVG\Antivirus
registry HKEY_LOCAL_MACHINE\Software\AVG\Antivirus
registry HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVG\AV
registry HKEY_LOCAL_MACHINE\SOFTWARE\AVG\AV
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast\properties
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast\LogFolder
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast\ChestFolder
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast\MovedFolder
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast\SetupLog
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast\CrashGuardProcessWatcherExclusions
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast\TempFolder
registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Avast Software\SymbolicLinkValue
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast\CertificateFile
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast\JournalFolder
registry HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software\Avast
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast\Instup_IgnoredDownloadTypes
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\SymbolicLinkValue
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast\ProgramFolder
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast\ReportFolder
registry HKEY_LOCAL_MACHINE\SOFTWARE\AVAST Software\Avast
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast\LicenseFile
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast\FwDataFolder
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast\DataFolder
registry HKEY_LOCAL_MACHINE\Software\AVAST Software\Avast
registry HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software\Avast\ShepherdDebug
Time & API Arguments Status Return Repeated

NtQuerySystemInformation

information_class: 8 (SystemProcessorPerformanceInformation)
1 0 0
registry HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B5E9C898-E8F6-427F-83B8-4BB33415E10C}\InprocServer32\(Default) reg_value C:\Program Files (x86)\GOM\GOMAudio\MiniBand.dll
registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\GOMA.exe
registry HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_EUPP_GLOBAL_FORCE_DISABLE\iexplore.exe
Time & API Arguments Status Return Repeated

NtCreateFile

create_disposition: 1 (FILE_OPEN)
file_handle: 0x000000a0
filepath: \??\PhysicalDrive0
desired_access: 0x00100080 (FILE_READ_ATTRIBUTES|SYNCHRONIZE)
file_attributes: 0 ()
filepath_r: \??\PhysicalDrive0
create_options: 96 (FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info: 0 (FILE_SUPERSEDED)
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
1 0 0

DeviceIoControl

input_buffer:
control_code: 2954240 ()
device_handle: 0x000000a0
output_buffer: (§Lu~ $ VBOX HARDDISK 1.0VBOX HARDDISK 1.0 42563265346333383963362d3532373632632066
1 1 0
Time & API Arguments Status Return Repeated

SetWindowsHookExW

thread_identifier: 0
callback_function: 0x00000000fff3ae10
hook_identifier: 13 (WH_KEYBOARD_LL)
module_address: 0x00000000ffe90000
1 524569 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob
process GOMAUDIOKORSETUP_NEW.EXE useragent NSIS_Inetc (Mozilla)
process GOMAUDIOKORSETUP_NEW.EXE useragent GOMAudioKorSETUP
process GOMAUDIOKORSETUP_NEW.EXE useragent HttpGetFile
process GOMAUDIOKORSETUP_NEW.EXE useragent Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3; MARKANYEPS#25118)
process GOMAUDIOKORSETUP_NEW.EXE useragent GOMPLAYERSETUP
Process injection Process 1488 resumed a thread in remote process 3032
Process injection Process 3032 resumed a thread in remote process 812
Process injection Process 812 resumed a thread in remote process 2040
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000180
suspend_count: 1
process_identifier: 3032
1 0 0

NtResumeThread

thread_handle: 0x0000000000000144
suspend_count: 1
process_identifier: 812
1 0 0

NtResumeThread

thread_handle: 0x00000000000005d4
suspend_count: 1
process_identifier: 2040
1 0 0
Time & API Arguments Status Return Repeated

NtQuerySystemInformation

information_class: 76 (SystemFirmwareTableInformation)
3221225507 0